Enterprise GenAI Amplifies Ransomware Risk Through Delegated Authority
Generative AI tools in the enterprise, while boosting productivity, can significantly amplify ransomware risks by granting excessive permissions to AI assistants and agents, according to Acronis.

The rapid integration of generative AI into enterprise workflows presents a dual-edged sword, promising unprecedented productivity gains while simultaneously introducing new vectors for sophisticated cyberattacks. As AI assistants and agents become more embedded in daily operations—summarizing documents, searching knowledge bases, and automating tasks—they increasingly gain access to the same sensitive data and systems that ransomware actors actively target. This convergence means that if not properly governed, AI can accelerate the speed and scale of ransomware attacks, rather than creating entirely new threat landscapes.
Acronis highlights two primary threat models: attackers leveraging AI to enhance their own operations and organizations deploying enterprise AI that inadvertently expands the attack surface. The former involves using AI for generating phishing emails, writing malicious code, and automating reconnaissance. The latter, and the focus of Acronis's concern, is when compromised AI systems within an organization can be used by attackers to rapidly locate sensitive information, navigate internal systems, and abuse legitimate access.
The core issue lies in delegated authority. Modern ransomware attacks typically begin with initial access through vulnerability exploitation or credential compromise, followed by reconnaissance, privilege escalation, data identification, and exfiltration. AI-enabled applications, particularly AI agents that interact with business applications and execute workflows, can dramatically shorten this timeline if the identities or permissions associated with them are compromised. Microsoft reports analyzing approximately 38 million identity risk detections daily, underscoring the critical role of identity in current attack strategies.
When an AI assistant is connected to an enterprise knowledge base, an attacker with compromised credentials could bypass manual searching and directly ask the AI to locate sensitive documentation, administrative procedures, or financial records. Similarly, an AI agent with permissions to send emails or export files could be abused to accelerate data theft. The risk is not inherent to AI itself, but stems from excessive access granted to these systems, insecure integrations, and insufficient oversight.
While prompt injection remains an AI-specific application-layer vulnerability, it is only one facet of the broader risk. Malicious instructions embedded in documents or web content can influence AI behavior when processed by enterprise applications. Security guidance from organizations like OWASP emphasizes layered controls, least privilege, and human approval for high-risk actions as crucial mitigation strategies, rather than relying solely on prompt filtering.
Evidence suggests AI is already making cybercrime more efficient. For instance, the GTG-2002 threat group reportedly used AI to generate and debug scripts, assist with credential harvesting, and personalize extortion communications. The GLOBAL GROUP ransomware operation even introduced an AI chatbot to automate ransom negotiations post-compromise, demonstrating how AI can streamline attacker operations without fundamentally altering the infection chain.
To combat these amplified risks, Acronis proposes its GenAI Protection solution. This tool aims to identify shadow AI usage, monitor AI interactions, detect policy violations, and provide visibility into AI-related risks. By integrating this with existing telemetry from endpoints, identities, SaaS applications, and backups, organizations can strengthen their detection, response, and recovery capabilities for AI-powered workflows.
Ultimately, the secure adoption of AI within enterprises hinges on extending robust identity controls, strict governance, and the principle of least privilege to these new technologies. Without these foundational security measures, the very tools designed to enhance productivity could inadvertently become powerful accelerators for cybercriminals.