AI Emerges as the New Insider Threat: Thales Releases the 2026 Data Threat Report
好的,我现在需要帮用户总结一篇文章的内容,控制在100字以内。用户的要求是直接写描述,不需要特定的开头。首先,我得仔细阅读文章内容,找出主要观点。 文章标题是“AI成为新的内部威胁:Thales发布2026数据威胁报告”。内容提到AI已经深入到各个行业,不再是创新工具,而是主要的安全威胁。61%的组织认为AI是最大的数据安全风险。AI系统被当作可信的内部人员,拥有广泛的数据访问权限,但缺乏足够的控制和监督。 接下来,文章指出数据可见性和加密方面的差距暴露了组织的风险。只有34%的组织知道所有数据的位置,47%的云敏感数据未加密。此外,身份认证成为主要攻击面,凭证盗窃是云攻击的主要手段。外部威胁方面,AI驱动的深度伪造攻击和虚假信息损害了声誉。 最后,尽管30%的组织增加了专门的AI安全预算,但仍有53%依赖现有资金模型。文章强调需要架构转变以应对AI带来的安全挑战。 总结时要涵盖AI作为内部威胁、数据安全问题、身份攻击面、外部威胁以及投资情况这几个关键点。控制在100字以内,并且语言要简洁明了。 </think> 2026年Thales数据威胁报告显示,人工智能已成为主要数据安全风险,61%的组织将其列为首要威胁。AI系统被赋予广泛访问权限,被视为“可信内部人员”,但缺乏足够控制和监督。身份认证成主要攻击面,凭证盗窃频发;数据可见性与加密不足导致暴露风险;AI驱动的深度伪造与虚假信息加剧外部威胁。尽管部分企业增加AI安全预算,但整体投资仍需优化以应对快速演变的安全挑战。 2026-3-3 15:0:4 Author: securityboulevard.com(查看原文) 阅读量:6 收藏

AI Emerges as the New Insider Threat: Thales Releases the 2026 Data Threat Report
madhav

Over the past year, I’ve watched AI move to operational reality across nearly every industry we work with. The conversation is no longer about whether AI will transform business. It already has.

AI Emerges as the New Insider Threat

Over the past year, I’ve watched AI move to operational reality across nearly every industry we work with. The conversation is no longer about whether AI will transform business. It already has.

What concerns me, and what this year’s Thales Data Threat Report confirms, is how profoundly it is transforming risk.

The report’s findings send a clear message: AI has moved from an innovation driver to a primary security concern.

According to the report, 61% of organizations now cite AI as their top data security risk. At the same time, 70% of IT and security professionals say the pace of AI-driven transformation is their most significant security challenge.

AI is embedded in workflows, connected to cloud platforms, accessing sensitive data, and increasingly acting with autonomy. However, AI does not introduce entirely new weaknesses. It scales existing ones.

And security teams are struggling to keep up.

AI Is Acting Like a Trusted Insider

One of the most striking findings in this year’s report is how organizations are treating AI systems.

AI tools and agents are increasingly granted broad, automated access to enterprise data, often with fewer controls and less oversight than human users.

What stands out to me this year is how quickly AI has shifted from being viewed as a productivity enhancer to being treated like a trusted insider. Insider risk is no longer just about people. It now includes automated systems that are being trusted too quickly and often too broadly.

When identity governance, access policies, or data protections are weak, AI does not simply inherit those weaknesses; it amplifies them at machine speed.

Visibility and Encryption Gaps Are Exposing Organizations

This year’s findings highlight a troubling reality: many organizations lack foundational data visibility and protection.

  • Only 34% know where all their data is stored
  • Just 39% can fully classify their data
  • 47% of sensitive cloud data remains unencrypted

As AI systems ingest, process, and act on enterprise information across cloud and SaaS environments, these visibility and encryption gaps create significant exposure.

AI increases data discoverability. Without strong data governance and encryption, that discoverability becomes a risk.

I firmly believe that organizations that succeed in this next phase will treat data security as an enabler of innovation, not a barrier.

