[{"data":1,"prerenderedAt":30},["ShallowReactive",2],{"nr-en-ki-notfallplaene-deutschland-11-prozent":3},{"slug":4,"title":5,"dek":6,"date":7,"time":8,"publishedAt":9,"updated":10,"updatedAt":10,"dateFmt":11,"updatedFmt":10,"kind":12,"tier":13,"author":14,"authorName":15,"topics":16,"tracker":22,"trackerLabel":23,"headlineStat":24,"image":25,"ogImage":26,"imageAlt":5,"csv":10,"minutes":27,"words":28,"html":29},"ki-notfallplaene-deutschland-11-prozent","KI Security: German Companies Completely Unprepared for Emergencies","A joint study by TÜV Association and BSI reveals alarming gaps in incident management. Only 11 percent of AI-using companies have specialized emergency procedures – while 17 percent have already experienced attacks.","2026-10-08","09:19","2026-10-08T09:19:00+02:00","","October 8, 2026","daten","standard","ideal-syka","Ideal Syka",[17,18,19,20,21],"KI Security","Cybersecurity","Incident Management","Mittelstand","Regulation","\u002Feu-ai-act-fahrplan","EU AI Act Compliance","Only 11 % of KI-using companies have specialized emergency procedures","\u002Fnewsroom\u002Fimg\u002Fki-notfallplaene-deutschland-11-prozent.webp","\u002Fog-nr\u002Fki-notfallplaene-deutschland-11-prozent.en.png",3,538,"\u003Cp>German companies are completely unprepared in emergencies: Only \u003Cstrong>11 percent\u003C\u002Fstrong> of businesses that already use artificial intelligence or plan to do so have specialized procedures for KI-related security incidents. This is shown by a Forsa survey of 505 companies with 20+ employees conducted in July 2026 by the TÜV Association and the German Federal Office for Information Security (BSI), published by media on October 7, 2026.\u003C\u002Fp>\n\u003Cp>The study &quot;Artificial Intelligence and Cybersecurity in Companies&quot; reveals a system without emergency plans: While 11 percent have specialized processes, \u003Cstrong>43 percent\u003C\u002Fstrong> rely on general IT security measures – without KI-specific rules. Another \u003Cstrong>20 percent\u003C\u002Fstrong> are currently developing such processes, and \u003Cstrong>25 percent\u003C\u002Fstrong> have no regulations in place at all.\u003C\u002Fp>\n\u003Ch2>The essentials\u003C\u002Fh2>\n\u003Cul>\n\u003Cli>\u003Cstrong>11 %\u003C\u002Fstrong> of KI-using companies have specialized emergency procedures for KI incidents\u003C\u002Fli>\n\u003Cli>\u003Cstrong>17 %\u003C\u002Fstrong> of all surveyed companies experienced a cyberattack or fraud attempt with KI involvement in the past 12 months\u003C\u002Fli>\n\u003Cli>\u003Cstrong>43 %\u003C\u002Fstrong> use only general IT security processes without KI adaptations\u003C\u002Fli>\n\u003Cli>\u003Cstrong>90 %\u003C\u002Fstrong> of KI-based attacks were phishing emails\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch2>The reality: Attacks are already happening\u003C\u002Fh2>\n\u003Cp>The critical point: The threat is not theoretical. \u003Cstrong>17 percent\u003C\u002Fstrong> of all surveyed companies experienced a cyberattack or fraud attempt with KI involvement in the past twelve months. Of these, \u003Cstrong>4 percent\u003C\u002Fstrong> were confirmed cases, \u003Cstrong>11 percent\u003C\u002Fstrong> were suspected cases, and \u003Cstrong>2 percent\u003C\u002Fstrong> were both.\u003C\u002Fp>\n\u003Cp>The most common attack vectors show a familiar picture with a new dimension:\u003C\u002Fp>\n\u003Cdiv class=\"tbl-scroll\">\u003Ctable>\n\u003Cthead>\n\u003Ctr>\n\u003Cth>Attack Type\u003C\u002Fth>\n\u003Cth>Share of Incidents\u003C\u002Fth>\n\u003C\u002Ftr>\n\u003C\u002Fthead>\n\u003Ctbody>\u003Ctr>\n\u003Ctd>Phishing emails\u003C\u002Ftd>\n\u003Ctd>90 %\u003C\u002Ftd>\n\u003C\u002Ftr>\n\u003Ctr>\n\u003Ctd>Automated attack scripts\u003C\u002Ftd>\n\u003Ctd>40 %\u003C\u002Ftd>\n\u003C\u002Ftr>\n\u003Ctr>\n\u003Ctd>Deepfakes (incl. CEO fraud)\u003C\u002Ftd>\n\u003Ctd>11 %\u003C\u002Ftd>\n\u003C\u002Ftr>\n\u003C\u002Ftbody>\u003C\u002Ftable>\u003C\u002Fdiv>\n\u003Cblockquote>\n\u003Cp>&quot;The registered incidents could only be the tip of the iceberg. The potential of KI in cyber defense has not yet been fully exploited, yet the technology also carries its own risks such as data disclosure and incorrect decisions.&quot;\u003C\u002Fp>\n\u003C\u002Fblockquote>\n\u003Cp>So commented TÜV President Dirk Stenkamp on the results. He sees legislative requirements as necessary baseline protection given existing liability uncertainties.\u003C\u002Fp>\n\u003Ch2>KI adoption widespread, security lagging behind\u003C\u002Fh2>\n\u003Cp>The discrepancy between adoption and protection is striking: \u003Cstrong>49 percent\u003C\u002Fstrong> of companies already use KI, \u003Cstrong>9 percent\u003C\u002Fstrong> plan to within twelve months. Only \u003Cstrong>42 percent\u003C\u002Fstrong> do not use KI and have no plans to. Adoption is already reality – but security infrastructure is not.\u003C\u002Fp>\n\u003Cp>BSI Vice President Thomas Caspers also warned of an additional dimension: Even companies without their own KI use are at risk. Furthermore, dependence on US and Chinese KI companies must be reduced – a point that goes beyond pure cybersecurity.\u003C\u002Fp>\n\u003Ch2>What this means for you\u003C\u002Fh2>\n\u003Cp>For German companies, this situation creates a clear need for action: The protection gap between technological deployment and organizational emergency management is unacceptable. If you use or plan to use KI, you cannot rely on general IT processes – specialized incident response plans for KI incidents become a requirement, not an option. At the same time, questions remain open: How specifically must these processes look? What liability applies to companies if they fail to properly document KI incidents? Regulation will need to make further adjustments here.\u003C\u002Fp>\n\u003Ch2>Sources\u003C\u002Fh2>\n\u003Cul>\n\u003Cli>\u003Ca href=\"https:\u002F\u002Fwww.ad-hoc-news.de\u002Fwirtschaft\u002Fki-sicherheit-in-unternehmen-nur-11-prozent-haben-spezielle\u002F70255338\">AD HOC NEWS\u003C\u002Fa>\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>\u003Cem>Editorially owned by \u003Ca href=\"\u002Fen\u002Fautor\u002Fideal-syka\">Ideal Syka\u003C\u002Fa>. Sources and method: \u003Ca href=\"\u002Fen\u002Fredaktion\">Newsroom &amp; method\u003C\u002Fa>. Tips and corrections: \u003Ca href=\"mailto:ai@i6eal.de\">ai@i6eal.de\u003C\u002Fa>.\u003C\u002Fem>\u003C\u002Fp>\n",1791455612983]