Exclaimer called on organizations to strengthen cybersecurity practices today. AI tools rapidly reshape the corporate communications threat landscape across all industries. As a result, security risks go well beyond just basic employee software use. Security personnel have to investigate which data the tools access and which operations AI bots perform. Moreover, companies need to determine who is responsible for automated results in Cybersecurity Awareness Month.
According to a recent study by Exclaimer, the prevalence of AI tools in everyday business messaging is quite high. The OnePoll survey of 1,000 American adults showed that 65% used AI in their business conversations. Nonetheless, 36% of respondents were unsure about the genuineness of the messages they receive. Also, 14% said that they did not trust any external emails from corporations.
Publishable commentary from Karl Bagci:
“Cybersecurity Awareness Month is a useful reminder that AI is changing the speed of cybersecurity. Attackers can increasingly use automation to move faster than people and traditional defensive processes can respond, which means security teams must work out where they can safely automate detection and response without removing human judgment from decisions that still need context.”
“We can’t just make everything instant; that creates its own risk because an AI system can make the wrong decision, block the wrong thing, or take an action without understanding the wider business context. The challenge for security teams is to get as close as possible to the speed of the attacker while being very deliberate about where a human still needs to be in the loop. Good security automation should remove unnecessary delay, not remove accountability.”
Bagci added:
“One of the biggest cybersecurity mistakes organizations can make with AI is to assume that saying no makes the risk disappear. Employees want to use these tools because they help them work faster, and if the business doesn’t give them a safe route, some will use personal accounts, devices, or unapproved services instead. The organization then has less visibility, not less risk.”
“A better approach is to give people approved tools, clear policies around what data can be used, and practical controls that make the safe option the easiest option. The same discipline needs to extend to AI agents. We are already seeing agents given far broader permissions than they need simply because it makes development easier. Cybersecurity Awareness Month should be a prompt to ask not only which AI tools people are using, but what those systems have been allowed to access and what they can do on the organization’s behalf.”
Ultimately, Exclaimer urges corporate leaders to audit automated access rights and maintain strict accountability across all AI deployments.
For related updates on digital trust and cybersecurity, explore our SOC News.