senn-techsenn-tech
Security
Security2026-10-09· By Franz Senn

AI Security Study 2026: One in Six Companies Reports an AI Attack, or the Suspicion of One

On Wednesday, 7 October 2026, the BSI and the TÜV Association presented their joint study in Berlin, published as "KI-Sicherheitsstudie 2026" (AI Security Study 2026). The number on the front page: 17 percent of companies in Germany had cyberattacks or fraud attempts in the past twelve months in which artificial intelligence played a role, or could have played one. One company in six. That number breaks down into 4 percentage points of confirmed incidents, 11 points of suspected cases and 2 points with both. The base population is companies in Germany with 20 or more employees, according to the BSI. Austrian figures are not in the study, which is worth saying before anyone reads their own incident log into it.

How the number comes about, and where it thins out

The questions came from forsa, on commission from the two publishers: telephone interviews, 505 companies, between 22 June and 31 July 2026. The methodology names its respondents as the people responsible for AI use, for IT security, for IT management, or the management board. That methodology starts on page 61 of the study, the running text about it on page 62, fieldwork dates included.

Three things are worth knowing before that number goes into a news ticker. First: this is a telephone self-report. No company handed over a forensics report, the answers are how the person on the phone rates the situation in their own business. Second: the 11 percentage points of suspicion are exactly that, suspicion. A mass-mailer judged AI-typical that ended up in spam counts there in the same way a confirmed break-in does. That the study keeps those categories apart is the most honest decision in it. Third: the fieldwork ended on 31 July, so the models, attack tools and fraud schemes of late summer are missing. Anyone quoting the number on the day of the presentation describes a state of affairs from some two months earlier.

What actually arrives in the companies

The affected companies name their attack methods in a clear order. 90 percent of them report highly realistic phishing mails, 40 percent automated attack scripts that look for vulnerabilities on their own and adapt while doing it, 11 percent deepfakes, meaning faked audio or video recordings in which a caller poses as a member of the management (study, page 46). Phishing is the door, the rest comes through behind it.

The Allianz für Cyber-Sicherheit of the BSI published a four-page handout for small businesses alongside the study, "Schutz vor KI-verstärkten Cyberangriffen" (Protection against AI-enhanced cyberattacks), and it plays one example chain through end to end. Worth reading, because every single step has been known for years and only the quality has deteriorated:

From the attachment to the callTuesday 09:32, thefalse invoiceThe attachment lands withaccountingSeveral days ofreading alongTone, customer contact,calendarFriday 15:47, thecallVoice of the boss, 18,500eurosWhat would standagainst itCall back over a secondchannel, code word, foureyes
The example case from the ACS handout, four pages, October 2026. The handout ends the story with the transfer; the fourth box shows the countermeasures the same handout recommends further down. (source: BSI / Allianz für Cyber-Sicherheit: Schutz vor KI-verstärkten Cyberangriffen)

Processes: a tenth has them, a quarter has none

In 17 percent of companies, something arrived. For day-to-day operations the question is what rules those companies then have in hand. Among the firms that use AI or plan to use it: 11 percent have special procedures for AI-related security incidents, 20 percent are working some out right now, 43 percent point at their general IT security processes without any AI rule, 25 percent have no rule at all (BSI press release of 7 October 2026). The 43 are the underrated problem here: an incident process that fails to pull a compromised mail account out of circulation within hours also runs at a snail's pace when the incident has an AI angle.

Handling of AI-related security incidentsSpecial AI procedures11Procedures in work20General procedures without AI rules43No rule at all25050
In percent, basis: companies that use AI or plan to, self-reported, KI-Sicherheitsstudie 2026 page 47. Only the first bar describes a procedure that explicitly knows the AI angle of an incident. (source: KI-Sicherheitsstudie 2026, page 47)

Usage: generative dominates, own servers come second

Inside the companies the picture looks like this: 49 percent use AI, another 9 percent plan to within twelve months, 42 percent neither use it nor plan to (press release, 7 October 2026). Generative AI stands at 76 percent of those surveyed, analytical AI at 24 percent (study, page 14). Agents acting on their own stand in one company in twenty, and those 5 percent are reckoned on the companies that use AI at all (page 42). On the process side, agents are not yet something a mid-sized business has to work through. The phishing mail a language model prepared during a 20-second phone call is the case that is already in the sample.

The publishers also asked where those applications run: 54 percent of the users rely mostly on external cloud services, 23 percent on their own servers or infrastructure, a fifth combines the two (study, page 29). A residual category is not spelled out there. Own operation is therefore an established minority rather than an exotic case.

