Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
_Val_
Admin
Admin

GenAI Security Readiness - Lakera Report

Screenshot 2025-11-24 at 13.02.58.png

 

Executive Summary

“Our adoption has been faster than our ability to build safeguards.”—Survey respondent, IT manager

Generative AI has crossed the line from experiment to everyday reality—but enterprise security hasn’t kept pace. Adoption is no longer about if—it’s about how fast companies can scale safely. Yet in 2025, most organizations remain dangerously underprepared for the risks they’ve already deployed. Nearly half are implementing GenAI, but only a fraction have the guardrails or expertise to secure it.

Incidents are real: 15% of respondents reported a GenAI-related security incident in the past year. These cases most often involved prompt injection, data leakage, and biased outputs. Yet while incidents raise concern, they do not reliably translate into greater preparedness.

Confidence remains fragile. Only 4% of organizations rate their security confidence at the highest level. Preparedness shows a similar pattern, with just 15% describing themselves as well-prepared for emerging threats.

Risks are diversifying. Privacy remains the most-cited concern (46%), but its weight has dropped sharply from 73% in 2024. In its place, adversarial misuse, agent risks, and offensive AI are climbing. Unauthorized access and novel vulnerabilities are flagged less often ( 34% and 29%, respectively), as organizations gain familiarity and redirect focus to newer risks.

Challenges are mounting. Talent shortages are now the #1 barrier (39%), and integration complexity has emerged as a major new obstacle. When these two pressures combine, preparedness drops sharply—a compound gap that many organizations struggle to close.

Perceptions also diverge by role and size. Developers often highlight misuse risks, while security analysts point to unauthorized acces,s and researchers focus on novel vulnerabilities. Business users remain most concerned with privacy and regulatory fallout. Enterprises tend to report more structure and higher preparedness, but also more incidents; mid-sized firms often feel the least prepared.

 

Access the full report here

  • AI
1 Reply
the_rock
MVP Platinum
MVP Platinum

Another great read.

Best,
Andy
0 Kudos