The AI Gold Rush Is Creating a Three-Headed Risk

Organizations are racing to adopt AI, but weak security, poor implementation and limited expertise are causing failed investments, lost value and a rapidly expanding attack surface.

Share
The AI Gold Rush Is Creating a Three-Headed Risk
Photo by Igor Omilaev / Unsplash
Organizations are racing to implement AI, often driven by the fear that competitors will move faster.

This pressure is real: McKinsey reported that 78% of surveyed organizations were already using AI in at least one business function, up from 55% the previous year.

However, rapid adoption does not guarantee business value. A widely reported 2025 MIT NANDA study found that 95% of the enterprise generative-AI pilots it examined were not delivering measurable financial returns.

The problem was not necessarily the AI models, it was poor integration, misaligned priorities and systems that failed to learn from organizational workflows.

đź’ˇ
Heavy AI marketing has also created space for "AI-washing": vendors whose claims exceed their actual technical capability. Builder.ai, once valued above $1 billion and backed by major investors, entered insolvency after revenue restatements, financial problems and long-running questions about how much of its supposedly AI-driven development was actually performed by people.

The security consequences are equally real. In 2025, researchers discovered that an administrator account associated with McDonald’s AI-powered recruitment platform used the credentials "123456".

The weaknesses could have exposed information connected to millions of applicant conversations, including names, email addresses and phone numbers. The vendor subsequently fixed the vulnerabilities. Wired documented the incident.

This creates a three-headed problem:

  1. Security debt: AI is deployed before access controls, governance, monitoring and testing are ready. IBM found that, among organizations reporting breaches involving AI systems, 97% lacked proper AI access controls.
  2. Financial loss: Poorly selected projects consume money without producing measurable business outcomes.
  3. A widening attack surface: Inexperienced teams connect models and agents to sensitive data, credentials, APIs and enterprise systems. More than one-third of cybersecurity professionals have identified AI as their teams’ biggest skills shortfall, according to ISC2 research.

The AI race will not be won by the organization that deploys first. It will be won by the organization that deploys AI securely, measures its value and builds it with people who understand both the technology and its risks.

SPONSORED
CTA Image

At RabitaNoor, we believe AI security must extend beyond the model itself. Identity, permissions, tools, data, runtime environments, network access and auditability all need to be treated as part of the AI security boundary.

Learn more