Business Wire

AI: The New Insider Threat Facing Organizations

25.2.2026 10:00:00 EET | Business Wire | Press release

Share

According to the Thales 2026 Data Threat Report, organizations across various markets including automotive, energy, finance and retail say the rapid pace of AI-driven transformation is now their biggest security challenge. Based on the report’s research, conducted by S&P Global 451 Research, 61% cite AI as their top data security risk. The concern is not only about malicious AI, but about the access it is being granted as it shifts from a tool to a trusted insider.

This press release features multimedia. View the full release here: https://www.businesswire.com/news/home/20260225599723/en/

©Thales

As enterprises embed AI into workflows, analytics, customer service, and development pipelines, these systems are being granted broad, automated access to enterprise data, often with fewer controls than those applied to human users in a corporate environment.

“Insider risk is no longer just about people. It is also about automated systems that have been trusted too quickly,” says Sebastien Cano, Senior Vice President, Cybersecurity Products at Thales. “When identity governance, access policies, or encryption are weak, AI can amplify those weaknesses across corporate environments far faster than any human ever could.”

Visibility Gaps Are Widening as AI Expands Data Reach

The report reveals a troubling disconnect between AI adoption and data control. Only 34% of organizations know where all their data resides, whatever the level of criticality, and just 39% can fully classify it. Meanwhile, nearly half (47%) of sensitive cloud data remains unencrypted.

As AI systems ingest and act on data across cloud and SaaS environments, limited visibility makes enforcing least-privilege access increasingly difficult, that is granting only the strictly necessary access rights. This increases the extent of exposure if credentials are compromised.

Identity infrastructure is now the primary attack surface. Credential theft remains the leading attack technique against cloud management infrastructure, cited by 67% of organizations experiencing cloud attacks. At the same time, 50% rank secrets management among their top application security challenges, reflecting the growing complexity of governing machine identities, API (interfaces de programmation applicative) keys, and tokens at scale.

AI Is Powering More Convincing Attacks

While organizations race to adopt AI, attackers are doing the same. Nearly 60% of companies report experiencing deepfake-driven attacks, and 48% report reputational damage tied to AI-generated misinformation or impersonation campaigns.

As AI introduces new risks, it also increases existing ones. Human error already contributes to 28% of breaches, and with automation layered on top, small mistakes can scale faster and spread wider.

Security Investment Is Shifting, But Not at the Pace of the new Risks

While organizations recognize the need to adapt, investment is not keeping pace with the rapid expansion of AI-driven access and automation. 30% now dedicate specific budgets to AI security, reflecting growing awareness. However, the majority (53%) still depend on traditional security programs built primarily for human users and perimeter-based controls. As machines increasingly authenticate, access, and act autonomously, many security strategies have yet to adjust to this shift in operating models.

“As AI becomes deeply embedded into enterprise operations, continuous data visibility and protection are no longer optional,” said Eric Hanselman, Chief Analyst at S&P Global 451 Research. “Organizations must treat data security strategy as foundational to innovation, not separate from it.”i

Trust Must Evolve as Machines Gain Access

AI is not replacing traditional threats; rather, it is intensifying them by increasing their speed, scale, and reach. As automated systems gain broader access to enterprise data, organizations must rethink identity, encryption, and data visibility as core infrastructure. The organizations that embed strong governance into their AI strategies will be better positioned to innovate securely and avoid turning AI into their newest insider threat.

For more information, please download the full report and join our webinar hosted by Eric Hanselman, Chief Analyst at S&P Global 451 Research.

About Thales

Thales (Euronext Paris: HO) is a global leader in advanced technologies for the Defence, Aerospace, and Cyber & Digital sectors. Its portfolio of innovative products and services addresses several major challenges: sovereignty, security, sustainability and inclusion.

The Group invests more than €4 billion per year in Research & Development in key areas, particularly for critical environments, such as Artificial Intelligence, cybersecurity, quantum and cloud technologies.

Thales has more than 83,000 employees in 68 countries. In 2024, the Group generated sales of €20.6 billion.

i Thales 2026 Data Threat Report, 2026, commissioned by Thales and conducted by S&P Global 451 Research

View source version on businesswire.com: https://www.businesswire.com/news/home/20260225599723/en/

Contacts

Press contact
Thales, Media Relations
Security & Cybersecurity
Marion Bonnet
+33 (0)6 60 38 48 92
marion.bonnet@thalesgroup.com

About Business Wire

For more than 50 years, Business Wire has been the global leader in press release distribution and regulatory disclosure.

www.businesswire.com

Subscribe to releases from Business Wire

Subscribe to all the latest releases from Business Wire by registering your e-mail address below. You can unsubscribe at any time.

