AI Ecosystem Emerges as Top GenAI Security Threat, Finds 2025 Thales Data Threat Report

According to the 2025 Thales Data Threat Report, nearly 70% of organizations identify the rapid pace of AI—particularly generative AI—as the top security concern in today’s digital landscape. Conducted by S&P Global Market Intelligence 451 Research, the study surveyed over 3,100 IT and security professionals across 20 countries and 15 industries.

The most cited risks related to GenAI adoption include:

  • Rapid AI development (70%)
  • Lack of data integrity (64%)
  • Trustworthiness concerns (57%)

As agentic AI gains momentum, ensuring high-quality data becomes critical for sound AI decision-making. One-third of respondents reported that GenAI is already transforming their operations or being actively integrated.

Rapid GenAI Adoption Spurs Security Investments

As organizations move from experimentation to full-scale GenAI deployment, they are increasingly investing in dedicated AI security measures. Key findings include:

  • 73% of respondents are funding AI-specific security tools—through new or reallocated budgets.
  • Over two-thirds utilize cloud provider tools; 60% leverage traditional security vendors; nearly half use emerging startups.
  • Security for GenAI now ranks second in security spending priorities, just behind cloud security.

However, analysts caution that rapid implementation, often ahead of robust security or architectural understanding, creates potential vulnerabilities. SaaS proliferation and embedded GenAI capabilities further amplify risk exposure.

Data Breach Frequency Declines, but Threats Remain High

Encouragingly, reported data breaches have declined modestly:

  • 45% of enterprises experienced a breach in 2025, down from 56% in 2021.
  • 14% reported breaches in the past 12 months, compared to 23% in 2021.

Despite this decline, malware remains the most common threat type. Phishing has overtaken ransomware as the second-most reported threat. The most worrisome threat actors include:

  • Hacktivists
  • Nation-state actors
  • Human error

Quantum Threats Spark Encryption Strategy Overhauls

The report highlights significant concern over quantum computing’s future threat to encryption:

  • 63% worry about encryption compromise due to quantum breakthroughs
  • 61% cite key distribution risks
  • 58% are concerned about “harvest now, decrypt later” (HNDL) tactics

In response, many organizations are evolving their encryption strategies:

  • 60% are evaluating or prototyping post-quantum cryptography (PQC)
  • 50% are reassessing existing encryption models
  • Only one-third rely on telecom or cloud providers for transition readiness

While three out of five organizations have taken initial steps toward PQC, experts note that deployment timelines remain tight, and delays could leave critical data vulnerable.

Looking Ahead: Strengthening Security in the GenAI Era

This year’s findings reveal progress in data security, but organizations must do more to ensure their defenses evolve alongside emerging technologies. As GenAI reshapes enterprise operations, securing foundational data and building quantum-resilient systems will be essential for safe innovation in the years ahead.