Identity Has Become the Primary Attack Surface

As AI systems depend on API keys, tokens, and machine credentials, identity is emerging as the most critical control layer.

The report finds that identity and access management is now ranked as the top security skills priority, ahead of cloud and application security.

Credential theft was cited as the leading attack technique against cloud management infrastructure by 67% of organizations that experienced cloud attacks.

In an AI-driven environment, compromising identity is often the fastest route to sensitive data.

In my view, this shift elevates identity governance from a technical discipline to a board-level priority.

AI-Powered Threats Are Escalating Business Impact

Besides expanding internal risk, AI is reshaping external threats.

  • Nearly 60% of organizations report experiencing deepfake-driven attacks
  • 48% report reputational damage linked to AI-generated misinformation

AI-powered impersonation, misinformation, and automated attack techniques are increasing the speed, scale, and sophistication of cyber threats.

Security teams are no longer protecting infrastructure alone. They are protecting trust, brand integrity, and digital authenticity.

Investment Is Growing — But the Model Is Still Evolving

I’m encouraged to see organizations responding to these threats.

  • 30% now allocate dedicated AI security budgets, up from 20% last year
  • However, 53% are still relying on existing security funding models

The data makes one thing clear: continuous visibility, classification, and protection are no longer optional. They are foundational requirements for operating safely in an AI-driven environment.

The real problem is not investment; it’s inefficient investment. AI security cannot be treated as an add-on. It requires an architectural shift toward enterprise-wide visibility, strong encryption, identity governance, and data security posture management.

2026 is a Defining Year for Data Security

For me, the key takeaway of the 2026 Thales Data Threat Report is that it reveals a pivotal transition:

  • AI is becoming a trusted insider.
  • Identity is the primary attack surface.
  • Data remains the ultimate target.

The organizations that succeed will be those that build security architectures designed for autonomous systems, not just human users.

We already know AI will continue to reshape business.

The real question is whether our security strategies are evolving at the same pace.

Download the 2026 Thales Data Threat Report

Explore the full findings, global insights, and expert analysis in the 2026 Thales Data Threat Report and discover how leading organizations are adapting their security strategies to manage AI-driven risk.

Schema

{
“@context”: “https://schema.org”,
“@type”: “BlogPosting”,
“mainEntityOfPage”: {
“@type”: “WebPage”,
“@id”: “https://cpl.thalesgroup.com/blog/cybersecurity/ai-insider-threat-2026-data-threat-report”
},
“headline”: “2026 Data Threat Report: AI Emerges as Insider Threat | Thales”,
“description”: “AI is now the top data security risk. Explore key findings from the 2026 Thales Data Threat Report on identity, encryption gaps, and AI-driven threats.”,
“image”: “”,
“author”: {
“@type”: “Person”,
“name”: “Todd Moore”,
“url”: “https://cpl.thalesgroup.com/blog/author/tmoore”
},
“publisher”: {
“@type”: “Organization”,
“name”: “Thales Group”,
“description”: “The world relies on Thales to protect and secure access to your most sensitive data and software wherever it is created, shared, or stored. Whether building an encryption strategy, licensing software, providing trusted access to the cloud, or meeting compliance mandates, you can rely on Thales to secure your digital transformation.”,
“url”: “https://cpl.thalesgroup.com”,
“logo”: “https://cpl.thalesgroup.com/sites/default/files/content/footer/thaleslogo-white.png”,
“sameAs”: [
“https://www.twitter.com/ThalesCloudSec”,
“https://www.linkedin.com/company/thalescloudsec”,
“https://www.youtube.com/ThalesCloudSec”
] },
“datePublished”: “2025-03-03”,
“dateModified”: “2025-03-03”
}

studio

*** This is a Security Bloggers Network syndicated blog from Thales CPL Blog Feed authored by madhav. Read the original post at: https://cpl.thalesgroup.com/blog/cybersecurity/ai-insider-threat-2026-data-threat-report


文章来源: https://securityboulevard.com/2026/03/ai-emerges-as-the-new-insider-threat-thales-releases-the-2026-data-threat-report/
如有侵权请联系:admin#unsafe.sh