AI: The New Insider Threat Facing Organizations
25.2.2026 09:00:00 CET | Business Wire | Press release
Thales 2026 Data Threat Report Finds 70% of Organizations Rank AI as Top Data Security Risk As AI systems gain broader access to enterprise data across environments, organizations must treat data visibility and encryption as core security elements. AI-enabled deepfakes and misinformation are increasing the effectiveness of identity-based attacks. Today, credential theft is the leading attack technique against cloud infrastructure (67%). Nearly 60% of companies report deepfake-driven incidents, and 48% experience damage from AI-generated misinformation Investment in AI security is growing, with 30% of companies allocating dedicated budgets; however, 53% are still relying on existing security budget
According to the Thales 2026 Data Threat Report, organizations across various markets including automotive, energy, finance and retail say the rapid pace of AI-driven transformation is now their biggest security challenge. Based on the report’s research, conducted by S&P Global 451 Research, 61% cite AI as their top data security risk. The concern is not only about malicious AI, but about the access it is being granted as it shifts from a tool to a trusted insider.
This press release features multimedia. View the full release here: https://www.businesswire.com/news/home/20260225599723/en/

©Thales
As enterprises embed AI into workflows, analytics, customer service, and development pipelines, these systems are being granted broad, automated access to enterprise data, often with fewer controls than those applied to human users in a corporate environment.
“Insider risk is no longer just about people. It is also about automated systems that have been trusted too quickly,” says Sebastien Cano, Senior Vice President, Cybersecurity Products at Thales. “When identity governance, access policies, or encryption are weak, AI can amplify those weaknesses across corporate environments far faster than any human ever could.”
Visibility Gaps Are Widening as AI Expands Data Reach
The report reveals a troubling disconnect between AI adoption and data control. Only 34% of organizations know where all their data resides, whatever the level of criticality, and just 39% can fully classify it. Meanwhile, nearly half (47%) of sensitive cloud data remains unencrypted.
As AI systems ingest and act on data across cloud and SaaS environments, limited visibility makes enforcing least-privilege access increasingly difficult, that is granting only the strictly necessary access rights. This increases the extent of exposure if credentials are compromised.
Identity infrastructure is now the primary attack surface. Credential theft remains the leading attack technique against cloud management infrastructure, cited by 67% of organizations experiencing cloud attacks. At the same time, 50% rank secrets management among their top application security challenges, reflecting the growing complexity of governing machine identities, API (interfaces de programmation applicative) keys, and tokens at scale.
AI Is Powering More Convincing Attacks
While organizations race to adopt AI, attackers are doing the same. Nearly 60% of companies report experiencing deepfake-driven attacks, and 48% report reputational damage tied to AI-generated misinformation or impersonation campaigns.
As AI introduces new risks, it also increases existing ones. Human error already contributes to 28% of breaches, and with automation layered on top, small mistakes can scale faster and spread wider.
Security Investment Is Shifting, But Not at the Pace of the new Risks
While organizations recognize the need to adapt, investment is not keeping pace with the rapid expansion of AI-driven access and automation. 30% now dedicate specific budgets to AI security, reflecting growing awareness. However, the majority (53%) still depend on traditional security programs built primarily for human users and perimeter-based controls. As machines increasingly authenticate, access, and act autonomously, many security strategies have yet to adjust to this shift in operating models.
“As AI becomes deeply embedded into enterprise operations, continuous data visibility and protection are no longer optional,” said Eric Hanselman, Chief Analyst at S&P Global 451 Research. “Organizations must treat data security strategy as foundational to innovation, not separate from it.”i
Trust Must Evolve as Machines Gain Access
AI is not replacing traditional threats; rather, it is intensifying them by increasing their speed, scale, and reach. As automated systems gain broader access to enterprise data, organizations must rethink identity, encryption, and data visibility as core infrastructure. The organizations that embed strong governance into their AI strategies will be better positioned to innovate securely and avoid turning AI into their newest insider threat.
For more information, please download the full report and join our webinar hosted by Eric Hanselman, Chief Analyst at S&P Global 451 Research.
About Thales
Thales (Euronext Paris: HO) is a global leader in advanced technologies for the Defence, Aerospace, and Cyber & Digital sectors. Its portfolio of innovative products and services addresses several major challenges: sovereignty, security, sustainability and inclusion.
The Group invests more than €4 billion per year in Research & Development in key areas, particularly for critical environments, such as Artificial Intelligence, cybersecurity, quantum and cloud technologies.
Thales has more than 83,000 employees in 68 countries. In 2024, the Group generated sales of €20.6 billion.
| |
i Thales 2026 Data Threat Report, 2026, commissioned by Thales and conducted by S&P Global 451 Research | |
View source version on businesswire.com: https://www.businesswire.com/news/home/20260225599723/en/

Subscribe to releases from Business Wire
Subscribe to all the latest releases from Business Wire by registering your e-mail address below. You can unsubscribe at any time.
