eCommerceNews US - Technology news for digital commerce decision-makers
United States
AI security gap grows in ERP systems, Onapsis warns

AI security gap grows in ERP systems, Onapsis warns

Fri, 31st Jul 2026 (Today)
Joseph Gabriel Lagonsin
JOSEPH GABRIEL LAGONSIN News Editor

Onapsis has released its first report on AI, security and ERP systems, finding that 22% of organisations reported a security incident in the past year in which attackers used AI to exploit a critical business platform.

The findings point to a widening gap between the pace of AI adoption in core business software and the confidence of security leaders responsible for protecting it. The report surveyed 204 senior cybersecurity leaders at US organisations with more than 1,000 employees across sectors including financial services, manufacturing, healthcare and utilities.

Concern about AI-related risk remains high, yet many organisations are already embedding the technology into enterprise resource planning environments. The study found that 58% had started using AI-based applications or agents that touch ERP systems within the previous six months, while 86% had already integrated, or planned to integrate shortly, AI directly into ERP code.

That rapid uptake is accompanied by weak trust in current safeguards. Seven in 10 senior cybersecurity leaders said they had only some trust, or no trust at all, in AI to secure business-critical data. Nearly 68.6% said they were not confident their existing security defences could detect an AI-based attack.

Internal resistance

The survey also found growing opposition within companies over whether AI should be allowed near the most sensitive operational and financial data. Almost 57% of respondents said at least one business unit had objected to implementing AI within the ERP environment.

Security teams were the most resistant group, cited by 41.4% of respondents, followed by IT teams at 20.7%. The main reasons for pushback were lack of confidence in AI security, cited by 75%, and compliance risk, cited by 71.6%.

These results suggest the debate over AI in back-office systems is no longer centred only on innovation budgets or productivity gains. It is also becoming a governance issue, particularly in platforms that hold payroll, procurement, finance, supply chain and other data companies consider sensitive or mission-critical.

The research also showed mixed views on who should take primary responsibility for protecting that data as AI use expands. A majority of respondents, 54%, said the responsibility sits with senior cybersecurity leaders, while nearly 47% said they expect ERP vendors to embed enough security into their platforms to ensure critical data is not compromised.

Confidence gap

The report highlighted several conditions respondents said would be needed to build trust in AI inside ERP systems. The most commonly cited requirement was robust access management controls, chosen by 61.8% of those surveyed. Strong personal data protections followed at 45.8%, while 36.8% pointed to sandboxing or digital twin environments.

That emphasis reflects concern about what happens when AI tools are granted direct access to large stores of operational data and embedded into software that runs core business processes. ERP systems often serve as the record of truth for a company's transactions and workflows, making them attractive targets for attackers and high-risk environments for experimentation.

Adoption is also arriving as many organisations rethink their ERP estates more broadly. More than half of those surveyed, 56%, said they were pursuing or planning an ERP transformation project within the next year, a shift that could further increase the number of AI integrations under consideration.

Mariano Nunez, chief executive officer and co-founder of Onapsis, said the report showed AI deployment is moving faster than many organisations' security planning.

"Allowing AI to expand unchecked while integrating it into the core framework of a business without robust security and compliance guardrails is highly perilous," said Mariano Nunez, chief executive officer and co-founder of Onapsis.

He said the issue requires closer coordination between technology and security decision-makers.

"Regrettably, this scenario has become a reality for numerous enterprises. The critical message from our research is that senior security professionals and executive leadership must remain completely aligned regarding their AI implementation strategies. We cannot allow technological deployment to outpace our defenses, nor should security measures impede artificial intelligence advancement," Nunez said.

The survey covered organisations using major ERP systems, including SAP, Salesforce and Oracle. SAP users made up 49.8% of respondents, followed by Salesforce at 31.2% and Oracle at 19%.

The findings add to a broader industry debate over how companies should manage AI risk in systems that sit deep inside finance, operations and supply chains. With adoption advancing despite internal objections and low confidence in current detection tools, the survey suggests many large organisations are entering the next phase of AI deployment before resolving who is accountable for securing it.