According to Kaspersky’s latest research, 41% of enterprises globally say AI adoption has prompted them to increase investments in information security. Across APAC, organisations are embracing AI at different stages of maturity, with businesses across the region reporting varying levels of concerns over AI vulnerabilities, deepfakes and employees’ use of third-party tools.
The growing threat of AI vulnerabilities
The survey conducted by Kaspersky's internal research centre revealed that 13% of enterprises across APAC identify AI vulnerabilities among their top cybersecurity threats. While software vulnerability exploits (20%) and phishing (19%) remain the leading cybersecurity concerns, AI-related risks are emerging as an increasingly important consideration for organisations across the region.
Concern over AI vulnerabilities also varies across APAC. India recorded the highest proportion of organisations identifying AI vulnerabilities (20%), followed by Malaysia (15%), Thailand and Vietnam (13% each), Indonesia (10%) and China (7%).
Employee-driven risky behaviors
External threats are not the only reason organisations perceive AI as a growing security concern. An equally significant danger comes from employees who, often in a mass and uncontrolled manner, use third-party AI tools such as ChatGPT and DeepSeek for work tasks, a phenomenon known as “Shadow AI”.
The survey highlights that 30% of respondents across APAC identified this behaviour as a common risk factor. India (36%) and Malaysia (35%) recorded the highest proportion of organisations reporting employees' use of external AI tools, followed by Vietnam (33%), China (31%), Indonesia (24%) and Thailand (18%). The results emphasise the urgent need for careful management and regulation of external AI solutions to mitigate potential data leaks and security breaches.
Moreover, many organisations have yet to fully control how their employees use such tools. According to the survey, 60% of organisations across APAC permit the use of third-party AI tools under certain restrictions such as prohibiting the uploading of company names or internal documents, while providing guidelines and training for their safe use. This approach is consistent across several markets, including China (62%), India, Malaysia and Vietnam (61% each).
Strategic AI development plans
The pace of AI integration across organisations in APAC remains rapid, despite associated risks. An impressive 85% of companies are actively discussing, developing or piloting internal AI tools powered by Large Language Models (LLMs), while 10% have already integrated these technologies into their workflow.
For organisations that have adopted their own internal AI solutions, the primary drivers are improved decision-making, increased process efficiency and reduction in human error. These motivations underscore a strong organisational commitment to leveraging AI as a means to gain a competitive edge and achieve operational excellence.
"One of the clearest shifts we are seeing is that organisations are moving beyond asking whether AI has a place in the business and trying to determine how it should be adopted responsibly. This reflects a transition in digital transformation, where success is no longer measured by deploying new technologies but through an enterprise's ability to understand the risks, establish the right governance and build trust as adoption scales. Businesses that integrate cybersecurity into their AI strategies from the beginning will be better positioned to innovate with confidence as AI adoption matures," added Adrian Hia, Managing Director for Asia Pacific at Kaspersky.
To protect companies against emerging AI-related threats, Kaspersky recommends:
● Applying all-encompassing solutions from the Kaspersky Next product line to provide real-time protection, threat visibility, investigation and response capabilities of EDR and XDR. Its AI-driven capabilities are used to automate and optimise security processes, helping teams operate more efficiently and reduce manual workload and skill gaps. Generative AI models within the platform enable rapid conversion of collected data into structured, actionable information for security teams and decision-makers.
● Equipping your cybersecurity team with in-depth visibility into cyber threats targeting your organisation. The latest Kaspersky Threat Intelligence delivers rich, contextual insights throughout the entire incident management cycle, enabling timely identification of cyber risks. Machine learning and generative AI support malware classification, analysis of large-scale threat data, and AI-generated summaries of indicators of compromise, enabling security teams to make faster and more informed decisions.
● Enterprises can also explore how advanced AI features can strengthen their cybersecurity through Kaspersky expert guidance that is tailored to their specific environment.
See What’s Next in Tech With the Fast Forward Newsletter
Tweets From @varindiamag
Nothing to see here - yet
When they Tweet, their Tweets will show up here.




