89% of Enterprises Hit an AI-Enabled Attack This Year. 41% Have a Governance Policy For It.

BCG’s newest cybersecurity analysis puts a number on a gap enterprises have mostly been guessing at: 89% of organizations experienced an AI-enabled attack in the past year, and 35% say it caused significant financial or operational impact — yet only 41% have a formal AI governance policy, and just 23% actively monitor or log what their AI agents are doing. The average organization now logs three major breaches and 25 sensitive-data incidents annually. Budgets are moving — cybersecurity spending rose 12% in 2025 and over 80% of security leaders plan further increases into 2027 — but BCG’s report argues the dollars are spreading thinner: security teams are now expected to cover agents and models alongside the infrastructure they already owned, and adoption of AI-specific controls like shadow-AI monitoring and prompt-injection detection sits under 20%.

Gartner’s own AI-security forecast, published a day earlier, quantifies where that spend is actually landing: the market for securing AI will hit $4.8 billion in 2027, a 68.7% jump from 2026, and nearly $7.7 billion by 2028. AI usage control — governing how employees and agents actually use AI day to day, not just locking down the underlying model — is the fastest-growing segment at 73% growth, ahead of AI gateways at 70.9%. Gartner sharpens BCG’s governance gap into a specific failure mode: by 2029, the firm expects more than half of successful attacks on AI agents to exploit access-control weaknesses and prompt injection specifically — the exact category of control BCG finds fewer than one in five organizations has deployed today.

Vendor consolidation is compounding the pressure. BCG reports frontier AI labs and incumbents like CrowdStrike and Microsoft are winning the bulk of AI-security purchases, while CISOs have already consolidated vendors across 18 of 24 tracked product categories — leaving less room for point solutions to compete on anything but integration ease.