TLDR: The rapid integration of Generative AI (GenAI) across enterprises is creating a significant gap in data security, as revealed by the 2025 Thales Data Threat Report. With nearly 70% of IT and security professionals identifying the evolving GenAI ecosystem as their top concern, organizations are struggling to keep pace with new risks like data integrity attacks and the need for digital sovereignty, despite increasing investments in AI-specific security tools.
Generative AI (GenAI) is rapidly permeating various sectors of the enterprise, from enhancing customer service chatbots to powering marketing campaigns. While it promises unprecedented speed and innovation, this swift adoption introduces a new array of complex and unfamiliar security risks. A significant finding from the 2025 Thales Data Threat Report, which surveyed over 3,000 IT and security professionals, underscores a critical challenge: many companies are discovering that their existing data protection strategies are ill-equipped to handle the security implications of AI’s rapid evolution. The report also highlights the increasing importance of digital sovereignty as organizations expand their operations across diverse cloud environments and international borders.
GenAI Adoption Outpaces Security Preparedness
One-third of enterprises are already deeply integrating generative AI into their operations, reaching a point where it is fundamentally transforming their business processes. This rapid shift is occurring without many organizations adequately addressing the associated security or compliance requirements. A striking nearly 70% of survey respondents identified the fast-changing GenAI ecosystem as their primary security concern. This complex ecosystem encompasses new Software-as-a-Service (SaaS) offerings, emerging infrastructure, and increasingly autonomous AI agents that process sensitive data.
The Rise of Data Integrity Concerns
Beyond traditional concerns of confidentiality and availability, data integrity and trustworthiness have emerged as central issues in the AI era. AI’s reliance on vast datasets makes it vulnerable to new forms of attack where malicious actors can inject false or biased information directly into models, leading to harmful outcomes. These ‘integrity attacks’ ranked as the second-highest concern among professionals, closely following the complexity of the GenAI ecosystem itself.
Data Security as the Foundation for AI Trust
For Generative AI to function safely and effectively, it requires large volumes of reliable and high-quality data. If this foundational data is compromised, the entire AI system’s integrity and safety are jeopardized. In response, enterprises are beginning to invest in AI-specific security tools, with over 70% of survey participants reporting funding for such initiatives, utilizing a combination of cloud provider offerings and specialized solutions. However, despite these new investments, a significant gap persists between AI adoption rates and the maturity of data protection measures. Security teams often lack adequate visibility into how data flows through AI systems, particularly when these systems are embedded within third-party SaaS products. This lack of oversight creates a substantial risk of exposing confidential data or violating privacy regulations, especially concerning data used for model training and inference.
Navigating a Hybrid Security Future
Also Read:
- Singaporean Firms Excel in AI Security Amidst Rising ‘Shadow AI’ Challenges
- Securing Non-Human Identities: The Challenge of AI Governance in the Enterprise
For Chief Information Security Officers (CISOs), the paramount challenge is to harmonize their security programs with both the inherent risks of AI and the evolving demands of digital sovereignty. The Thales report suggests several practical steps: mapping data flows across both on-premises and cloud environments is crucial; adopting unified security tools can help reduce the complexity arising from fragmented controls; and planning for flexibility will enable organizations to adapt swiftly as both regulatory landscapes and AI technologies continue to evolve. The continued success and growth of Generative AI will ultimately depend on the quality and robust protection of the data that underpins it. Simultaneously, digital sovereignty will increasingly dictate the geographical location and methods of data storage and processing. By addressing these intertwined challenges proactively, security leaders can effectively manage risk while simultaneously fostering innovation.


