More than four out of five security and finance leaders expect to boost cybersecurity spending over the next year, driven largely by mounting threats from artificial intelligence, according to PwC's 2027 Global Digital Trust Insights Survey. The figure reached 84%, climbing from 78% a year earlier, in a survey that gathered nearly 4,000 responses from business and technology executives spanning 71 countries and territories. AI ranks among the top cyber budget priorities for 58% of security leaders, but the spending surge is accompanied by significant preparedness shortfalls.
Half of security leaders identified attacks targeting AI systems as threats their organizations are least prepared to handle, according to the report. That places AI-related attacks ahead of cloud threats at 40%, third-party breaches at 34%, and ransomware at 33%. Roughly half of security and risk leaders cited autonomous botnet compromises, adversarial attacks, and data poisoning as areas where preparedness remains weak. Only 39% of security, risk, and operations leaders reported having a fully formalized and integrated operational continuity plan specifically addressing cyber risks. While AI is increasingly deployed for defensive purposes such as threat detection, alerting, and phishing detection, just 22% of leaders would authorize AI agents to carry out cyber-defense actions fully autonomously. Reliability and technology maturity were the biggest barriers, cited by 55% of respondents, followed by accountability and explainability at 46%.
Organizations are adding AI leadership faster than they're defining who ultimately owns AI risk, the survey suggests. About one-third have created dedicated AI roles, but only 47% strongly agree that cyber risk is a standing board-level agenda item. Accountability for AI is fragmented: 29% place it with the CIO, CTO, or similar technology role, while 26% favor a dedicated AI leader and 17% assign responsibility to the CISO or cybersecurity function. Among CISOs, 44% identified workforce skills in AI oversight and governance as a major obstacle. PwC argued that "cyber resilience will require C-suite elevation," with security needing to be embedded in executive decision-making as organizations deploy AI.
The survey points to a fundamental problem lurking behind the AI spending boom: organizations may be adding advanced defenses while basic protections remain incomplete. Only 5% of respondents said they had fully implemented all seven data-risk measures examined by PwC, down from 7% last year. Just 49% had fully implemented data classification policies and 48% had fully deployed data-loss prevention across key data-exit channels. According to the report, customers may need help with data classification, DLP, identity and access controls, continuity planning, cloud security, and AI governance before autonomous security tools can be deployed safely. AI can improve detection and response, but it can't compensate for weak data controls or unclear accountability. For security providers, managed service providers, and integrators, the findings suggest demand will extend well beyond AI-specific security products to include continuity planning, data protection, multicloud security, and third-party risk management as customers try to close foundational gaps before expanding AI adoption. The spending increase is real, but whether it addresses the controls and governance needed to support increasingly autonomous AI systems remains the key question for channel partners and their clients. Organizations face a choice between chasing the next wave of intelligent defenses and shoring up the unglamorous infrastructure that determines whether those defenses can function at all.

