Dive Brief:
- Businesses are getting better at securing their AI systems as they spend more time using the technology, the advisory firm KPMG found in its latest quarterly AI survey.
- Accountability is also improving, according to KPMG’s Q3 report, with many organizations assigning responsibility for AI to a C-suite executive — including, in some cases, the CEO — or the executive committee.
- KPMG’s latest report also found that agentic AI use is growing.
Dive Insight:
One of the KPMG report’s key insights is that organizations’ AI maturity levels strongly influence how they use AI in the context of cybersecurity. Only 8% of organizations at the experimentation stage are deploying AI-assisted cyber defense technologies, for example, compared with 58% of organizations that have been using AI long enough to see returns on investment.
Among experimenters, 26% use AI only to monitor systems; among established users, the figure is 4%, reflecting organizations’ growing comfort with plugging AI into more security tasks over time. Established AI users were also more likely than experimenters to report spending some of their AI budgets on cybersecurity (71% versus 36%). Interestingly, established users were also more likely than experimenters to describe cybersecurity as a barrier to AI use (50% versus 34%).
As businesses see the threat landscape grow more complex, they are racing to update their cybersecurity strategies to account for faster-moving attacks. In KPMG’s latest report, 86% of organizations said they were “adapting their cybersecurity operating model for AI-accelerated threats.”
As part of the business community’s growing focus on AI governance, more than half (55%) of organizations reported operating an AI harness layer that incorporates a variety of technical controls to prevent AI from doing damage. Security and identity top the list of capabilities included in these harnesses (43% of organizations reported including those features), followed by data access controls (43%) and monitoring of AI outputs (41%).
But human controls also matter, and KPMG heralded the finding that 53% of organizations said they assigned AI responsibility to a senior executive. (Nearly one-quarter of organizations said they held their CEO or executive committee directly responsible for AI governance.) “A control layer without a named owner is a policy rather than a management system,” KPMG said in its report. “Accountability is what turns controls into decisions someone can be asked to explain.”
Security remains high on companies’ list of AI priorities. Human-AI collaboration tops the list, with 32% of respondents citing it, but responsible AI and security follow close behind with 30% each. All three of those figures increased by four percentage points between Q1 and Q3.
Agentic AI use is also growing, the report found: Nearly four in 10 respondents said they were either building or using multiagent systems, and 34% of organizations reported significant employee use of AI agents (up from 25% in Q1).
KPMG’s latest survey is based on interviews with 2,131 senior business leaders in 20 countries.





