4.8M
Unfilled cybersecurity roles globally (ISC2, 2024)
87%
Organizations reporting an AI-driven cyberattack in the past year
20%
Organizations breached in the past year via unmanaged "shadow AI" use
~1 in 5
File uploads to consumer AI tools estimated to contain sensitive data
Self-reported rates across the workforce and threat data cited in the brief.
Three fronts, from the threat landscape down to the individual chat window.
Threat landscape
CriticalAutonomous vulnerability exploitation — Five Eyes (2026) warns AI models can now discover and exploit flaws without a skilled human operator.
SeriousAI-written phishing & deepfake voice calls — now mainstream, per UK NCSC; the technical barrier to a convincing scam has dropped sharply.
SeriousJailbreak-as-a-service kits sold on the dark web lower the skill floor for attackers.
SystemicDefender skills gap — AI/ML defense is the #1 cited hiring need (41%), ahead of cloud security.
Civilian data exposure
SeriousIndefinite retention — free/Plus chats often stored indefinitely; "deleted" chats can persist 30–90 days for review.
CriticalAgentic screen capture — browsing/acting AI features can screenshot banking dashboards or credentials, retained regardless of deletion.
Systemic"Delete" isn't a guarantee — a 2025–26 US court order forced preservation of 20M user chat logs post-deletion.
SeriousCasual oversharing — identity, financial, and health data routinely enter prompts without users registering the exposure.
Institutional & regulatory
SystemicUneven protection — EU AI Act obligations phase in from Aug 2026; the US relies on a voluntary framework and state-law patchwork.
SeriousShadow AI — ungoverned employee use of AI tools drives 1 in 5 organizational breaches.
SystemicSkills shortage compounding risk — 88% of ISC2 respondents tie a significant security event directly to the workforce gap.
CriticalUntrusted systems — agents now "act on their own... dealing with other agents" without matching trust infrastructure (Schneier, 2026).