Decoding the world of cybersecurity

Cyber risk slows enterprise AI rollouts

Sixty per cent of large companies surveyed by FTI Consulting say they have slowed, paused, or withdrawn planned AI deployments as cyber risk, regulation, and trust complicate adoption.

Cyber risk slows enterprise AI rollouts
Summary
  • FTI surveyed 1,600 senior decision-makers across seven markets, including six European countries.
  • Sixty per cent said their company had slowed, paused, or pulled back a planned AI deployment in the previous year.
  • Cybersecurity, regulatory uncertainty, shadow AI, and immature governance are emerging as constraints on enterprise deployment.

Cybersecurity and governance concerns are beginning to constrain the pace of enterprise artificial-intelligence deployment, with new research suggesting that a majority of large companies have slowed, paused, or withdrawn at least one planned AI initiative during the past year.

FTI Consulting surveyed 1,600 senior business decision-makers across seven markets and found that 60% said their organisation had pulled back a planned deployment because of reputational, regulatory, or trust concerns. The sample includes respondents in the United Kingdom, France, Germany, Spain, Belgium, Ireland, and the United States.

Cybersecurity was among the most frequently cited pressures. Sixty per cent of respondents identified data privacy and security breaches among their largest AI-related risks for the year ahead, while 54% said employee use of unapproved AI tools was a major concern for 2027.

The figures come from commissioned survey research and describe respondents’ perceptions rather than independently measured rates of security failure. They nevertheless capture a change in the enterprise AI discussion: the central constraint is increasingly the ability to control deployment rather than simply access models with adequate technical capability.

Governance maturity remains uneven. Only 17% of organisations surveyed said their AI governance framework had existed for more than two years, while 41% had created one within the previous year. FTI also found that 81% of respondents believed unclear AI rules had caused material issues for their business, including greater risk aversion and pressure to slow adoption.

Early experimentation could often be confined to pilots, isolated productivity tools, or small groups of users. Production deployment brings models into contact with corporate data, customer information, identity systems, software-development environments, business processes, and third-party platforms.

That changes the risk calculation. An AI system that can summarise public documents creates a different exposure from an agent that can read internal repositories, invoke tools, modify code, initiate transactions, or take action using an employee’s privileges. Governance controls that were sufficient for experimentation can become inadequate once models are given persistent access to operational systems.

Shadow AI adds another layer. Employees can adopt consumer and software-as-a-service tools more quickly than central teams can evaluate them, creating familiar problems around data leakage, identity, retention, supplier assurance, and access governance. The difference is that AI tools can combine those exposures with a rapidly changing model and application layer that conventional procurement processes were not designed to assess.

Regulation also affects the economics of deployment. European organisations are simultaneously dealing with AI-specific rules, privacy obligations, sector requirements, cyber-resilience expectations, and contractual demands from customers. Even where regulation does not prohibit a use case, uncertainty over responsibility can increase the amount of testing, documentation, legal review, and technical control required before a project is approved.

FTI’s findings do not suggest that large organisations are abandoning AI. They indicate that adoption is moving into the slower work of making systems governable. The next constraint on deployment may be less about model performance than whether companies can establish enough confidence in data handling, security boundaries, accountability, and regulatory exposure to move experiments into production.

×