Emerging Data Risks and Security Challenges from Enterprise AI Adoption
Enterprises are rapidly integrating artificial intelligence (AI) into their core operations, leading to a significant increase in both the scale and complexity of cybersecurity risks. Autonomous AI agents, once limited to providing suggestions, now act independently within enterprise systems, accessing sensitive data, executing transactions, and triggering downstream workflows without human oversight. These agents, often deployed by individual teams or embedded in third-party software, can inadvertently ingest confidential information, such as customer credit card data, even if the data is only briefly accessible. Unlike human users, AI agents lack contextual understanding and ethical judgment, acting continuously and at scale, which introduces a new category of 'Shadow AI' risk. Multimodal AI systems, which process multiple input streams to generate more human-like outputs, further expand the attack surface. Adversaries can exploit these systems by manipulating data inputs, such as subtly altering images or text, to deceive the AI and bypass security controls. Research has demonstrated that these attacks are not merely theoretical; adversarial manipulations can evade detection and cause significant harm, especially in critical sectors like defense, healthcare, and finance. Organizations are increasingly aware of the dangers posed by AI-augmented threats, including deepfakes and AI-driven social engineering, but many lag in implementing effective technical defenses. Surveys indicate that while a majority of firms have experienced deepfake or AI-voice fraud attempts, more than half have suffered financial losses as a result. Despite this, investment in detection and mitigation technologies remains inadequate, and many companies overestimate their preparedness. The surge in AI adoption is reflected in corporate disclosures, with over 70% of S&P 500 firms now reporting AI as a material risk, up from just 12% two years prior. Reputational and cybersecurity risks are the most frequently cited concerns, followed by legal and regulatory challenges as governments move to establish AI-specific compliance requirements. However, only a minority of corporate boards have formally integrated AI oversight into their governance structures, highlighting a gap between risk awareness and actionable governance. The lack of comprehensive frameworks for managing AI risk leaves organizations vulnerable to both technical and compliance failures. As AI becomes more deeply embedded in business processes, the need for robust governance, continuous education, and responsible-use frameworks becomes increasingly urgent. Security and governance leaders must adapt to this new frontier by developing strategies that address the unique risks posed by autonomous and multimodal AI systems. Failure to do so could result in significant financial, operational, and reputational damage as adversaries continue to exploit the evolving AI landscape.

Get ahead of threats like this
Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
How this story unfolded
6 events from the most recent confirmed update back to the earliest known activity.
Report says deepfake awareness is high but defenses remain weak
October 2025 reporting indicated that while organizations are increasingly aware of deepfake threats, their cyber defenses have not kept pace.
Researchers warn multimodal AI expands social engineering threats
Industry reporting in October 2025 highlighted multimodal AI as creating new opportunities for attackers to conduct more convincing social engineering attacks.
Industry reporting highlights shadow AI and agentic data-access risks
Security industry coverage in October 2025 drew attention to shadow AI and agentic access as an emerging frontier of enterprise data risk.
Material AI risk disclosures surge among S&P 500 companies
By 2025, more than 70% of S&P 500 public firms were disclosing material AI risks, with reputational, cybersecurity, legal, and regulatory concerns cited as key issues.
PwC survey finds limited formal AI board oversight
PwC's 2025 survey found that only 35% of corporate boards had formal AI oversight, indicating that governance has lagged behind enterprise AI deployment.
S&P 500 firms begin disclosing material AI risks at low levels
In 2023, about 12% of S&P 500 public companies disclosed material AI risks, establishing a baseline before broader enterprise AI adoption accelerated.
Related entities
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Sources
4 references tracked. Mallory keeps watching after this page renders.
Shadow AI: Agentic Access and the New Frontier of Data Risk
securityboulevard.com
Open sourceMultimodal AI, A Whole New Social Engineering Playground for Hackers
securityboulevard.com
Open sourceDeepfake Awareness High at Orgs, But Cyber Defenses Badly Lag
darkreading.com
Open sourceAI risk disclosures in enterprises spike, report finds
scworld.com
Open sourceSee the full picture, correlated to your attack surface.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.


