AI cybersecurity risks top company worries, Arctic Wolf says
Arctic Wolf says AI now leads cyber concerns for about one-third of firms, even as malware and credential theft remain active threats.
By Wei-Lin Zhao · AI Correspondent
· 3 min read
AI cybersecurity risks have moved to the top of corporate security concerns, with about one-third of organizations naming AI as their leading worry, according to a Tuesday report from Arctic Wolf. The security firm warned that executive focus on AI could pull attention away from more common problems such as malware, credential theft and cloud misconfigurations.
Arctic Wolf’s annual AI and cybersecurity trends report found that concern over those traditional attack paths fell from 2025 levels. The firm said that shift may leave companies less prepared for the threats they are most likely to face, even as they build plans for AI-related risks.
What does Arctic Wolf's AI cybersecurity report say?
Arctic Wolf said companies are trying to address AI as both a new risk and a defensive tool. Nearly half of surveyed organizations said they were in early phases of adding AI to their cybersecurity programs, while 22% said they had rolled it out in limited ways and 34% described their deployments as mature.
The report also points to a gap between confidence and outcomes. Sixty-three percent of organizations said they had suffered at least one cybersecurity incident during the prior 12 months. Another 29% said they were confident they had not had an incident.
Despite that incident rate, 53% of business leaders surveyed said they were highly confident that their security teams could keep pace with evolving threats, and 43% said they were somewhat confident. Arctic Wolf said confidence was higher among organizations that had been hit: 57% of leaders at those companies said they were very confident in their security personnel, compared with 47% at organizations that reported no incident.
The incidents described in the report were not limited to short interruptions. Nearly half of affected businesses said they lost at least two weeks of productivity, and about one in 10 said disruptions lasted at least two quarters.
Where are companies using AI in security?
Companies told Arctic Wolf they expect AI to help human security teams across core tasks, including threat identification, context gathering and reducing false-positive alerts. Majorities of respondents said AI would eventually outperform humans in those areas.
That optimism does not extend evenly to autonomous systems. Arctic Wolf found that blocking malicious IP addresses and domains was the only task a majority of companies allowed AI agents to perform. Respondents cited several reasons for limiting agentic AI, including lack of human judgment, occasional inaccuracy and privacy risks tied to unsupervised data access.
For security vendors and enterprise buyers, the report shows a market that wants automation but still draws a line around autonomous action. That tension is likely to shape how AI security products are packaged, approved and governed inside large organizations.
Arctic Wolf based the report on a survey of 1,350 IT and security leaders across 13 industries in the U.S. and 17 other countries.
This story draws on original reporting from CIO Dive.