A new report from global technology company Thales reveals how global IT and security professionals at retail organizations across 20 countries view data security in the age of AI. The report illustrates how AI security stacks up against other security operations and data security initiatives:
Key findings from the report:
- Spending on AI security is rising: 32% of retail organizations have a dedicated budget for AI security, while 52% fund it through existing security budgets.
- The speed of AI development puts security teams on the back foot: 72% of retail organizations cite rapid changes in AI ecosystems as their leading security concern, undermining the ability of traditional tools to keep pace.
- AI Attacks are Already Hitting Retailers: 61% of respondents have already experienced deepfake attacks, and 48% have suffered reputational damage from AI-generated misinformation.
- Identity is the Primary Target: 51% of retailers rank identity and access management as a top-three security priority as attackers increasingly exploit user credentials.
- Human Error vs. Geopolitical Threats: Nation-state attackers and hacktivists were cited as the top security concerns; however, reality shows that 27% of retail organizations reported human error as the leading cause.
The full report is available here.
Todd Moore, Global Vice President of Encryption Products at Thales, said the biggest challenge is that AI is moving faster than most organizations can adapt.
“Retailers are trying to secure an environment that’s changing every few weeks, not every few years. The first thing they need to do is get visibility into their data. Our research found that only 37% of retailers say they know where all of their data is stored, and if you don’t know where your sensitive data lives, you can’t protect it from AI or anything else,” he said.
“Over the next year, I’d focus on discovering and classifying your data, strengthening identity controls, and encrypting your most sensitive information. Those fundamentals become even more important in an AI-driven world.”

Moore said AI has dramatically lowered the cost of deception.
“A fake executive voice, a fraudulent customer support message, or convincing misinformation about a brand can all be created in minutes. Retailers have always worried about protecting transactions, but now they also have to protect trust,” he said.
“The answer is stronger identity verification, better monitoring for abnormal behaviour, and making sure employees know how to recognize AI-enabled social engineering. Ultimately, the organizations that verify identities instead of simply trusting what they see or hear will be much better positioned.
Moore said attackers have realized it’s often easier to log in than to hack in.
“AI makes phishing, credential theft, and impersonation much more convincing, so identities have become the new perimeter. Once someone steals legitimate credentials, they can often bypass traditional security controls,” he explained.
“The mistake many retailers still make is thinking about identity as just an employee login problem. Every customer account, API, machine identity, and now AI agent needs to be authenticated and governed. As AI creates more digital identities, identity security becomes the foundation for everything else.”
The report suggests that nation-state actors and hacktivists dominate security concerns, yet human error remains the leading cause of many incidents. Why is there still such a gap between perceived threats and the realities retailers face?

“I think it’s human nature. We worry about the sophisticated attacker we see in the headlines, but most breaches still start with everyday operational problems such as a misconfiguration, a stolen credential, or someone clicking the wrong thing. Our research found human error remains the leading cause of breaches, and complexity is a big reason why. Security teams are managing more tools, more cloud environments, more identities, and now AI. The simpler you can make your security operations, the fewer opportunities there are for mistakes,” noted Moore.
“I don’t think organizations necessarily need a completely separate AI security budget, but they do need to avoid treating AI as a bolt-on project. AI touches your identity systems, your cloud infrastructure, your data, and your applications. If you’re simply moving money from one security priority to another, you may create gaps somewhere else. The best investment is strengthening the foundation by knowing where your data is, encrypting it, protecting identities, and simplifying your security architecture. Those investments pay off whether you’re defending against traditional attacks or AI-powered ones.”
More from Retail Insider:












