Five Polls, One Underlying Question
Over the past two months, Topgallant Partners ran a series of quick polls on LinkedIn asking our network how they see AI reshaping cybersecurity risk. These weren’t designed as rigorous research, and we’re not treating them that way. But taken together, they trace a pattern worth unpacking: the way practitioners talk about the “biggest” AI threat has shifted in a short window of time, and that shift tells us something about how the conversation itself is maturing.
Where the Conversation Started: Broad Categories
Our earliest polls asked what danger AI poses to cybersecurity in general terms. Respondents gravitated toward broad categories, faster and more scalable attacks, adversarial manipulation of AI models, and increasingly convincing phishing or deepfakes, while more technical or structural risks drew far less attention.
Read side by side, these early polls tell a consistent story: when people were asked to think broadly about AI risk, they gravitated toward the threats that are easiest to picture, faster attacks and more convincing phishing, rather than the more technical or structural risks like model poisoning or governance gaps.
Where It’s Heading: Specific, Structural Concerns
Our more recent polls tell a different story. Asked which AI-driven threat poses the greatest risk to enterprise security looking ahead, respondents converged strongly around autonomous agentic malware over deepfake social engineering, indirect prompt injection, or poisoned training data. Another poll, framed in similar terms, split attention between data leakage from AI tools and a lack of AI governance and policies, with social engineering and model manipulation trailing behind.
That’s a meaningful change in vocabulary. Instead of “AI will make attacks faster” or “AI will make phishing better,” the concerns getting votes now are specific and structural: autonomous agentic systems acting on their own, data leaking out through AI tools, and organizations lacking the policies to govern any of it. The threat model is getting more precise as agentic AI moves from a talking point to something security teams are actually seeing in their environments.
The Budget Signal
One poll stepped outside the threat-naming exercise and asked something more practical: where will CIOs increase spending most going forward? The response leaned heavily toward cybersecurity and risk management, well ahead of AI and automation, with infrastructure, cloud, and application modernization barely registering. Whatever uncertainty exists about which specific AI threat matters most, there’s little uncertainty about where the money is expected to go. Security is being treated as the priority line item, not a subset of the AI spending conversation.
The Takeaway
These polls aren’t meant to be read as hard data, but the direction across all of them is consistent enough to matter: the conversation about AI and cybersecurity is moving from generic alarm toward specific, operational concerns, agentic malware, data leakage, governance gaps, while budget priorities suggest security teams expect to be funded accordingly. Organizations that are still framing their AI risk conversations around “AI will make attackers faster” may be behind where the discussion, and the money, is already headed.
0image sources
- pexels-pixabay-327533: Photo by Pixabay: | All Rights Reserved



