Gartner: AI-Driven Vulnerability Discovery Emerges as Top Emerging Cyber Risk
Companies now perceive AI's ability to discover cyber vulnerabilities as the highest impact emerging risk, surpassing information integrity threats.

A recent survey by Gartner has identified the AI-driven discovery of cyber vulnerabilities as the most significant emerging risk facing organizations today. The finding represents a dramatic shift in perception, with this threat jumping to the forefront in just a three-month period, overtaking concerns previously held about information integrity.
The accelerated pace of vulnerability identification is attributed to two key factors: the sheer volume at which AI systems can scan for previously unknown flaws, far exceeding human patching capabilities, and the drastically reduced time it takes to develop working exploit code from a discovered vulnerability. Historically, the complexity of exploit development served as a significant barrier to attackers; however, this barrier is rapidly diminishing.
This evolving landscape presents defenders with a growing backlog of unpatched critical vulnerabilities, exacerbated by the increasing complexity of AI-integrated systems, which can make them harder to secure and monitor. The survey, which polled risk managers, auditors, and senior executives from 316 companies, indicated that respondents assigned this risk a time frame score of 1.92 on a scale where 1 signifies impact within a year, placing the average expectation just under two years.
Geographically, the concern is widespread, with AI vulnerability discovery ranking first in all four surveyed regions: Europe, Asia-Pacific, the Americas, and the Middle East and Africa. The financial sector, including banking, financial services, and insurance, reported the highest concern at 78%, slightly above other industries at 74%. This broad consensus underscores the pervasive nature of the threat across diverse business environments.
Despite ranking AI vulnerability discovery as the top impact risk, respondents also rated themselves as the most prepared to handle it. This self-reported preparedness, measured on a five-point scale, suggests that organizations are actively discussing the risk and implementing measures. However, Gartner analysts caution that this preparedness assessment may not fully account for the actual capabilities driving the risk to the top of the list, potentially leading to a false sense of security.
Kevin Mercado, Senior Principal Analyst at Gartner, emphasized the challenge traditional risk management approaches face in keeping pace with AI's advancements. He noted that without corresponding improvements in governance, security operations, and remediation, AI-driven vulnerability discovery could outpace organizational defenses, increasing the likelihood of severe cyber incidents and operational disruptions.
Gartner recommends several actions for organizations to recalibrate their defenses. These include reassessing the impact assigned to cyber risks, revisiting risk appetite for continuous exposure, demanding stronger security validation from vendors, and accelerating vulnerability management towards more automated remediation processes. The survey also highlighted that AI vulnerability discovery is notably absent from the list of risks where companies see the most business upside, such as AI-driven competitive displacement or agentic AI.
The findings paint a stark picture of a rapidly changing cybersecurity threat landscape, where the very tools designed to enhance efficiency and innovation also present unprecedented challenges. As AI capabilities continue to grow, organizations must proactively adapt their security strategies to effectively manage the escalating risks associated with AI-driven vulnerability discovery.