Eighty-five per cent of Indian enterprises surveyed by cybersecurity vendor ESET reported at least one artificial-intelligence-related cyber threat during the past twelve months, according to a Newspatrolling summary of the study published ahead of 25 September. The poll covered 400 IT and security decision-makers across manufacturing, banking, technology services and government-linked contractors, highlighting how generative AI adoption outpaced defensive playbooks.
What counted as an AI-related threat
ESET’s questionnaire grouped incidents that would not have scaled without machine-learning tools: deepfake audio used in CEO fraud, large-language-model-generated phishing at native language quality, malicious plugins targeting copilots, and adversarial attempts to poison internal retrieval-augmented generation corpora. Respondents also cited AI-assisted vulnerability scanning by attackers probing exposed APIs faster than human red teams could rotate keys.
The 85 per cent figure is self-reported, not a CERT-In census, but it aligns with anecdotal casework from Mumbai and Bengaluru SOCs that saw ticket volumes spike after enterprises turned on Microsoft Copilot, Google Gemini or domestic chatbots tied to customer support.
Who felt it most
Banks and NBFCs reported the highest incidence of voice-clone wire fraud attempts, especially around month-end treasury transfers. IT services firms saw spear-phishing targeting developers with fake pull requests generated to resemble internal style. Manufacturing respondents worried about IP exfiltration through employees pasting CAD snippets into public chat models against policy.
Defensive gaps
Only a minority of respondents told ESET they had formal policies governing training data residency for third-party models, Newspatrolling’s recap noted. Many relied on legacy email gateways not tuned for LLM-crafted lures that vary syntax per recipient. Security operations centres still budgeted for signature-based malware even as attackers used AI to mutate payloads hourly.
India’s MeitY push on indigenous AI makes the timing sensitive: incentives to deploy models quickly can collide with CERT-In directions on logging and incident reporting if teams skip architecture reviews. ESET’s marketing angle is endpoint and XDR coverage, but the underlying data point is vendor-neutral: AI lowered attacker cost.
Regulatory backdrop
CERT-In’s six-hour incident reporting rule and KYC-style logging for specified entities already pressured CISOs; AI incidents add ambiguity about what qualifies as a reportable breach when no files were encrypted. MeitY’s draft AI safety frameworks emphasise consent and audit trails, which help forensics after a deepfake payment but do not block initial clicks.
Insurance underwriters have begun asking about AI usage questionnaires on cyber policies; the ESET survey gives brokers a statistic to justify higher premiums or mandatory controls.
What security leaders are doing
Enterprises interviewed in trade press follow a common trio: block paste into public models on managed devices, deploy outbound DLP on code repositories, and run tabletop exercises with synthetic audio samples. Red teams commission jailbreak tests against internal copilots before HR or finance workflows attach. None of that is universal; the 85 per cent incidence suggests many learned after the first incident.
Shared intelligence through ISAC forums remains thin on AI-specific indicators because vendors classify detections differently. ESET urged cross-sector sharing; practitioners want IOC formats that include prompt hashes and model version IDs. Several banks told the survey they now record synthetic-media attempts in the same case management queue as wire fraud, which helps compliance teams spot repeat callers.
What builders should watch
Vendor procurement teams are extending security questionnaires to model hosts, asking whether training logs can leak customer prompts. Several respondents in ESET’s sample reportedly blocked USB exfiltration paths after discovering employees used personal ChatGPT accounts for contract review, a policy violation that still counts as an AI-related near miss in the survey taxonomy.
For Ananya Krishnan’s AI desk, the ESET number is not a forecast but a rear-view mirror: four in five enterprises already touched by AI-enabled abuse. Pair that with MeitY’s parallel push for domestic models and agentic government bots, and the security story is supply-side innovation racing demand-side hardening. The next India AI summit soundbite may be growth; SOC managers will cite 85 per cent until budgets catch up.
