企业在人工智能领域投入更多资金的同时,却将针对AI系统的攻击列为其准备最不足的威胁。普华永道(PwC)在2026年5月至7月期间对来自71个国家的3,934名商业和技术领导者进行了调查。其中,一半的安全和技术高管将此类攻击列为其五大准备不足领域之首,高于清单上的其他所有威胁。
在被问及由AI驱动的攻击时,超过半数的领导者将其中的三种列入了他们的五大担忧:由AI大规模指挥的僵尸网络、通过微妙改变AI系统所见内容以使其做出错误回答的对立攻击(adversarial attacks),以及将误导性记录混入模型训练数据中的数据投毒(data poisoning)。普华永道的评估认为,前沿AI模型现在能够发现未知的软件漏洞,并在极少人工参与的情况下加以利用。
预算在增加,但备份计划却未跟上
在被调查的安全和财务领导者中,84%的人预计网络预算将增长,而AI是资金优先投入的领域之一。然而,只有39%的受访者已完全正式化其针对网络事件的连续性计划,即拥有记录在案的方法以确保关键业务在遭受攻击后继续运行或恢复运行。近四分之一的人根本没有制定正式的计划。普华永道本身也将网络事件描述为“何时发生”的问题,而非“是否发生”。
AI下的数据基础薄弱
平均而言,公司仅在组织范围内实施了七项数据风险措施中的三项。只有约一半的公司实施了数据分类(data classification),这是了解哪些数据敏感的基本步骤。普华永道的观点是,AI的可信度取决于其底层的数据质量,因此,如果您今年正在推出AI工具,请检查它们可以访问哪些数据以及这些数据受到保护的程度如何。
很少有公司会让AI独自行动
在防御方面,不到四分之一的领导者会允许AI代理(agents,即自主采取行动的软件)在未经人类批准的情况下遏制和修复攻击。大多数公司会将代理的权限限制在低风险操作,或保留人工监督。超过半数的人将技术的可靠性和成熟度列为主要障碍。
“要在AI时代取得成功,我们需要能够以机器速度进行防御,”劳埃德银行集团(Lloyds Banking Group)首席安全官Matt Rowe表示。
企业在谁拥有AI风险的问题上也存在分歧。三分之一的公司设立了专门的AI职位,如首席AI官(chief AI officer),而其他公司则将其分配给技术部门或首席信息安全官(CISO)。
代理产生的是概率性输出(probabilistic output),即结果很可能正确但不能保证绝对正确。普华永道的建议是,当结果必须每次都正确时,代理的工作应通过其无法影响的控制环节,例如审查、审批工作流或由另一个系统进行的检查。
网络研讨会:弥合AI辅助交付中的问责制差距
Companies are putting more money into AI while naming attacks on AI systems as the threat they are least ready to face. PwC surveyed 3,934 business and technology leaders in 71 countries between May and July 2026. Half of the security and technology executives among them ranked such attacks in their top five preparedness gaps, ahead of every other threat on the list.
More than half of the leaders asked about AI-enabled attacks put three in their top five: botnets that AI directs at scale, adversarial attacks that subtly alter what an AI system sees to make it answer wrongly, and data poisoning, which slips misleading records into the data a model learns from. PwC’s assessment is that frontier AI models can now find unknown software flaws and exploit them with minimal human involvement.
Budgets are rising, backup plans are not
Of the security and finance leaders surveyed, 84 percent expect cyber budgets to grow, and AI is among the top priorities for the money. But only 39 percent of leaders asked have fully formalized continuity plans for cyber incidents, meaning documented ways to keep critical operations running or restore them after an attack. Nearly a quarter are not developing formal plans at all. PwC itself describes cyber incidents as a matter of when, not if.
The data under AI is thin
The average company has put three of seven data risk measures in place across the whole organization. Only about half have implemented data classification , which is the basic step of knowing what data is sensitive. PwC’s argument is that AI is only as trustworthy as the data beneath it, so if you are rolling out AI tools this year, check what data they can reach and how well it is protected.
Few will let AI act alone
On the defense side, fewer than a quarter of leaders would let AI agents , software that takes actions on its own, contain and fix attacks without human approval. Most would limit agents to low-risk actions or keep a person in charge. More than half named reliability and maturity of the technology as a top barrier.
“To be successful in the era of AI, we need to be able to defend at machine speed,” says Matt Rowe , chief security officer at Lloyds Banking Group.
Companies also split on who owns AI risk. A third have set up dedicated AI roles such as a chief AI officer, while others assign it to the technology function or the CISO.
Agents produce probabilistic output, meaning output that is likely right but not guaranteed. PwC’s advice is that when an outcome must be correct every time, the agent’s work should pass through a control it cannot influence, such as a review, an approval workflow, or a check by another system.
Webinar: Closing the accountability gap in AI-assisted delivery
| 刊期 | 得分 | 排名 | 结果 |
|---|---|---|---|
| 2026-10-04 | 6.35 | 70 | 入选 |
| 2026-10-03 | 7.14 | 71 | 未入选 |