BSI: Only every tenth company in Germany is prepared for AI attacks
Only one in ten companies has established protective measures, although one in six has already fallen victim to AI attacks.
Quick Look
- According to a BSI and TÜV study, only eleven percent of German companies are prepared for AI-supported cyber attacks.
- The most common threats are phishing emails and automated attack scripts.
AI-generated summary
Why It Matters
A study by the TÜV Association and the BSI surveyed over 500 larger German companies on the topic of AI security.
The Federal Office for Security and Information Technology, together with TÜV, published a study that examined German companies for AI defense: The results are worrying.
Berlin. According to a study, only a few companies in Germany are sufficiently prepared for cyber attacks using artificial intelligence. Only around one in ten companies have established protective measures, although one in six has already registered an incident or attempted fraud in the past twelve months. This emerged from a study by the TÜV Association and the Federal Office for Information Security (BSI), for which over 500 larger companies were surveyed.
The most common form of attack, in 90 percent of cases, is deceptively genuine phishing emails, in which attempts are made to obtain passwords, bank details or other data. In addition, 40 percent named automated attack scripts and eleven percent named deepfakes, i.e. fake audio or video recordings.
Nevertheless, according to the study, most companies are inadequately prepared. Only eleven percent of companies that use AI or plan to do so have specific processes in place to deal with AI-related security incidents.
The president of the TÜV association, Dirk Stenkamp, warned that the recorded incidents could only be the “tip of the iceberg”. At the same time, the potential of artificial intelligence in cyber defense is far from being exhausted.
“This creates an open flank, because while attackers become faster and more targeted with AI, cyber defense must also catch up technologically,” said Stenkamp. Independent audits could also close a trust gap in the security of AI applications.
“Anyone who uses AI must also know where its protective mechanisms fail.”
BSI Vice President Thomas Caspers emphasized that there are risks even for companies without their own AI use. “It is important to understand that even companies that do not use AI themselves are at risk from AI-supported cyberattacks,” said Caspers.
An intensive examination of the topic is therefore worthwhile for all companies. Companies should also consider AI as a crucial measure for their own cybersecurity. “Anyone who uses AI also needs to know where its protective mechanisms fail – this includes targeted tests and monitoring during ongoing operations.”
Around 49 percent of companies are using AI, and another nine percent are planning to do so within the next twelve months. About 42 percent do not use AI and do not plan to do so.
Open Questions
- Which specific sectors are most affected?
- How does politics react to the security gaps?