Latest releases from Business Wire

Darktrace Selects Navan to Modernise Travel Program25.2.2026 11:00:00 EET | Press release

Navan (NASDAQ: NAVN), the global AI-powered business travel and expense platform, today announced it has been selected by Darktrace, a global leader in AI for cybersecurity, to upgrade its global travel program. This press release features multimedia. View the full release here: https://www.businesswire.com/news/home/20260225522665/en/ Darktrace Selects Navan to Modernise Travel Program “As Darktrace accelerates its expansion, in-person collaboration is critical,” said David Smith, Chief People Officer at Darktrace. “Navan’s inventory and user experience will ensure our teams and customers can easily connect, while we can maintain financial control.” As the UK-based cybersecurity company grows, Darktrace sought a partner to consolidate its travel operations, minimize administrative burden, and improve the booking experience for its workforce. Previously hampered by fragmented processes, Darktrace required a solution that would increase platform adoption and empower its employees to tra

Zuper and Vonage Reimagine Network Connectivity for Skilled Trades with Quality on Demand25.2.2026 10:00:00 EET | Press release

Zuper, the AI operating system for the trades, and Vonage, part of Ericsson, have entered into a Memorandum of Understanding (MoU) to enter into a collaboration to integrate Vonage’s network APIs into the Zuper platform. The collaboration will provide Zuper with early access to Vonage network powered solutions, starting with Quality on Demand (QoD), where mobile network performance can be selectively applied to support critical field workflows, delivering improved latency, reliability, and connected experiences for mobile workforces. This press release features multimedia. View the full release here: https://www.businesswire.com/news/home/20260225852261/en/ QoD is the first advanced network API being integrated¹ and represents one component of a larger vision for mobile networks as a platform that aligns network behaviour with application intent as these capabilities continue to be exposed. The ambition is to provide Zuper with programmable mobile network capabilities, powered by Vonag

Industrial Decarbonization: Calderion, WenCo and Terravent Invest in Graforce to Scale Plasma Pyrolysis Globally25.2.2026 09:07:00 EET | Press release

The investor consortium comprising the Paris-based Next Generation Fuels Industrial & Technological fund Calderion (Audacia), alongside infrastructure developer Terravent and WenCo Family Office, announces the closing of a strategic double-digit million-euro financing round for Berlin-based Graforce GmbH. The investment is dedicated to the industrial scale-up of Graforce’s proprietary plasma pyrolysis technology, addressing the growing global demand for cost-efficient low-carbon hydrogen, syngas, and carbon removal solutions that are compatible with existing industrial infrastructures. Disruptive alternative to conventional processes Graforce’s technology aims at replacing CO₂-intensive legacy routes such as steam reforming and classical gasification. By applying plasma to methane, biogas, flare gas, and landfill gas, the process converts these streams into their valuable molecular components instead of emitting them. The result is a high-efficiency production of clean hydrogen and syn

Mevion Medical Systems Announces CE Marking of the MEVION S250-FIT™ Proton Therapy System, Expanding Global Access to Compact Proton Therapy25.2.2026 09:00:00 EET | Press release

Mevion Medical Systems, the global leader in compact proton therapy, today announced that the MEVION S250-FIT Proton Therapy System has successfully completed the conformity assessment process and has received CE Marking under Regulation (EU) 2017/745 (EU MDR). This regulatory milestone enables the marketing, sale, and clinical use of the MEVION S250-FIT system throughout the European Union, building on the system’s existing U.S. FDA 510(k) clearance granted in September 2025. The MEVION S250-FIT is the first and only proton therapy system designed to fit into a standard radiation therapy vault. By enabling cancer centers to use their existing infrastructure, the MEVION S250-FIT dramatically reduces the cost, complexity, and timeline traditionally associated with proton therapy adoption. This opens a new pathway for hospitals and cancer centers across Europe to bring advanced proton treatment to their patients. “With both FDA clearance and CE Marking now in hand, the MEVION S250-FIT is

Bureau Veritas: Sector-Leading Organic Revenue Growth of 6.5% in FY 202525.2.2026 08:30:00 EET | Press release

Bureau Veritas (BOURSE:BVI): 2025 key figures1 › Full-year revenue of EUR 6,466.4 million, up 6.5% organically (with 6.3% organic growth in Q4). At constant currency, the growth was up 7.3% year-on-year and up 3.6% on a reported basis, › Adjusted operating profit of EUR 1,052.9 million, up 5.7% versus EUR 996.2 million in FY 2024, representing an adjusted operating margin of 16.3%, up 32 basis points year-on-year and up 51 basis points at constant currency, › Operating profit of EUR 992.4 million, up 6.3% versus EUR 933.4 million in FY 2024, › Adjusted net profit of EUR 631.4 million, up 1.7% versus EUR 620.7 million in FY 2024, › Adjusted EPS stood at EUR 1.42 in 2025, with a 2.8% increase versus FY 2024 (EUR 1.38 per share) and up 9.2% at constant currency, › Attributable net profit of EUR 588.0 million, up 3.3% versus EUR 569.4 million in FY 2024, › Free Cash Flow of EUR 824.2 million, up 3.9% organically and up 2.6% at constant currency, and cash conversion of 107%2, › Adjusted net

In our pressroom you can read all our latest releases, find our press contacts, images, documents and other relevant information about us.

Visit our pressroom
World GlobeA line styled icon from Orion Icon Library.HiddenA line styled icon from Orion Icon Library.Eye