
The information displayed in the AIM should not be reported as representing the official views of the OECD or of its member countries.
A 2026 Eset report reveals that 73% of global companies use AI technologies, but 40% lack policies restricting unapproved AI applications. This gap has led to increased cybersecurity incidents, including data breaches, theft of API keys, and AI-powered fraud, as organizations struggle with shadow AI and malicious AI agents.[AI generated]
Why's our monitor labelling this an incident or hazard?
The article explicitly discusses AI systems being used maliciously or misconfigured, leading to actual cybersecurity incidents such as data breaches, unauthorized access, and fraud. The presence of AI-enabled threats like malicious AI plugins and AI bots that manipulate social processes confirms direct harm caused by AI systems. The lack of governance policies enabling 'shadow AI' usage further contributes to these harms. Since these harms are realized and directly linked to AI system use and misuse, the event qualifies as an AI Incident under the framework definitions.[AI generated]