Three quarters of firms have halted AI projects over safety and security concerns – and cyber pros think things will deteriorate as models like Claude Mythos improve
AI has become a leading problem for enterprise security teams, they can't automate their way out of trouble
Three quarters of companies have had to halt AI projects because of safety and security concerns over the last year, and systems like Claude Mythos are only going to make security teams' jobs harder.
That's according to a pair of surveys by Aikido and CybaVerse, which highlighted that AI is clearly becoming a security problem – a fact echoed by Five Eyes cybersecurity agencies warning that leaders need to act now to stay ahead of AI-related security risks.
"Adversaries are already using AI to move faster and more effectively. Defenders must do the same," said the UK's National Cyber Security Centre in a blog post.
Rolling out AI to solve the challenges of AI may not prove a simple solution, however. A survey from Aikido Security found that 76% of organizations polled had to stop, restrict, or roll back AI projects over the last year.
That figure rises to 98% for more active teams that are shipping multiple times a day.
The report found that seven-in-ten companies had a security issue that was harder to detect, investigate, or remediate because of AI, which again rose to 86% for daily shippers.
According to Aikido, the key challenge here lies in velocity. AI has accelerated the pace of development, meaning security teams have less time to spot flaws — and more arrive by the time the first round can be fixed.
Sign up today and you will receive a free copy of our Future Focus 2026 report - the leading resource for IT decision-maker insight on priorities and investment areas in AI, security and more.
Notably, the survey found that three quarters of those polled are rolling out significant production changes weekly – or faster – but only two-in-ten are validating security at that rate.
Because of that, nearly eight-in-ten are concerned about vulnerabilities being introduced between tests and half say test findings are outdated by the time they see them.
Rising AI security concerns
It's perhaps no surprise then that nine-in-ten security professionals see the rise of security-focused models such as Anthropic's Claude Mythos as increasing cyber risk for companies
According to a survey by CybaVerse, 86% of polled cyber pros believe AI systems like Mythos will cut the time it takes for hackers to spot and exploit flaws, leading to more patching. More than two-thirds said their employer lacks the budget to address that increased workload.
“Advanced AI platforms were blasted into the public domain and organizations had no time to prepare for the impact they would have on their cyber defences," said Oliver Spence, CEO of CybaVerse.
"Now that some of the largest technology companies in the world have access to these platforms, we are already seeing an increase in the volume of vulnerabilities being identified and disclosed, with the latest Patch Tuesday being the largest on record."
Looking ahead, security professionals aren't optimistic that AI will make the situation better. Indeed, three quarters believe an advanced AI system will eventually be weaponized by cyber criminals.
"This is something organizations must be prepared for because bulletproof security doesn’t exist," said Spence.
Back to basics
Spence added that core defense techniques haven't changed, even if AI has accelerated the pace of vulnerability discovery.
"Security teams still need visibility of their assets, they still need strong vulnerability management processes and they still need to prioritise remediation efforts based on risk," he said.
"Advanced AI may change the speed and scale of cyber threats, but the organizations that maintain strong cyber hygiene and focus on reducing exposure to their most significant risks will always be in the strongest position to defend themselves,” added Spence.
FOLLOW US ON SOCIAL MEDIA
Follow ITPro on Google News and add us as a preferred source to keep tabs on all our latest news, analysis, views, and reviews.
You can also follow ITPro on LinkedIn, X, Facebook, and BlueSky.

Ross Kelly is ITPro's News & Analysis Editor, responsible for leading the brand's news output and in-depth reporting on the latest stories from across the business technology landscape. Ross was previously a Staff Writer, during which time he developed a keen interest in cyber security, business leadership, and emerging technologies.
He graduated from Edinburgh Napier University in 2016 with a BA (Hons) in Journalism, and joined ITPro in 2022 after four years working in technology conference research.
For news pitches, you can contact Ross at ross.kelly@futurenet.com, or on Twitter and LinkedIn.
-
OpenAI expands 'Daybreak' cyber program: New tools, partnerships, and a cyber-focused GPT-5.5 aim to help 'patch the world'News The company has added new tools, signed up partners, and released its GPT-5.5-Cyber model more widely
-
IT teams are bullish on AI tools, but they’re worried security practices can’t keep paceNews Executives and IT teams are at odds over the risks associated with AI adoption
-
‘These sorts of post-compromise techniques used to be restricted to actors with the technical knowledge to carry them out’: Anthropic warns AI is helping lower the bar for up-and-coming hackersNews AI is making it harder to differentiate between high and low-skilled actors
-
AI is shrinking attack windows, and it’s forcing a complete rethink of cyber resilience – here’s how organizations can prepareNews Commvault has urged companies to improve their business continuity and resilience plans in the face of flaws spotted by AI
-
Google says AI is now being used to build zero-days – and we just narrowly avoided a 'mass exploitation event'News Google cyber researchers think they’ve found the first AI-generated zero-day exploit
-
Anthropic targets vulnerability detection gains with Claude Security public beta — here's what users can expectNews The Claude Mythos developer is aiming for a more limited approach to cyber tooling for public consumption

