Organizations have a trust problem with artificial intelligence. They're deploying it anyway.
That contradiction sits at the heart of new research from Onapsis, which found that enterprises are rapidly embedding AI into the business applications that run finance, supply chains, procurement, manufacturing, and human resources — even as security leaders openly question whether their organizations can protect those systems from AI-powered attacks.
The full report:

The findings point to what may become one of the defining cybersecurity challenges of the next several years: enterprises are accumulating AI security debt faster than they are building the controls to manage it.
According to the survey, 22% of cybersecurity leaders say their organizations have already experienced a security incident in which attackers used AI to exploit a critical business platform.
Yet despite those experiences, AI adoption inside enterprise resource planning (ERP) environments continues to accelerate.
The survey found that 86% of organizations have already integrated — or expect to integrate in the near future — AI directly into their ERP code.
That would be less concerning if security leaders expressed confidence in their defenses. Instead, the survey paints the opposite picture.
Nearly 69% of respondents said they are not confident their organizations could detect an AI-based attack, while 70% said they have only some trust — or no trust at all — in AI's ability to help secure their most business-critical data.
These sentiments come amid recent news that an OpenAI agent escaped its lab environment and breached Hugging Face. OpenAI confirmed this week that the autonomous agent didn't stop after compromising Hugging Face's infrastructure. It used exposed credentials to access four additional third-party services as it worked toward completing its ExploitGym benchmark, using those services to stage data, conceal its activity, and continue pursuing its objective.
More on the OpenAI/Hugging Face incident:


The uncomfortable march forward
Even internally, organizations appear divided over how much access AI should receive.
Security teams were the most likely to resist granting AI access to sensitive enterprise data, cited by 41.4% of respondents. IT teams followed at 20.7%, underscoring that the greatest skepticism isn't coming from the business—it is coming from the people responsible for protecting the organization's most valuable information.
The disconnect illustrates a broader reality facing enterprise security teams.
Organizations no longer deploy AI only through standalone chatbots or productivity assistants. Increasingly, AI agents are becoming embedded directly into the systems responsible for approving invoices, processing payroll, managing inventory, forecasting demand, and orchestrating supply chains. Those systems often contain an organization's most sensitive operational and financial data.
As AI becomes another application with privileged access, the attack surface changes dramatically.
Traditional enterprise security programs were designed around human identities, service accounts, APIs, and application integrations. AI agents introduce something fundamentally different: software capable of making decisions, chaining actions across multiple systems, accessing sensitive data, and initiating additional workflows with minimal human oversight.
If attackers can manipulate those agents — or the identities and permissions behind them — the consequences extend well beyond a single compromised chatbot.
Acceptable risk
The Onapsis research suggests many organizations recognize that risk but have accepted it as part of the race to deploy AI.
That growing gap between deployment and preparedness is what security leaders increasingly describe as AI security debt.
Like technical debt, security debt accumulates when organizations prioritize speed over resilience. Every new AI integration connected to a business-critical application introduces additional identities, permissions, APIs, and decision paths that security teams must understand, monitor, and govern. If those controls are added later — or not at all — the risk compounds over time.
The survey suggests many organizations are already operating in that reality.
While AI promises productivity gains across finance, operations, procurement, and customer service, relatively few organizations appear confident they could recognize an AI-enabled attack once it begins.
CISO balancing act
For CISOs, that presents a difficult balancing act.
Business leaders increasingly expect AI initiatives to move quickly, especially inside ERP platforms where automation can produce measurable operational gains. Security leaders, meanwhile, are left trying to secure technologies whose capabilities — and attack techniques — are evolving faster than traditional governance models.
The result is an uncomfortable paradox.
Organizations know AI-powered attacks are no longer theoretical. More than one in five have already experienced one targeting a critical business platform. Yet most are still accelerating AI deployments into the very systems they admit they are not fully prepared to defend.
The question facing enterprises is no longer whether AI belongs inside business-critical applications.
It is whether security programs can mature quickly enough to keep pace with the speed of AI adoption before today's security debt becomes tomorrow's breach.


