Finance Lets AI Security Automation Act Alone; Attackers Use AI Right Back

A close-up of an empty operator's chair at a security

Sixty-six percent of financial institutions now let AI security automation act with no human in the loop, well above the 53 percent average across industries. The number comes from Gigamon’s 2026 survey of 139 finance security and IT leaders. It sits next to an uncomfortable one: 77 percent of those institutions experienced a breach that involved AI, and detection is getting slower, not faster.

What the AI security automation numbers say

The adoption side looks like a success story. Ninety-one percent of the surveyed firms run AI-powered tools to protect data, and two-thirds letting those tools act autonomously puts finance ahead of every adoption number in the study. Finance is automating security decisions faster than anyone else.

The breach numbers undercut that story. Seventy-seven percent of these organizations experienced a breach that involved AI. Fifty-four percent watched AI-written phishing and smishing climb this year, and 47 percent saw more attacks aimed directly at their AI and large language model deployments. Among the firms that were breached, 98 percent took material damage: financial losses, higher cyber insurance premiums, lost data, or a regulator’s attention.

The spending paradox completes the picture. Ninety-four percent invested in new detection and visibility technology, yet 42 percent say breaches now take longer to find, and 52 percent name their own fragmented toolset as the biggest obstacle to securing hybrid cloud. The sector bought more tools and got slower answers.

Why autonomy without visibility multiplies risk

Here is the verdict these numbers argue for: finance automated the response before it automated the seeing. AI security automation that acts alone inherits whatever blind spots its telemetry has. Ninety-five percent of the surveyed leaders admit their security depends on visibility into data in motion that many do not yet have. Attackers targeting a widening AI security gap get to exploit both layers at once: the models making decisions and the traffic nobody watches.

The encrypted-traffic numbers sharpen it further. Eighty-eight percent of finance leaders call harvest-now, decrypt-later collection a present concern, 36 percent rank encrypted traffic as their single greatest breach vulnerability, and 93 percent tie post-quantum readiness to seeing inside that traffic. One caveat a careful reader should apply: Gigamon sells visibility tooling, so the survey frames visibility as the answer. The breach and detection numbers stand on their own regardless of who commissioned them.

How to act on the survey

Match AI autonomy to blast radius. Inventory every security action AI can take today without a person, then rank each by the damage a wrong or hijacked action could do. The 66 percent autonomy rate against the 77 percent AI-breach rate is the argument for pulling a human back into the loops that can lock accounts, kill sessions, or move money.

Treat your security AI as an attack surface, not just a defender. With 47 percent of firms reporting more attacks on AI and LLM deployments, the models doing the defending are targets themselves. Log their prompts and actions like administrator commands, and give their credentials the same rotation and scoping discipline.

Start the harvest-now inventory before the deadline forces it. If 88 percent of the sector believes adversaries are already collecting encrypted data to decrypt later, the useful question is which of your long-lived secrets travel encrypted today. Map those flows now; post-quantum migration goes to the data that matters first, not the data that is easiest.

The sector that automates security fastest is also the one paying the most for AI-involved breaches, and those two facts are not a coincidence. AI security automation amplifies whatever the system can and cannot see. Before the next budget cycle buys another tool, the better spend is proving the AI you already trust can actually see what it is acting on.

Join our LinkedIn group Information Security Community!

Holger Schulze
Holger Schulze is the founder and publisher of Cybersecurity Insiders, an independent cybersecurity research and media company. He writes about how AI is reshaping cybersecurity, where attackers are moving faster than defenses, and what security leaders can do about it. His work draws on original research and real-world incidents, translating both into practical guidance for security teams. Holger moderates the Information Security Community on LinkedIn, one of the largest professional networks in cybersecurity. Connect at linkedin.com/in/holger-schulze

No posts to display