German companies are drastically underprepared in the fight against AI-powered cyberattacks. That's the central finding of a new study by the Federal Office for Information Security (BSI) and the TÜV Association, which surveyed more than 500 companies with at least 20 employees. The verdict is alarming: only 10 percent of businesses have established protective measures and processes against such attacks – while simultaneously 17 percent have already reported confirmed incidents, suspected cases, or both.
Key Facts
- 17 percent of companies reported AI-powered cyberattacks or fraud attempts in the past 12 months (4 percent confirmed, 11 percent suspected)
- 90 percent of affected companies cite convincing phishing emails as the most common attack vector
- Only 31 percent of AI-using companies deploy AI to improve their own IT security
- 11 percent have specialized processes for handling AI-related security incidents
Attack Methods: From Phishing to Deepfakes
The range of AI-powered attacks is impressive – and frightening. Phishing emails dominate at 90 percent: AI enables attackers to craft highly convincing messages tailored to specific individuals or companies. 40 percent of affected firms report automated attack scripts that independently search for IT security vulnerabilities and adapt dynamically. An especially insidious variant involves deepfakes: 11 percent of companies encountered fabricated audio or video recordings – for example, mimicking executive voices to trick employees into making transfers (so-called CEO fraud).
Protective Measures: Major Gaps Among AI Users
The situation is particularly troubling among companies already using or planning to use AI: 49 percent already deploy AI, with another 9 percent planning to do so within the next twelve months. Yet their defensive readiness falls short.
| Measure | Share |
|---|---|
| Specialized processes for AI security incidents | 11 % |
| General IT processes (without AI-specific additions) | 43 % |
| Currently under development | 20 % |
| No regulations in place | 25 % |
To protect their own AI operations, companies employ various measures: 56 percent offer training, while 45 percent each conduct risk assessments or have established approval processes. However, 29 percent have implemented none of these measures.
Why AI Adoption Stalls: Security Concerns as a Brake
Fear of AI-powered attacks is a genuine obstacle: 42 percent of companies currently don't use AI and have no plans to do so. More than half of them (53 percent) cite data protection or security concerns as the reason – only lack of perceived benefit ranks higher (58 percent). Other barriers include high integration effort (44 percent), legal uncertainty (43 percent), lack of expertise (39 percent), and expected high costs (36 percent).
What This Means for You
The study paints a picture of widespread unpreparedness: German companies are falling significantly behind in securing AI-related risks. If you want to use AI or already do, don't wait for an attack to happen – specialized processes, training, and risk assessments are not a luxury but a necessity. At the same time, the data shows that security concerns are a legitimate reason to pause AI projects. The question isn't whether AI-powered attacks will come, but when – and whether you'll be ready.
Sources
Editorially owned by Ideal Syka. Sources and method: Newsroom & method. Tips and corrections: ai@i6eal.de.




