Wer hat Schutzmaßnahmen?: Firmen zumeist nicht speziell für KI-Angriffe gewappnet
Etwa jeder zweite Betrieb nutzt Künstliche Intelligenz. Spezielle Prozesse, um das eigene Unternehmen gegen KI-gestützte Cyberangriffe zu schützen, haben nur die wenigsten etabliert.
In Germany, roughly one in ten companies have established processes specifically for security incidents related to artificial intelligence (AI), according to a Forsa survey conducted for the Federal Office for Information Security (BSI) and the TÜV Association. Only 11% of the 505 companies surveyed reported having specialized precautions for such cases, while 43% used general IT security processes without AI-specific rules.
Twenty percent of respondents are currently developing such processes, and 25% have no regulations for these incidents. Two percent responded with "I don't know." The survey, which included IT or AI leaders and executive members from companies with at least 20 employees, found that about half of the respondents (49%) currently use AI.
Nine percent plan to adopt AI within the next year, while 42% reported not using it at all. Of the AI skeptics, 53% expressed concerns about data privacy or security. Of those using AI, 96% used it for creating texts, images, or code. Less than one-third (31%) of companies are using AI to improve IT security, with 25% using it for automating processes like generating invoices or chatbots in customer service.
Artificial intelligence is not just a new technological innovation, but also brings significant "operational and strategic changes," said BSI Vice President Thomas Caspers. Its potential has not been fully utilized by European companies. To reduce dependence on Chinese and US-based AI companies, it's important to identify the "truly relevant application areas" for Europe, allowing for successful competition "on equal footing" with developers in the US and China.
In the survey, 17% of businesses reported AI-powered attacks, though the true figure is likely higher since AI involvement in cyberattacks is not always easily detectable. TÜV Association President Dirk Stenkamp noted that there is often uncertainty about liability in the event of a security incident involving AI: "Is it the AI provider, myself, or others?"
As many companies lack the expertise to assess AI model security, legislative measures could help establish a basic form of protection.
Written by urgent.news from Handelsblatt's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.