Are cyber budgets rising faster than AI safeguards?
New analysis today of PwC’s 1 October survey of 3,934 business and technology leaders across 71 countries. Spending expectations are rising and attacks on AI systems top respondents’ preparedness concerns, but the findings are self-reported perceptions—not audited resilience or incident rates.
Editorial responsibility: The Impact of AI Editorial Desk · Report a factual concern
Research topic
Whether rising cyber budgets and stated concern about attacks on AI systems translate into independently verified resilience, safer agent deployment and fewer material incidents

At a glance
- 1PwC surveyed 3,934 business and technology leaders in 71 countries from May to July 2026; 36% worked at companies with annual revenue of at least US$5 billion.
- 2Eighty-four per cent of security and finance leaders expected cyber budgets to rise, while 50% of security leaders placed attacks targeting AI systems among the threats they were least prepared to address.
- 3The survey measures senior leaders’ expectations and reported practices. It does not audit budgets, controls, breach rates, AI systems or whether PwC’s recommended services improve resilience.
The Impact Brief
Keep the evidence trail, not the noise.
Get the most consequential AI developments with direct sources and clear limits.
Living evidence record
Impact record IAI-0XORTK7
Evidence stage
Observed
Confidence
Supported
Reporting basis
Source analysis
Independent support
Not yet
Record status
Monitoring
Last checked
3 October 2026
Source trail
2 direct sources across 2 source types.
People impact
Documented in this record.
Uncertainty
Limits and next checks are explicit.
Stages describe the evidence available—not whether a technology is good or bad. See the public method.
Related-source reporting disclosure
This record analyses 2 linked source records around the same underlying development. The extra records add method, date or context, but they do not by themselves constitute independent replication of every performance claim or predicted outcome.
New analysis today — the report was released on 1 October
PwC’s 2027 Global Digital Trust Insights report says cybersecurity spending expectations are strengthening as organisations deploy more AI. The report and accompanying press release were published on 1 October. This article is new analysis today, not a claim that the evidence was released on 3 October, and it is not Breaking News. Both linked records come from PwC and describe the same survey, so they do not provide independent corroboration.
The headline finding is that 84% of surveyed security and finance leaders expected their cyber budgets to increase over the following 12 months, compared with 78% in the previous edition. Separately, 58% of security leaders placed AI among their leading cyber-budget priorities. These percentages describe anticipated budgets and priorities; the study did not inspect approved spending, completed purchases, security performance or return on investment.[1][2]
Who answered—and who the results best describe
PwC Research conducted the survey between May and July 2026. It collected responses from 3,934 business and technology leaders in 71 countries. Thirty-six per cent represented companies with annual revenue of at least US$5 billion. Financial services supplied 21% of respondents, technology, media and telecommunications 20%, industrial manufacturing and automotive 19%, retail and consumer markets 16%, healthcare 10%, energy and resources 10%, and government and public services 3%.
Regional coverage was Western Europe 32%, North America 26%, Asia Pacific 18%, Latin America 12%, Africa 5%, Central and Eastern Europe 4%, and the Middle East 3%. That breadth is useful, but the sample is weighted toward large organisations and Western markets. The public methodology does not disclose the recruitment frame, invitation count, response rate, country-by-country denominator, weighting scheme or full questionnaire wording, limiting replication and precise national comparisons.[1]
Concern about AI systems is high; measured preparedness is not shown
Half of security leaders selected attacks targeting AI systems among the cyber threats their organisations were least prepared to address, ahead of cloud-related threats at 40%, third-party breaches at 34% and ransomware at 33%. Within AI-enabled threats, respondents highlighted compromised autonomous botnets, adversarial attacks and data poisoning. These are rankings of perceived preparedness, not counts of incidents or controlled tests of defensive capability.
Only 39% of security, risk and operations leaders said they had a fully formalised and integrated continuity plan specifically addressing cyber risks. Across seven data-risk measures, organisations reported implementing an average of three, and 5% said they had implemented all seven. The publication does not present an external audit of those controls, define a common maturity threshold for every organisation or link each response to subsequent outage, loss or recovery outcomes.[1][2]
Most leaders are not ready to hand cyber defence to autonomous agents
Twenty-two per cent of respondents said they would authorise AI agents to execute defensive actions without human approval. Thirty-eight per cent would permit partial autonomy, while 36% preferred human-led execution with AI support. Organisations were most comfortable automating narrower tasks such as enriching threat intelligence, quarantining suspected phishing messages and removing malware. The survey does not test whether those actions were accurate, reversible or safer than human-led alternatives.
