# AI gold rush leaves accountancy firms exposed to costly cyberattacks

> Source: <https://www.cityam.com/ai-gold-rush-leaves-accountancy-firms-exposed-to-costly-cyberattacks/>
> Published: 2026-08-12 14:42:28+00:00

# AI gold rush leaves accountancy firms exposed to costly cyberattacks

Accountancy firms are pouring millions of pounds into AI, but the industry forgot to modernise security systems and is leaving itself exposed to costly cyberattacks.

According to a report by software company Fastly, shared with *City AM*, more than 75 per cent of businesses that identified as AI-first, meaning they had integrated AI into core processes from the outset, took an average of 80 days longer to recover from security incidents than their peers.

The data revealed nearly half of the businesses surveyed said AI was directly exploited in their most recent security incident, compared with seven per cent of non-AI-first organisations. It also added that these businesses battled an average of 54 known security breaches per year.

Marshall Erwin, chief information security officer at [Fastly](https://www.fastly.com/), said: “Cyber criminals target accounting firms for the privileged access to sensitive financial information they hold.”

This comes as the [accountancy sector has been rapidly reshaped](https://www.cityam.com/private-equity-boom-nearly-9-in-10-accountancy-firms-approached-last-year/) with the surge of external capital in the form of private equity as the industry looks to invest in tech upgrades, including AI integration.

## Chatbots gone rogue

One of the main problems was that more than half (53 per cent) of security teams admitted to lacking specialised AI expertise required to combat emerging threats. Even approved AI tools created vulnerabilities because they frequently received extensive automated permissions.

Erwin said these tools became “privileged parts of your infrastructure and that’s what created the risk”.

This occurred as OpenAI’s ChatGPT and Anthropic’s Claude, the two leading AI chatbot platforms, were revealed recently to have tried to hack businesses in rogue attacks. The news was revealed in the same week [Britain’s AI safety watchdog](https://www.cityam.com/uks-ai-watchdog-flags-anthropics-mythos-openai-in-security-breach/) was forced to declare a security incident after Anthropic’s Mythos went rogue during a routine test.

Fastly said shadow AI, which referred to unauthorised AI tools that employees adopted without IT approval, ran 31 per cent higher among employees at AI-first organisations, but as a result, has hit the bottom line of the businesses.

He said: “Security has to move at the same pace as innovation. Firms need an understanding of where AI is being used, what data and systems it can access, and who is responsible when something goes wrong.”

In June,[ Holly Waszak](https://www.cityam.com/professional-services-firms-the-flavour-of-the-month-for-cyberattacks/), head of cyber claims advocacy at Marsh, told *City AM* professional services firms were the “current flavour of the month” for cyberattacks.
