German companies are completely unprepared in emergencies: Only 11 percent of businesses that already use artificial intelligence or plan to do so have specialized procedures for KI-related security incidents. This is shown by a Forsa survey of 505 companies with 20+ employees conducted in July 2026 by the TÜV Association and the German Federal Office for Information Security (BSI), published by media on October 7, 2026.
The study "Artificial Intelligence and Cybersecurity in Companies" reveals a system without emergency plans: While 11 percent have specialized processes, 43 percent rely on general IT security measures – without KI-specific rules. Another 20 percent are currently developing such processes, and 25 percent have no regulations in place at all.
The essentials
- 11 % of KI-using companies have specialized emergency procedures for KI incidents
- 17 % of all surveyed companies experienced a cyberattack or fraud attempt with KI involvement in the past 12 months
- 43 % use only general IT security processes without KI adaptations
- 90 % of KI-based attacks were phishing emails
The reality: Attacks are already happening
The critical point: The threat is not theoretical. 17 percent of all surveyed companies experienced a cyberattack or fraud attempt with KI involvement in the past twelve months. Of these, 4 percent were confirmed cases, 11 percent were suspected cases, and 2 percent were both.
The most common attack vectors show a familiar picture with a new dimension:
| Attack Type | Share of Incidents |
|---|---|
| Phishing emails | 90 % |
| Automated attack scripts | 40 % |
| Deepfakes (incl. CEO fraud) | 11 % |
"The registered incidents could only be the tip of the iceberg. The potential of KI in cyber defense has not yet been fully exploited, yet the technology also carries its own risks such as data disclosure and incorrect decisions."
So commented TÜV President Dirk Stenkamp on the results. He sees legislative requirements as necessary baseline protection given existing liability uncertainties.
KI adoption widespread, security lagging behind
The discrepancy between adoption and protection is striking: 49 percent of companies already use KI, 9 percent plan to within twelve months. Only 42 percent do not use KI and have no plans to. Adoption is already reality – but security infrastructure is not.
BSI Vice President Thomas Caspers also warned of an additional dimension: Even companies without their own KI use are at risk. Furthermore, dependence on US and Chinese KI companies must be reduced – a point that goes beyond pure cybersecurity.
What this means for you
For German companies, this situation creates a clear need for action: The protection gap between technological deployment and organizational emergency management is unacceptable. If you use or plan to use KI, you cannot rely on general IT processes – specialized incident response plans for KI incidents become a requirement, not an option. At the same time, questions remain open: How specifically must these processes look? What liability applies to companies if they fail to properly document KI incidents? Regulation will need to make further adjustments here.
Sources
Editorially owned by Ideal Syka. Sources and method: Newsroom & method. Tips and corrections: ai@i6eal.de.