Reliability and technical maturity appeared among the top three barriers to greater agent autonomy for 55% of respondents; accountability and explainability were cited by 46%. Among chief information security officers, 44% identified workforce skills in AI oversight and governance as a barrier. Those responses support staged deployment with approval gates and independent validation, but they cannot establish which governance model reduces real incidents or how often human review catches an unsafe automated action.[1]
Impact on people and global context
For employees and customers, the practical issue is whether new spending protects the services and data they depend on. A larger budget can fund stronger identity controls, tested recovery plans and skilled security teams; it can also purchase poorly integrated tools that add alerts without reducing harm. Organisations should publish outcome measures such as detection time, recovery time, repeat incidents, unauthorised agent actions and the percentage of high-consequence decisions stopped for review.
The regional split prevents the report from being treated as a US-only survey, but small African and Middle Eastern shares mean the global percentage should not substitute for local evidence. Infrastructure, regulation, workforce supply, conflict exposure and dependence on managed services vary sharply between countries. The 3% Middle East and 5% Africa shares are too small for confident regional conclusions without disclosed denominators and uncertainty intervals.[1]
Evidence limits, commercial interest and what would change the assessment
PwC describes one of the world’s largest recurring surveys of senior cyber leaders, but the evidence remains cross-sectional and self-reported. Expectations can differ from approved budgets; stated controls can differ from implementation; concern can rise without an increase in attacks. The public materials do not publish confidence intervals, sampling weights, non-response analysis or respondent-level data. PwC also sells cybersecurity, AI, assurance and managed services, while the report recommends specialised support, creating a commercial interest that should remain visible.
Independent longitudinal evidence would strengthen the conclusions: audited spending, common control assessments, incident and recovery data, and pre-registered comparisons of organisations using different levels of agent autonomy. Country-level samples should expose denominators and uncertainty, particularly in under-represented regions. Until then, the report supports a narrower claim: senior leaders expect to spend more and feel underprepared for AI-related cyber risk; it does not prove that threats have increased by the same amount or that higher spending will make systems safer.[1][2]
What this means for people
- Workers may receive stronger tools and training, but they also need clear responsibility when an autonomous defence action disrupts legitimate work.
- Customers benefit only when higher spending produces tested continuity, faster recovery and better protection of personal and financial data.
- People in under-represented regions should not have a global percentage applied to their institutions without local samples and disclosed uncertainty.
Global context
The sample spans 71 countries, but Western Europe and North America account for 58% of responses, compared with 5% from Africa and 3% from the Middle East. The findings describe a large international executive sample, not the preparedness of every country, organisation size or public service.
What the evidence does not yet show
- Both linked sources are PwC publications based on the same survey; there is no independent replication of the reported percentages.
- The survey is cross-sectional and self-reported. It does not audit spending, controls, incidents, recovery performance or AI-agent decisions.
- The public methodology omits the recruitment frame, response rate, complete questionnaire wording, weighting details and uncertainty for subgroup estimates.
- PwC sells cybersecurity, AI, assurance and managed services, giving it a commercial interest in the subject and recommendations.
What to watch next
- Audited 2027 spending and resilience outcomes, including detection, recovery and repeat-incident measures rather than budget intentions alone.
- Independent comparisons of human-led, partially autonomous and fully autonomous cyber-defence workflows, including false actions and reversibility.
- Country-level denominators and uncertainty for Africa, the Middle East, Latin America and Asia Pacific in future survey releases.
Evidence trail
Sources used for this report
Links checked 3 October 2026
This report is labelled source analysis. We summarise and analyse source material in our own words; company statements remain attributed claims until independently supported. Translated summaries preserve the meaning of the original source and link back to it. Read our editorial standards.
Continue the story
Related reporting
Security & Defence
What must Australian agencies change after the new AI-enabled cyber direction?
A binding direction requires non-corporate Commonwealth entities to inventory and plan down legacy-technology risks. It sets deadlines and a reporting route, but leaves agencies to define the depth of their own stocktakes.
4 min · 2 sources
Security & Defence
Is AI changing cyberattacks—or speeding up familiar tactics?
Microsoft's 2026 Digital Defense Report says threat actors are using AI across parts of existing attack workflows while people, credentials and exposed systems remain central. Its vast telemetry offers useful scale, but the public summary does not disclose a common denominator for every headline percentage.
9 min · 2 sources
Security & Defence
Did AI agents hack government websites—or only attempt to?
Canada has issued a government-wide cyber direction for the frontier-AI era, while California is compelling information from OpenAI. Neither action proves that the reported Canadian activity breached a government system.
10 min · 5 sources
Reader discussion
Add evidence, experience or a question
No account is required. Reader notes are published after a brief civility, relevance and safety check; disagreement is welcome.
Published reader notes
0No published reader notes yet. You can start the evidence-led discussion above.
Prefer a private correction or response? Contact the newsroom.