Global EV Outlook 2025, expanding sales in diverse markets

Based on a global survey of 4,000 professionals—800 cybersecurity decision makers and 3,200 employees—the report examines how agentic AI is changing human-related cybersecurity risk.
It finds that everyday mistakes are the leading source of impact, while AI adoption is expanding faster than governance: 58% of cybersecurity leaders report that AI tools or agents are taking actions autonomously in multiple workflows, yet only 48% say AI use is formally approved and governed.
The report also highlights growing exposure to AI-enabled attacks, with 86% of employees saying deepfakes are now realistic enough to make it harder to know what to trust.
The report assesses organizational maturity in managing human and agent risk and identifies an integrated, culture-embedded approach as the most mature model.
Only 19% of organizations report operating at this level, compared with 34% that remain awareness-led.
The findings emphasize that awareness alone does not reliably translate into secure behavior, particularly under time pressure or distraction; instead, organizations need to embed security into workflows, reinforce behavior through guidance and systems, and integrate awareness, behavior and governance.
Trust and psychological safety are presented as important drivers of resilience.
More supportive, coaching-led responses to mistakes and learning-oriented phishing simulations are associated with stronger security-culture outcomes.
The conclusion calls for organizations to design systems that guide behavior, create supportive environments for reporting and learning, reinforce positive actions, and extend a security-first mindset across both employees and AI agents.
Access the full report.

