BERLIN: German companies are vulnerable and unprepared for a growing wave of artificial intelligence (AI)-driven cyberattacks, a new study published on Oct 7 warned, creating broader economic and security risks for the country.
Only one in 10 companies has specific procedures in place to handle AI-related security incidents, according to the joint study from the German government's BSI cybersecurity office and the independent Association of Technical Inspection Agencies (TÜV).
AI has "immediate and strategic consequences for national security," Thomas Caspers, BSI's vice president, said in a press release.
The study, which surveyed roughly 500 companies with at least 20 employees, found that one in six companies had experienced "a cyberattack or fraud attempt in which AI played – or could have played – a role" within the last 12 months.
The study notes that the most common method involves AI-generated phishing emails that are "highly convincing and precisely tailored to specific individuals or companies".
Next come "automated attack scripts that autonomously scan for IT security vulnerabilities and dynamically adapt to them".
Another growing issue is the use of "deepfakes" – manipulated audio or video content – such as those imitating the voices of company executives to trick employees into making financial transfers.
The study's authors note with concern that 43% of companies "rely on their general IT security processes without having yet supplemented them with AI-specific guidelines".
Furthermore, 71% of the companies surveyed state that they are poorly informed about the obligations imposed on them by the European Union's AI Act, adopted in 2024 and touted by Brussels as the world's most comprehensive legal framework for AI. – AFP
