Enterprise Adoption2 min read

AI Newcomers Rarely Use It For Cybersecurity, KPMG Finds

By , Senior AI ConsultantPublished

KPMG's global survey of 2,131 senior leaders finds that only 8% of companies just starting with AI use it to defend against cyberattacks, compared with 58% of companies with years of AI experience, showing security trust grows with time, not with access to the tool.

KPMG just published its latest quarterly AI survey, and it contains a number every business owner should sit with for a second. Among companies still in the early, experimental phase of using AI, only 8 percent have deployed AI tools to help defend against cyberattacks. Among companies that have used AI long enough to see clear returns on their investment, that figure is 58 percent.

That is not a small gap. It means companies furthest along with AI are more than seven times as likely to use it for security as companies just getting started. Comfort with AI for defense does not come from buying the tool, it comes from spending time with it.

The pattern holds up elsewhere too. Companies new to AI mostly use it to watch their systems and not much else, with a quarter of them limiting AI to monitoring alone. Experienced companies spread AI across far more security tasks and put more money behind it, with 71 percent spending part of their AI budget on cybersecurity, compared with 36 percent of newcomers.

Here is the part that should change how you think about AI adoption generally. Companies with the most AI experience are also more likely to say cybersecurity concerns are slowing down their AI plans, 50 percent of them compared with 34 percent of newer users. This is not companies getting cold feet.

It is companies who understand the technology well enough to see where the real risks sit, so confidence and caution rise together instead of trading off.

This matches what is happening outside the survey too. Attackers are already using AI to write more convincing phishing emails and to produce fake voice and video calls that trick employees into wiring money or handing over passwords. Security researchers have tracked a sharp rise in both over the past year.

That threat is moving faster than most companies' old defenses were built for, which is why 86 percent of companies KPMG surveyed said they were reworking how they run cybersecurity specifically because AI has sped up the pace of attacks.

The survey also shows how companies are trying to keep their own AI systems from causing damage. More than half now run a layer of technical guardrails around their AI, covering who can access data, whether AI outputs get checked, and how identity and permissions are managed. Controls without a named person responsible for them are just rules on paper, KPMG argues.

Just over half of companies have now assigned a senior executive to own AI decisions, and roughly one in four have put that responsibility directly on the CEO or executive committee.

The other trend worth watching is how fast AI agents, systems that can take actions on their own rather than just answer questions, are spreading inside companies. Over a third of companies now report meaningful employee use of AI agents, up from a quarter earlier in the year. Agents that act on their own create new entry points for something to go wrong, which is exactly why accountability matters more now than it did a year ago.

If your company is still early with AI, the takeaway is not to slow down. It is to stop treating security as an afterthought for later in the project. The data says the opposite happens: the longer you wait, the more exposed you likely are, and the companies furthest ahead treat security and accountability as part of the AI rollout from day one, not something bolted on afterward.


STAY INFORMED

Get AI intelligence like this delivered to your inbox.

Free forever · Unsubscribe anytime


You May Also Find Valuable