Vanta's 2025 State of Trust Report reveals that a majority of organizations are facing unprecedented security risks, with 69% of UK companies reporting higher threats than ever before, largely due to the rapid evolution of AI-driven cyber attacks. The report highlights that 53% of business and IT leaders believe AI cyber threats are advancing faster than their security teams' expertise, with significant increases in AI-generated phishing, malware, and identity theft incidents. Despite these challenges, 80% of organizations are either using or planning to use AI agents to bolster their defenses, though 61% admit their understanding of agentic AI lags behind its deployment. The findings underscore a critical need for balance between leveraging AI for security and ensuring teams are equipped to manage the associated risks.
Industry analysis further emphasizes that compliance and security are often conflated, with many organizations spending excessive time on manual compliance tasks rather than proactive security measures. The Vanta report and related commentary stress the importance of automation, innovation, and demonstrable security practices to build customer trust. As AI continues to reshape the threat landscape, organizations are urged to modernize their security operations and invest in both technology and expertise to keep pace with evolving risks.

Track how attackers are adapting to this technology.
2 events from the most recent confirmed update back to the earliest known activity.
A follow-on industry analysis discussed the intersection of AI and trust, reinforcing the report's themes around AI-related risk, governance, and organizational readiness. This represented broader interpretation of the report rather than a separate incident.
Vanta released its State of Trust 2025 report highlighting that AI-driven threats are advancing faster than organizations' available security expertise. The report framed AI risk and trust as a growing governance and security challenge.
Follow how adversaries are adapting to this technology, and where it touches your stack today.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.