According to a new research report from tech giant IBM, 92 percent of companies that experienced an AI security incident lacked basic access controls for their AI systems. Notably, the study points out that the AI models themselves were rarely the primary cause of these data breaches or cyber attacks. This reality indicates that conventional system vulnerabilities remain the most lucrative targets for hackers.
Background & Causes
In the context of global enterprises racing to integrate AI into their operational workflows, cybersecurity challenges are becoming increasingly complex. However, instead of facing sophisticated AI attack techniques such as data poisoning or prompt injection, many organizations are failing at the most fundamental steps. According to IBM's data, lax practices in authorization and access account management are the largest loopholes for malicious actors to exploit. This reflects a worrying reality where enterprises focus too heavily on deploying new technology while neglecting foundational security principles.
Technical Analysis & Technology
Technically, the lack of basic access controls often includes the failure to implement multi-factor authentication (MFA), unclearly defined user privileges, and a lack of monitoring for API gateways connected to AI models. When an AI system is deployed, it requires continuous communication with internal databases and third-party applications. Without strict control mechanisms, attackers can easily hijack high-privilege accounts, thereby deeply interfering with the model's data flow. IBM emphasizes that securing the touchpoints surrounding the AI system, rather than the internal algorithms of the model itself, is the decisive shield for maintaining enterprise data integrity.
Expert Opinions & Insights
Security experts from IBM note that this trend highlights a major misalignment in the defensive mindset of enterprises. Many organizations fear theoretical AI attack scenarios rather than focusing on reinforcing long-standing traditional security vulnerabilities. Market analysts echo this sentiment, stating that standardizing authorization procedures and establishing a "Zero Trust" policy (never trust, always verify) is currently the most urgent task. Without promptly addressing this management loophole, financial and reputational damages from AI-related leaks will continue to escalate in the coming years.
Impact & Future
For the tech community and enterprises in Vietnam, IBM's report serves as a timely wake-up call as the wave of AI adoption surges. To build a safe and sustainable AI ecosystem, both engineers and managers must prioritize establishing strict access barriers right from the system design phase. In the future, adhering to basic security standards will not just be an option, but a mandatory requirement to protect the digital assets of every organization against increasingly sophisticated cyber threats.