Russian software developers are implementing artificial intelligence significantly faster than they are able to protect it. In a study by AppSec Solutions and ARPP "Otechestvenny Soft", all surveyed companies reported using AI, but only 23% implement basic AI security control measures.
The most common tool is large language models: 81% of participants use them. Another 72% use AI assistants for working with code, and the same number have already integrated AI agents into the corporate network, effectively delegating some employee responsibilities to them.
However, the feeling of security may be deceptive. Only 4% of companies reported confirmed attacks, but over 90% have not conducted a full threat assessment at all. Therefore, the absence of recorded incidents does not yet mean that they truly did not occur.
A separate problem is so-called shadow AI. Employees of all surveyed organizations use external AI services: in 41% of companies, this is already a widespread practice, and in another 59%, it is partial. At the same time, people can send internal documents and other sensitive data to such services without centralized control from the employer.
Among the main risks, experts name confidential data leaks, prompt injections, leaks through RAG systems, bypassing built-in restrictions, and attacks on the ML supply chain. The study specifically highlights the segment of medium-sized IT companies with 100 to 500 employees, where, according to the authors, the greatest potential and risk of AI application are concentrated, and where decisions are often made "manually".