Where the AI runs, among the usersMostly external cloud54Mostly own servers23Combination20060
In percent, basis: companies with AI use, self-reported, study page 29. The three values stand on their own, the study lists neither a residual category nor a don't-know answer. (source: KI-Sicherheitsstudie 2026, page 29)

The number on the other side unsettles more than the attack number: only 31 percent of the companies using AI also deploy AI for their own IT security, and that figure appears in the press release alone, absent from the study text. Among the 42 percent who neither use AI nor plan to, more than half name security or data-protection concerns (53 percent), a slightly larger group names a missing benefit (58 percent). One convincing fake invoice a day is enough to argue the opposite case, so that hurdle looks high.

The self-check, measured against our own operation

Two places let that study be laid over our own setup. First question: are we inside the 31 percent? Yes, measured on 9 October 2026 on our company mail gateway. Running there is a spam classifier whose training pairs are harvested from our own mail estate at 03:40 in the night, from the original message through to labelled vectors. On Sunday at 04:20 a refit runs over the head layer and writes a candidate model; that model is promoted by hand, and the unit is built so a candidate never becomes the live head on its own. Alongside it, measurably since the end of September, a language model in shadow mode writes a verdict on the already delivered mail every 30 minutes. It stands in the log only and never intervenes in the mail flow. Today's midday run at 12:15 had 14 mails to judge and was through in 31 seconds, the largest run of the last two weeks had 58. This is the use case the study itself names in its recommendations, where it asks companies to check how AI can help filter suspicious mail.

Second question: the 23 percent running their own infrastructure? Us as well, with the AI stack we costed against an API over one month. The control gateway behind it is LiteLLM in v1.100.4, measured at the container image tag, running on one of our own hosts, the model above it on our own GPU hardware too. The monthly comparison in that linked post carries a correction of its own by now: one column that had counted prefill into its measured totals is no longer quoted there.

Anyone who answers those two questions for their own business has done more than half of what the study's recommendations ask for.

What the ACS handout asks for in concrete terms

For small businesses the BSI supplied a handout of four pages, and the three immediate measures in it are instructions rather than statements of intent. First: write down which AI tools are allowed in the business, which data those tools may see, and name a person who maintains that list. Without that list every AI use stays a shadow operation. Second: against deception by voice and by mail, introduce the call-back over a second known channel rather than the number taken from the suspicious message, plus an agreed code word for calls from the management, handle transfers and sensitive data only under the four-eyes principle, and repeat the phishing awareness work with real example mails. A single training is not enough, the handout writes in so many words. Third: the technical basics, patching, multi-factor authentication for every employee, a security contact per RFC 9116. Page 2 adds the frame the handout draws as a job for the management board, with risk precautions, emergency management and restoration, plus the guiding question of its self-test: whether the business can work again within a defensible period after a successful attack. Our awareness page for that subject is here, and the AI competence duty under Article 4 of the AI Act, which already applies in Austria, is covered here.

Two figures at the margin, because they concern purchasing: 69 percent of the companies that use or plan AI expect independent testing and certification to bring more security, and for 51 percent a certification is already a selection criterion today (press release, 7 October 2026). The TÜV Association announces that its framework programme for AI certifications should be available at the end of this year. Whoever puts AI software out to tender can write that expectation into the criteria today. Assessment reports exist before that date, from the providers that already have them.

Further reading

Questions?
What does the AI security study 2026 say in one sentence?+

Across twelve months, 17 percent of companies in Germany recorded cyberattacks or fraud attempts with AI involved: 4 percentage points confirmed incidents only, 11 points suspected cases only, 2 points both. The other side of the same survey: 11 percent have procedures for AI-related incidents, a quarter have no rule on the subject at all.

How much weight do these numbers carry?+

The polling institute forsa surveyed 505 companies by telephone between 22 June and 31 July 2026, every attack figure is a self-report and all of them include suspected cases. The study splits confirmed incidents (4 percent), suspicion (11 percent) and both (2 percent) into groups that exclude each other. The field window closed at the end of July, so attacks using the models of late summer are not in it.

What should a company with 20 employees do first?+

From the ACS handout of the BSI: write down which AI tools are permitted and which data they may see, and name one person responsible for that list. For calls and transfers, call back over a second channel, introduce a code word and the four-eyes principle, and work with real phishing examples instead of a single training session. Third block: patching, multi-factor authentication, a security contact on the web. That holds for a business running no AI of its own as well.