Gartner warns AI rollouts expose firms to security risks
As enterprises rush to deploy artificial intelligence, security analysts warn that many organizations are unprepared for critical vulnerabilities like data leaks and rising technical debt.

Enterprises are rapidly integrating artificial intelligence into their daily workflows, but security analysts warn that these organizations remain highly vulnerable to both internal and external threats. According to Pete Shoard, chief of research for cybersecurity at Gartner, businesses are simply not ready for the unique security challenges posed by AI. A primary concern is the accidental leakage of sensitive corporate data to public large language models or public code repositories like GitHub. Shoard highlighted that a major immediate risk involves developers uploading hard-coded secrets to GitHub through "vibe-coded" applications, which can grant malicious actors an easy entry point into corporate networks.
To combat these vulnerabilities, organizations are transitioning from reactive threat detection to proactive attack surface management. This approach involves simulating potential attack scenarios to identify and patch weaknesses before hackers can exploit them. Erik Nost, a senior analyst at Forrester, noted that AI is currently augmenting how security vendors analyze threat signals and how customers interact with security data. While major cybersecurity firms like Palo Alto Networks and CrowdStrike dominate the market, specialized vendors are also gaining traction. For instance, Tenable and Rapid7 focus on network monitoring, while Wiz—which Google acquired in March—specializes in cloud monitoring. Some practitioners are even deploying honeypot technologies like Thinkst Canary to lure and study attackers.
The security gap is particularly acute for small and medium-sized businesses. Jack Gold, principal analyst at J. Gold Associates, pointed out that smaller firms often lack the internal controls or the budget required to hire expensive security firms like Mandiant or CrowdStrike. Furthermore, the rapid creation of unmanaged AI agents is generating significant technical debt, creating even more potential entry points for attackers. For security practitioners, this shifting landscape means that automated threat detection must be paired with careful, manual remediation and patching, rather than relying on automated fixes that could disrupt critical business systems.
This is our own summary of reporting by Computerworld AI



