Data Breaches are Inevitable. Minimize their Impact with Fully Optimized Homomorphic Encryption
January 8, 2025
Naked AI: DeepSeek’s Data Blunder Exposes the Emperor’s New Clothes 
January 30, 2025

Prediction 1: Companies Will Elevate Data Protection with the Expanding AI Attack Surface

By Ravi Srivatsav, CEO

2025 Cybersecurity Predictions

In this blog series, we’ll unpack each of our 2025 cybersecurity predictions and look deeper into the trends we expect to gain prominence in the coming months.

A delicate balance: fostering innovation and minimizing risk

In cybersecurity, the rapidly expanding attack surface and increasing sophistication of attack methods drive the innovation of new tools and technologies to combat such threats. However, the advent of artificial intelligence (AI) has created a different scenario for businesses around the globe. As companies have flocked to use AI and accelerate innovation, they now face greater risks.

We now see companies grappling with a serious dilemma: do they expand the use of AI to hasten innovation, or should they limit or outright ban its use, given heightened concerns about data exposure when training AI models? This growing divide creates obstacles for companies in improving efficiencies and offering cutting-edge products and services, as they limit employees’ reliance on AI for fear of compromising sensitive data – and the organization’s brand value.

Our prediction is that in 2025, the friction between AI-driven possibilities and risks will drive companies to implement more stringent data privacy policies while leveraging technologies that offer stronger protection and keep data out of malicious hands.

The Dark Side of AI

The unfortunate truth about AI is that it can increase companies’ exposure to data risks and vulnerabilities due to its widespread adoption and integration into critical business processes. These risks are prevalent in the areas of data exposure and data poisoning, as described below.

Data Exposure Risks

  • Sensitive Information Disclosure: When employees use open AI models and generative AI (genAI) tools, they can inadvertently expose sensitive data, such as intellectual property or personally identifiable information (PII), to untrustworthy parties. This risk is exacerbated by assumptions that AI systems inherently protect private data and can lead to incidents of unintentional disclosure through model outputs or compromised systems.
  • Insider-Driven Data Loss: Employees may unknowingly input sensitive company information into AI tools, which can lead to data exfiltration or leakage. GenAI tools, especially unsanctioned ones, pose significant risks as companies often lack visibility into how these tools handle sensitive data.
  • AI Breaches: A March 2024 study conducted by HiddenLayer revealed that 77% of businesses experienced AI-related breaches the previous year, exposing sensitive data and intellectual property. Such breaches disrupt operations and pose financial and reputational risks. (It’s worth noting that the same study cited that 98% of IT leaders consider their AI models crucial to business success, underscoring the inherent AI dilemma we mentioned earlier.)

Data Poisoning Risks

  • Manipulation of Training Data: Data poisoning involves injecting harmful or deceptive data into AI training datasets, which can skew model behavior. This leads to flawed predictions, biased outputs, or even model failure. For example:
    • Financial models may fail to detect fraud.
    • Healthcare diagnostics could recommend harmful treatments.
    • Security systems might misidentify individuals or allow unauthorized access.
  • Targeted Attacks: Cybercriminals exploit open-source datasets or enterprise AI systems to introduce malicious data. These attacks can cause integrity violations such as backdoor access, resulting in a major data breach, or availability issues and system-wide degradation, rendering a company’s website and/or applications inoperable.
  • Amplification of Biases: Poisoned datasets can amplify existing biases in AI systems, leading to discriminatory outcomes in applications like hiring decisions or law enforcement surveillance.

The risks of AI are growing due to the increased adoption of genAI tools and Large Language Models (LLMs) like ChatGPT, which expand the attack surface. Additionally, the growing accessibility of malicious tools like FraudGPT, a generative AI tool designed to assist cybercriminals in conducting sophisticated attacks such as phishing, malware creation, and other forms of digital fraud, enables attackers to automate and scale data poisoning attacks.

The best of both worlds: innovate with AI and protect your data

To address these risks, there are proactive measures organizations can (and should) adopt that will become paramount in the coming months:

  • Limit or prohibit the use of open AI models, relying instead on closed models to minimize data exposure.
  • Implement robust data governance practices, such as access controls and regular monitoring, to limit malicious data access.
  • Foster security awareness among employees to minimize insider-driven risks and ensure the responsible use of AI tools.

While these measures are important and necessary, another option exists to ensure that data is protected and inaccessible to cyber attackers if they should succeed in hacking AI models – leveraging Fully Homomorphic Encryption (FHE) to ensure data protection. While other steps can prevent bad actors from accessing sensitive data, they are not 100% failproof.

FHE allows data to be processed and in transition while still encrypted, so data is never “in clear” or unprotected. With AI and AI models, FHE can protect source data and intellectual property (IP) so that when attackers penetrate defensive perimeters, FHE ensures that any sensitive data they acquire can’t be used, tampered with, or poisoned.

In 2025, the balance between harnessing AI’s transformative potential and mitigating its growing risks is shaping the cybersecurity landscape. Organizations must embrace innovation with eyes wide open, adopting robust strategies like limiting open AI models, fostering security awareness, and prioritizing advanced solutions such as FHE. Only then can businesses turn AI’s challenges into opportunities, ensuring that innovation flourishes without compromising data integrity or trust.