News

AI Security Risks: Why Analysts Say Companies Aren’t Ready

5 min read Editorial

Enterprises are bolting AI tools onto their workflows faster than ever, but analysts warn that most organizations are walking into a minefield of AI security risks they never planned for.

According to commentary from cybersecurity analysts at Gartner, Forrester, and J. Gold Associates, the rush to deploy AI has outpaced the defenses meant to protect it—leaving companies exposed to both external attackers and their own careless habits.

Here’s what’s changing, who’s most at risk, and what you should watch for.

Advertisement

Why enterprises aren’t ready for AI security risks

Pete Shoard, chief of research for cybersecurity at Gartner, was blunt about the state of play.

“I don’t think they are ready,” he said. “I think the underlying thing here is that we’ve been doing the same thing for so long—and it hasn’t been working—that it’s time for a change.”

The core problem, per the analysts, is that AI adoption has been driven by the promise of speed and productivity rather than security. Companies are integrating large language models (LLMs) and AI agents into daily operations without the governance frameworks that typically accompany new technology.

That mismatch is creating fresh vulnerabilities on both fronts: insiders and automated tools can accidentally leak sensitive data, while attackers hunt for new routes into systems never designed to handle AI-driven traffic.

The number one risk: secrets leaking to GitHub

The most immediate danger, per Shoard, isn’t a sophisticated hack—it’s your own team handing over the keys.

“The number one risk at the minute is hard-coded secrets being uploaded through vibe-coded applications to GitHub, and then providing a route in [to a company],” he said.

In other words, developers using AI to rapidly write code—colloquially called “vibe coding”—are frequently embedding credentials, API keys, and passwords directly into their scripts. When those scripts get pushed to public repositories like GitHub, those secrets become trivially discoverable by anyone, including attackers hunting for an entry point.

External threats come in other forms too. Sensitive information can leak into LLMs without users even realizing it, and AI tools can wind up uploading confidential files to public code repositories.

A close-up illustration of lines of code on a dark computer screen with a glowing red secret-key symbol, representing ha
Hard-coded secrets pushed to public repositories are the top AI-era risk, per analysts.

From reactive to proactive: attack surface management

The response from the security industry is a shift toward what’s called attack surface management—tools that continuously assess both internal and external systems to predict and prevent attacks before they happen.

“Organizations are shifting from a reactive posture—detecting a threat after it has happened—to a more proactive one,” Shoard said. “That is: ‘I’m going to go off and pretend and run the scenario that a threat would, and then I’m going to go and fix that issue.'”

External attack surface management tools scan public-facing websites, file repositories, and social media feeds to locate a company’s digital assets. They’re looking for things like spoofed websites, exposed servers, or files containing sensitive information that shouldn’t be public.

Once organizations gain visibility into what’s exposed, they can prioritize the risks and remediate them by orchestrating a fix.

Erik Nost, senior analyst at Forrester, noted that AI itself is now part of the solution. “AI is augmenting all of these steps, typically through ways that vendors assess signals, but also how customers interact with the data,” he said.

Why small businesses are most exposed

Not all companies face these risks equally. Jack Gold, principal analyst at J. Gold Associates, said the problem is especially acute for small and medium-sized businesses (SMBs).

“There are a lot of dark sites out there,” Gold said. “Most companies are more about putting up barriers to security impacts than trying to find out what’s out there about them.”

SMBs often lack the internal controls and dedicated security staff that larger organizations take for granted. They’re also less likely to be able to afford the premium services that bigger firms rely on.

“There are services that will do this for big companies, including the big security outfits like Mandiant, CrowdStrike, etc., which of course they do as part of a contract service which likely is not inexpensive,” Gold said.

The result is a growing security gap: smaller companies are adopting AI at similar rates to larger ones but have far fewer tools to defend themselves.

The growing vendor landscape

With threats proliferating, hundreds of vendors now offer products spanning vulnerability scanning, attack path mapping, threat intelligence, and protection at various layers of the stack.

The most prominent players include Palo Alto Networks and CrowdStrike. Smaller firms have carved out specialties of their own: Tenable and Rapid7 are strong at network monitoring, while Wiz—acquired by Google in March—focuses on cloud monitoring.

Some products even turn an attacker’s own tactics against them.

“There’s something called Thinkst Canary, which is a honeypotting technology,” Shoard said. “Honeypots are, as the name suggests, designed to attract the attacker to understand a little bit more around their techniques.”

But detection is only half the battle. Remediation requires a more careful approach.

“People are not auto-remediating these issues. They are very carefully considering them for patching,” Shoard said.

An illustrative security dashboard showing a network map with glowing nodes and shield icons, representing attack surfac
Attack surface management tools are shifting security from reactive detection to proactive prevention.

What this means for you

For most individual Windows users, this story is less about your personal device and more about your employer. If your company has rolled out AI tools—whether an official chatbot or a developer using AI coding assistants—you may be part of the “dark sites” and exposed-secrets problem the analysts describe.

A few practical takeaways:

  • Be mindful of what you paste into AI tools. Sensitive credentials, API keys, and confidential files shouldn’t be fed into public AI systems or pushed to public code repositories.
  • Keep secrets out of your code. Use proper secret-management tools rather than hard-coding passwords into scripts.
  • Watch for company-wide AI rollouts. If your employer is adding AI without clear security guidance, it’s worth raising the governance gap with your IT or security team.

The broader takeaway is that AI’s security posture is still catching up to its adoption. As Gartner’s Shoard put it, the old approach hasn’t been working—and the industry is finally moving toward something more proactive.

Source: Computerworld

Over to you: Has your company introduced AI tools without proper security guidance—and have you noticed any data-leak risks yourself?

Advertisement
Share:
Editorial
Written by
Editorial

Windows & Microsoft news editor at 9to5Windows. Covering everything from Windows 11 builds to enterprise updates.

Advertisement