Security teams are grappling with change stemming from enterprises adopting AI. Whilst with challenging repercussions, this hasn’t stopped 34% of enterprises embedding AI agents for real uses according to a 2026 Thales Data Threat report.

It’s a careful balancing act for enterprises to trust AI with undertaking more corporate tasks and boosting efficiency. Among 70% of respondents, AI related concerns are considered in the top three sources of risk and the expectation of using AI agents is that it will increase the number of fraud targets.

The popularity of AI has made it common to make huge investments into the technology and rank it the second highest priority after cloud security. Dedicated AI security spending has risen to 30%.

On the downside, 97% have experienced organisational harm from AI-generated misinformation or deepfakes, the report says. On the global stage, the top AI company founders in the world have been vocalising gears that AI could be the end of the human race if allowed total autonomy and human-level artificial intelligence; it could outmaneuver human capacity and cause deception. UN Human Rights Chief Volker Türk on Monday called on States and the world’s ‘frontier’ artificial intelligence companies to act urgently to regain AI governance as the technology exponentially advances. It creates unprecedented risks to human rights, confirmed by the Office of the High Commissioner for Human Rights in the United Nations.

“We are on the cusp of irreversible change, affecting not just us but generations of humanity to come,” the High Commissioner addressed world leaders.

“Failures involving agentic AI systems – let alone systems deliberately so designed – could bring essential services to a standstill, fracture communications, destabilise critical infrastructure, and strike at the very heart of democratic institutions,” he wrote.

Cloud storage (35%), cloud applications (34%), and cloud management infrastructure (32%) are also ranked in the top three cyberattack targets. Moreover, only 47% of sensitive cloud data is protected by encryption, with 53% leaving key control entirely to cloud providers.

In daily business operations, organisations still struggle with visibility, knowing where all their data is stored and classification. The sprawl of AI security and data protection tools which enterprises are arming themselves with are actually creating significant operational friction.

Quantum threats are transitioning from theoretical concerns to immediate risks. The top-cited quantum risk is “harvest now, decrypt later” attacks at 61%, with 59% of organisations actively evaluating or prototyping Post-Quantum Cryptography (PQC) solutions.

When global leaders gather at the RAI Exhibition Centre in Amsterdam for Identity Week Europe 2027 (15–16 June 2027), the core mission, building identity and trust for government, enterprise, and partners, will collide directly with the challenges outlined in recent NIST and Thales reports. From NIST IR 8587’s guidelines on token protection to Thales’ findings on agentic AI fraud and post-quantum threats, these insights set the agenda for Europe’s largest digital identity gathering.