Nearly three quarters of European IT and cybersecurity professionals say employees are already using generative AI at work, but just under a third (31%) of organizations have put formal policies in place to manage the risks in this area, according to new ISACA research.
AI is already making a positive impact day to day – for example, over half (56%) of respondents say it has boosted organizational productivity, and 71% report efficiency gains and time savings. Looking ahead, 62% are optimistic that AI will positively impact their organization in the next year. Yet that same speed and scale make the technology a magnet for bad actors. Almost two-thirds (63%) are extremely or very concerned that generative AI could be turned against them.
Deepfakes are a specific emerging threat: 71% expect deepfakes to grow sharper and more widespread in the year ahead. Despite that, only 18% of organizations are putting money into deepfake detection tools – a significant security gap. This disconnect between rising awareness and lack of organizational investment leaves businesses exposed at a time when AI-powered threats are evolving quickly.
AI has significant promise, but without clear policies and training to mitigate risks, it becomes a potential liability. Robust, role-specific guidelines are needed to help businesses safely harness AI’s potential, says ISACA.






