
The “Global Digital Trust Insights 2027” report issued by PwC revealed that organizations are still far from reaching a unified model for distributing responsibility for artificial intelligence risks, despite the increase in spending on cybersecurity and the increased use of artificial intelligence in operations, as 29% believe that the responsibility falls on the responsibility of the IT leader, and 26% see it as the responsibility of an independent department for artificial intelligence, while artificial intelligence has become an increasing target for attacks, with half of security leaders indicating a lack of preparedness to confront it.
AI-generated summary
As the use of AI expands within organizations, risks are no longer just about what models or agents can do, but also about who bears responsibility when a security flaw occurs or systems take unexpected actions.
As the use of AI expands within organizations, risks are no longer just about what models or agents can do, but also about who bears responsibility when a security flaw occurs or systems take unexpected actions. The “Global Digital Trust Insights 2027” report issued by “PwC” shows that companies are still far from reaching a unified model for distributing this responsibility, despite the rise in spending on cybersecurity and the acceleration of the introduction of artificial intelligence into operations.
The survey, which included 3,934 business and technology leaders in 71 countries and regions, revealed that 84 percent of security and finance officials expect cybersecurity budgets to increase over the next 12 months, compared to 78 percent the previous year. 58 percent also included artificial intelligence among the top priorities for cyber spending, an indication of its transition from a tool for improving productivity to an essential element in protection and risk management strategies.
Who is responsible for AI risks?
One of the most prominent findings of the report is the lack of agreement within organizations about who is supposed to bear responsibility for artificial intelligence risks, especially with the rise of agent systems capable of taking actions and carrying out tasks with varying degrees of independence.
29 percent of participants said that responsibility should fall to the CIO, CTO, or technical function, while 26 percent believed it should fall to an independent AI leader or department. 17 percent chose the head of information security or cybersecurity teams, while 11 percent said that responsibility is unclear because it is distributed among more than one function within the organization.
In contrast, some organizations have already begun to create dedicated organizational roles, as the survey showed that 33 percent of them have appointed officials or created positions directly related to AI leadership, including executive positions or board-level roles.
But the fact that the issue has reached the highest levels does not mean that governance has become stable. Only 47 percent reported that cybersecurity has become a permanent item on the board of directors’ agenda, while PwC indicates that the spread of artificial intelligence imposes a greater need for clarity of accountability and determining who has the decision when an incident occurs or a failure in controls occurs.
Artificial intelligence is also a target for attacks
The paradox is not limited to the use of artificial intelligence as a defensive tool, as it has itself become an increasing target for attacks. Nearly half of security leaders say attacks targeting AI systems are among the threats they feel least prepared to address.
The risks highlighted in the report include attacks directed against models and proxy systems, in addition to tampering with data or influencing the behavior of systems. Data related to the study showed that 53 percent cited hacking into autonomous automated networks as a risk of concern, while 52 percent cited hostile attacks on artificial intelligence systems, and approximately the same percentage for data poisoning.
These risks gain greater weight as artificial intelligence moves from the role of assistant to systems that can access applications and data and take steps within workflows, which means that a weakness in permissions, identity, or governance may move from producing an incorrect answer to implementing an actual action within the organization.
Beware of independent agents
While plans to use AI for cyber defense are on the rise, organizations remain wary of granting agents full powers. The report showed that only 22 percent would agree to grant AI agents full autonomy to carry out defensive actions.
This caution, according to PwC, is linked to factors including trust in technology, accountability, and the lack of expertise capable of monitoring independent systems. In this context, the company believes that expanding reliance on artificial intelligence in security requires clear governance, human supervision, and mechanisms that define the limits of what the system can do without direct intervention.
This reflects a new equation within cybersecurity teams; Organizations want to benefit from the speed of artificial intelligence and its ability to analyze large amounts of data and respond to threats, but at the same time they are required to prevent the defense system itself from becoming a source of new risks.
Budgets are rising... but readiness is not complete
High budgets do not necessarily mean that institutions have reached an advanced level of readiness. According to the report, only 39 percent have a formal and fully implemented continuity plan that specifically addresses cyber risks, despite the expanding use of advanced artificial intelligence models.
Preparedness for future threats also remains uneven. In the field of quantum computing-resistant encryption, the report’s data showed that only 21 percent of organizations have already implemented security measures resistant to quantum threats, reflecting that a large part of the market is still in the early stages of preparing for this shift.
The numbers show that the increase in investment comes in parallel with the expansion of the scope of responsibilities. Security teams no longer only need to protect networks, data, and cloud services, they also need to protect models, training data, agents, and new digital identities operating within organizations.
From a defense tool to a governance file
PwC summarizes the shift by saying that artificial intelligence is now working on both sides of the cybersecurity equation. It expands the attack surface and creates new types of risks, but at the same time provides tools that can be used to detect, respond, and protect with higher degrees of automation. Therefore, the company believes that the actual value does not depend on adopting the technology, but rather on building the trust, governance, and human supervision necessary to use it responsibly.
As organizations prepare to increase spending, the question remains as to who gets to decide when an AI agent becomes able to access systems and data and take defensive or operational actions.
The survey numbers indicate that companies are starting to create new roles and mechanisms to answer this question, but the division of responsibility between technology, security, and AI leadership has not yet stabilized.

OpenAI has fired three researchers for violating policies for handling sensitive information, amid growing global concerns about the safety of artificial intelligence technologies and their potential risks to humanity.
SpaceX has launched a Google satellite with the aim of testing the operation of artificial intelligence devices in harsh space conditions. The project raises questions about expanding orbital infrastructure and the dangers of space debris.

Montenegrin authorities have extradited an Iranian national accused of participating in a hacking scheme to steal data from more than 150 American universities and companies worth more than $3 billion to the United States to face criminal charges, where Amir Barati, 40, is expected to face charges of wire fraud and computer fraud in the federal court for the Southern District of New York.

British inventor Percy Shaw was inspired by the reflection of car light in the eyes of a cat on a foggy night in 1933 to create reflective markers known as 'cat eyes', which are still used globally; Crowded.

Lenovo has launched the “AI Express” path to accelerate the deployment of artificial intelligence architecture in cooperation with NVIDIA. In another technical context, entrepreneur Sam Terris unveiled the “Freckle” phone for children, designed to promote independence away from social media platforms and digital addiction.

Entrepreneur Sam Terris launched the “Freckle” phone, which is intended for children aged 7-13 years and is free of social media to prevent digital addiction. In a separate context, Apple intends to enter the smart home market next October by launching a central control device and new updates.