# AI deployments bring with them risks companies are ill-prepared for — analysts

> Source: <https://www.computerworld.com/article/4214445/ai-deployments-bring-with-them-risks-companies-are-ill-prepared-for-analysts.html>
> Published: 2026-08-26 19:05:16+00:00

Enterprises that have been rapidly adding AI tools and services into their workflows are [often not prepared for the internal and external threats](https://www.computerworld.com/article/4127206/testing-cant-keep-up-with-rapidly-advancing-ai-systems-ai-safety-report.html) that could expose weaknesses in their systems, analysts said.

“I don’t think they are ready,” said [Pete Shoard](https://www.gartner.com/en/experts/pete-shoard), chief of research for cybersecurity at Gartner. “I think the underlying thing here is that we’ve been doing the same thing for so long — and it hasn’t been working — that it’s time for a change.”

External threats can emerge when sensitive information leaks to large language models (LLMs) without users realizing the problem. AI tools could also wind up uploading sensitive files to public repositories like GitHub.

“The number one risk at the minute is hard-coded secrets being uploaded through vibe-coded applications to GitHub, and then providing a route in [to a company],” Shoard said.

As a result, companies need to get ahead of the curve by detecting internal and external threats before they materialize. That’s led to renewed interest in attack surface management tools, which assess internal and external systems to predict and prevent possible attacks.

“Organizations are shifting from a reactive posture — detecting a threat after it has happened — to a more proactive one. That is: ‘I’m going to go off and pretend and run the scenario that a threat would, and then I’m going to go and fix that issue,’” Shoard said.

External attack surface management tools can, for example, scan public-facing websites, file repositories, and social media feeds to look for a company’s digital assets, which could include spoofed websites, exposed servers, or files containing sensitive information.

Once organizations gain visibility into exposed threats, they can prioritize them and remediate them by orchestrating a fix.

“AI is augmenting all of these steps, typically through ways that vendors assess signals, but also how customers interact with the data,” said [Erik Nost](https://www.forrester.com/analyst-bio/erik-nost/BIO20004), senior analyst at Forrester.

Security issues can arise when companies rush to bolt AI onto existing IT systems to solve problems, but [don’t plan for security or governance](https://www.computerworld.com/article/4002046/genai-adoption-outpaces-governance-ernst-young-finds.html). That’s especially a problem for small and medium-sized businesses (SMBs), since threat detection and response are more often a major focus of large companies, said [Jack Gold](https://jgoldassociates.com/Biography/Bio-Jack-Gold-2021.pdf), principal analyst at J. Gold Associates.

“There are a lot of dark sites out there,” Gold said. “Most companies are more about putting up barriers to security impacts than trying to find out what’s out there about them.”

SMBs often have far less robust capabilities, particularly because they lack internal controls and are unwilling, or unable, to pay big firms for their services.

“There are services that will do this for big companies, including the big security outfits like Mandiant, CrowdStrike, etc., as part of their services, which of course they do as part of a contract service which likely is not inexpensive,” Gold said.

Companies have also seen a rise in technical debt as more AI agents are generated and put to use. The proliferation of agents — many of which may not work or open up new attack surfaces — creates additional security headaches.

With threats proliferating, hundreds of vendors now offer products spanning services such as vulnerability scanning, attack path mapping, threat intelligence, and protection at various levels.

The most prominent vendors include the likes of Palo Alto Networks and CrowdStrike, though smaller firms have their specialties: Tenable and Rapid7 are strong at network monitoring, while Wiz — acquired by Google in March — focuses on cloud monitoring.

Some products even turn the attacker’s own approach against them.

“There’s something called Thinkst Canary, which is a honeypotting technology,” Shoard said. “Honeypots are, as the name suggests, designed to attract the attacker to understand a little bit more around their techniques.”

While detection can be largely automated, remediation requires a different toolkit. “People are not auto-remediating these issues. They are very carefully considering them for patching,” Shoard said.
