GoFirm
Back to Blog
Threat Landscape·2 min read

54% of security professionals have faced an AI-related incident. Same root cause.

By GoFirm

Check Point Software Technologies surveyed 1,042 cybersecurity and IT professionals globally and found that 54% had experienced an AI-related security incident in the past year. A further 24% could not confirm whether they had, due to lack of visibility.

The incidents fell into three categories: unauthorised or shadow AI usage at 41%, AI-generated content used in attacks such as phishing or deepfakes at 37%, and sensitive data leaked to or through AI services at 32%.

Those three categories look different on the surface. One is an insider behaviour problem. One is an attacker capability problem. One is a data governance problem. The security industry has a different product for each of them.

But they share the same root cause. In every case, an action executed that should not have.

  • A tool was used without authorisation.
  • A phishing payload triggered a response.
  • Data moved without approval.

The common factor is not the threat vector. It is the absence of a control at the point of execution.

TJ Marlin, CEO at Guardrail Technologies, put it plainly in the report: the biggest incidents today are not rogue AI systems. They are AI agents getting too much access, and employees trusting AI-generated actions.

That is a precise description of an execution boundary problem. The agent had permission. The employee trusted the output. Nothing intervened between the instruction and the action.

Detection does not solve this.

Detection fires after the action. Visibility tells you what happened. Neither stops the action before it completes. For high-consequence and irreversible actions, after-the-fact is too late.

The control that addresses all three categories simultaneously is a hard stop at the execution boundary, requiring confirmed human authority before the action proceeds. It does not matter whether the instruction came from a shadow AI tool, a deepfake, a phishing payload, or a compromised agent. If a named human authority has not confirmed on a registered personal device through a separate channel, the action does not execute.

Unauthorised AI usage stopped. AI-generated attack neutralised. Sensitive data protected. Three categories. One control.

GoFirm is The Authority Platform. That is the control.

GoFirm is The Authority Platform. Stop unauthorised action. Every time.

In association with Osinto.ai, the collective intelligence platform for Security, Resilience & Defence. Osinto’s AI-enabled open-source network and governed collaborative operational environment help mitigate the growing security, resilience and governance obligation in seconds, not days.

References

1. Check Point Software Technologies. AI Security Report. May 26, 2026. Via IT Brew: https://www.itbrew.com/stories/report-54-of-cybersecurity-pros-faced-ai-related-security-incident

2. Verizon. Data Breach Investigations Report 2026. May 19, 2026.

Share this article