Antes de investir em IA, faça estas quatro perguntas à empresa

AI-related incidents are rising in Portugal

The adoption of Artificial Intelligence is transforming the way businesses operate, but it is also creating new cybersecurity challenges. In Portugal, the latest data shows that vulnerabilities associated with AI are no longer a distant concern. They are already materialising in real-world incidents.

According to the Hiscox Cyber Readiness Report 2026, 92% of Portuguese businesses that experienced cyberattacks reported at least one incident associated with new AI-related vulnerabilities over the past 12 months. In 2025, that figure was 48%.

The increase is not limited to the number of businesses affected. The average number of incidents associated with new AI vulnerabilities rose from 1.60 to 3.48 per business, an increase of approximately 118%.

These figures raise an important question for any organisation integrating AI into its processes: are we accelerating technology adoption at the same pace as we are strengthening security?

 

AI is creating new points of exposure

Artificial Intelligence can help businesses automate tasks, analyse information and improve decision-making. However, its integration also introduces new technological components, data flows, permissions and external dependencies that need to be assessed.

Among Portuguese businesses that experienced cyberattacks, 24% identified an AI tool or software as one of the entry points for successful attacks.

This highlights the importance of understanding not only which tools are being used across the organisation, but also what data they process, which systems they can access and what security controls are in place.

The use of AI solutions without the knowledge or oversight of IT and cybersecurity teams, often referred to as shadow AI, can increase an organisation's exposure. Tools adopted informally, without clear policies or risk assessments, can create blind spots in data protection and access management.

 

Third-party tools among the main concerns

Dependence on external solutions is one of the issues that concerns Portuguese businesses most when looking ahead to the next five years.

According to the study, 46% of organisations rank vulnerabilities arising from third-party AI tools among the three main AI-related threats.

These are followed by:

  • 43% — AI data poisoning.
  • 43% — AI-based malware or phishing.
  • 40% — Use of compromised data or models.
  • 40% — Over-reliance on AI and reduced human oversight.

 

These risks demonstrate that AI security does not depend solely on the technology being used. It also involves how models are integrated, how data is protected, how access is controlled and how responsibilities are assigned.

 

AI adoption requires more than choosing a tool

Implementing Artificial Intelligence should be accompanied by an assessment of the organisation's security readiness.

 

Before integrating a new solution, it is important to answer some fundamental questions:

1. What data will be used? It is essential to understand what information will be shared with the tool, whether it contains sensitive data and what safeguards are in place for its processing and protection.

2. Who can access the information? Access should be defined according to the actual needs of each user, application or AI agent. Excessive permissions can increase the impact of misuse or a security breach.

3. What external dependencies are involved? The use of third-party tools should be accompanied by an assessment of the risks associated with the provider, integration, service availability and data protection.

4. How are incidents detected and handled? Prevention is essential, but it cannot eliminate every risk. Organisations need the ability to identify anomalous behaviour, investigate incidents and respond quickly when something goes wrong.

 

Cybersecurity and AI must evolve together

Incidents are also influencing technology transformation decisions. Among Portuguese businesses that experienced cyberattacks, 42% say they have delayed the adoption of AI or other new technologies as a result of an incident.

At the same time, 42% plan to bring some AI-related work in-house, 35% point to employee training and regular audits, and 34% intend to ensure that their cyber insurance covers risks related to this technology.

These figures show that security is becoming increasingly important in decisions around AI adoption. Rather than holding back innovation, the objective should be to create the conditions for it to take place in a controlled and sustainable way.

 

From adoption to technological resilience

Integrating AI into a business means adding new elements to its technology ecosystem. To ensure that this integration is secure, organisations need to understand the architecture, protect data, control identities and monitor the systems involved.

Na ORBCOM, acreditamos que a tecnologia deve ser pensada como um todo. A cibersegurança não pode ser tratada como uma camada isolada, acrescentada depois da implementação de uma solução.

A proteção deve acompanhar todo o processo, desde a avaliação das necessidades e desenho da arquitetura até à implementação, monitorização e resposta a incidentes.

Isto implica:

  • Avaliar os riscos associados à adoção de IA e às suas integrações.
  • Proteger redes, endpoints, identidades e ambientes cloud.
  • Definir políticas de acesso e utilização adequadas.
  • Identificar comportamentos anómalos através de monitorização contínua.
  • Reforçar a capacidade de deteção, resposta e recuperação perante incidentes.

 

A IA pode acelerar o negócio. A cibersegurança deve garantir que essa evolução acontece com controlo, visibilidade e resiliência.

A pergunta já não é apenas que solução de IA escolher. É saber se a organização está preparada para a integrar de forma segura.

Need help getting your organization ready?

Talk to ORBCOM and find out how we can help assess your risks, strengthen your cybersecurity and prepare your organization for new requirements.

Frequent questions

The main risks include vulnerabilities in third-party AI tools, data exposure or misuse, AI-powered phishing and malware, compromised models or data, and the use of AI tools without adequate oversight.

According to the Hiscox Cyber Readiness Report 2026, 92% of Portuguese businesses that experienced a cyberattack recorded at least one incident associated with new AI-related vulnerabilities in the past 12 months..

Businesses should assess the AI tools they use, control access and the data shared, define clear usage policies, monitor their technology environments, and ensure they have effective incident detection and response capabilities.

 

Shadow AI is the use of Artificial Intelligence tools without the knowledge or oversight of the teams responsible for technology and security. It can create new points of exposure, particularly when employees share sensitive data or grant permissions without an adequate risk assessment.

Did you like it?

Sign up to our newsletter and keep up with the latest insights.

Want to know more about ORBCOM? Speak to a specialist

If you would like to get to know ORBCOM better and understand how our products, consulting services and outsourcing, fit your reality, speak to a specialist.