Latest releases from Business Wire
David Hagan, Dean and Pegasus Professor at CREOL, The College of Optics and Photonics, Will Serve as Vice President of SPIE26.8.2026 05:00:00 CEST | Press release
Newly elected SPIE board members bring distinct backgrounds to optics and photonics community David Hagan has been elected to serve as the 2027 Vice President of SPIE, the international society for optics and photonics. He will serve as President-Elect in 2028, and as the Society’s President in 2029. The SPIE Board of Directors is influential in the scientific community, establishing policy and strategy and conducting activities of interest to SPIE Members. This press release features multimedia. View the full release here: https://www.businesswire.com/news/home/20260825934622/en/ Top row, from left to right: David Hagan, Jim McNally, Mark Clampin. Bottom row, from left to right: Marla Dowell, Jana Kainerstorfer, Katie Schwertz The 2026 SPIE President, Julie Bentley, professor of optics at the University of Rochester, made the new electees announcement at the Annual General Meeting of the Society on 25 August during SPIE Optics + Photonics. Terms begin on 1 January 2027. In addition to
FORTÉ Acquires Vega Global, APAC's Largest Systems Integrator, Expanding Global Reach26.8.2026 03:00:00 CEST | Press release
With new presence in Asia, FORTÉ serves customers in more than 70 cities worldwide – the largest global footprint in the industry FORTÉ, the leader in communication and collaboration solutions designed for the modern workplace, today announced its acquisition of Vega Global, APAC’s largest systems integrator and a leading provider of workplace technology and audiovisual solutions serving corporate, education, government and other market segments. With this acquisition, FORTÉ adds to its international presence, including established office locations in Hong Kong, Mainland China, India, Japan, Taiwan, Thailand, Singapore, Korea, Vietnam, Australia, Philippines, Malaysia, Macau, New Zealand, Indonesia, and United Arab Emirates. With its headquarters in Minneapolis, Minn., FORTÉ also has operations in the U.S., Ireland, Germany, Sweden, the United Kingdom, and Mexico. “Multinational organizations need strategic partners who can deliver consistent communication and collaboration experiences
Access Advance Launches Exploration Phase for an AV1/AV2 Device and Software Patent Pool, Invites Participation of Potential Licensors26.8.2026 02:00:00 CEST | Press release
Access Advance LLC announced today that in conjunction with the recent release of the AV2 video codec specification, it has launched the exploratory phase for a new patent pool covering devices and software implementing the AV2 video codec, as well as its predecessor AV1. During this exploratory phase, Access Advance will engage with market participants to seek their input, including holding pool formation discussions with potential licensors to gather their feedback on the scope, structure, and terms of a prospective program. All patent owners with a good-faith belief that they own or control AV1 and/or AV2 essential patents are invited to participate in the pool formation discussions. AV1 adoption is being driven largely by members of the Alliance for Open Media (“AOM”). AOM members such as Google, Meta, and Netflix increasingly utilize AV1 to deliver video, and adoption now spans smart TVs, streaming media players, mobile devices, web browsers, and chipsets. AV2, AOM’s successor to
Lattice to Showcase Industrial FPGA Innovations at FPGAWorld Conference 202625.8.2026 22:00:00 CEST | Press release
Lattice Semiconductor (NASDAQ: LSCC), the low power programmable and platform firmware leader, today announced its exhibition plan for the upcoming FPGAWorld Conference 2026, taking place on Sept. 8, 2026, in Stockholm, Sweden. As part of the event, Lattice will deliver technical presentations and host a demo showcase focused on how its low power FPGA solutions are advancing Industrial IoT and sensor bridging applications. Who: Lattice Semiconductor What / When (GMT+2): Tuesday, Sept. 8, 2026 Lattice Demo Showcase Presentations (Track: 12:20 – 13:35, Room Brave 05) “Solving Your Power Puzzle: Lattice FPGAs’ Path to Uncompromised Low Power” “Practical Security Fundamentals for FPGA Engineers” Where: AFRY, Frösundaleden 2A, 169 70 Solna, Sweden The FPGAWorld Conference is an international forum for researchers, engineers, teachers, students, and hackers. It covers topics such as complex analog/digital/software FPGA SoC systems, FPGA/ASIC-based products, educational and industrial cases,
France Becomes First Official Participant at Expo 2030 Riyadh25.8.2026 19:40:00 CEST | Press release
France is the first country to officially sign its Participation Contract for Expo 2030 Riyadh, a major milestone in its preparations and growing international momentum. The signing took place on the sidelines of the visit to France by His Royal Highness Prince Mohammed bin Salman bin Abdulaziz Al Saud, Crown Prince and Prime Minister. This press release features multimedia. View the full release here: https://www.businesswire.com/news/home/20260825634516/en/ The ceremony in Paris was attended by H.H. Prince Faisal bin Farhan Al Saud, Minister of Foreign Affairs of the Kingdom of Saudi Arabia, and Dimitri S. Kerkentzes, Secretary General of the BIE. The Participation Contract was signed by Talal Al-Marri, Chief Executive Officer of Expo 2030 Riyadh, and Jacques Maire, Chairman of the Compagnie Française des Expositions (COFREX). The agreement formally establishes France’s participation in Expo 2030 Riyadh, providing the framework for its presence throughout the six-month event. It spec
In our pressroom you can read all our latest releases, find our press contacts, images, documents and other relevant information about us.
Visit our pressroom