Onapsis Finds ERP AI Security Readiness Lagging
Onapsis published a report on July 31 finding that 86% of surveyed enterprises have integrated, or expect shortly to integrate, AI directly into ERP code, while only 30% are fully confident they could detect an AI-based attack. The survey covered 204 senior cybersecurity leaders at large US organizations using SAP, Oracle, or Salesforce systems.
Onapsis published a report on July 31 finding that AI adoption in enterprise resource planning environments is advancing faster than organizations' confidence in defending those systems. According to the report, 86% of surveyed organizations have integrated, or will shortly integrate, AI directly into ERP code, but only 30% are fully confident they could detect an AI-based attack.
The findings are based on 204 completed responses from senior cybersecurity leaders at US organizations with more than 1,000 employees that run SAP, Oracle, or Salesforce. As a survey of a defined enterprise population, the results describe respondents' reported adoption and confidence levels rather than a measurement of all ERP deployments.
Adoption and detection gap
Onapsis examined the use of AI agents and AI-generated code in ERP systems, as well as respondents' views of threats, compliance, and organizational resistance. The report also found that 70% of respondents lack confidence in AI's ability to secure critical business data.
The company identifies regulatory exposure, including GDPR and ISO obligations, as a factor respondents weigh against potential efficiency gains. It also reports that security teams are among the business units resisting AI-in-ERP adoption.
Why ERP integration raises the stakes
ERP platforms commonly connect financial, supply-chain, human-resources, and customer data with business processes. In comparable enterprise deployments, AI-generated custom code and agentic workflows can increase the number of code paths, integrations, permissions, and automated actions that security teams need to assess.
For data and ML practitioners working on ERP-connected systems, the survey underscores a practical distinction between deploying an AI capability and establishing controls around it. Security review of generated code, identity and authorization boundaries for agents, audit logs, and testing for unsafe automated actions are recurring concerns across enterprise AI implementations. The Onapsis findings do not establish which controls respondents have deployed, but they quantify a large confidence gap around attack detection within the surveyed group.
Key Points
- 1Onapsis found 86% of surveyed enterprises integrating AI into ERP code, while only 30% reported full confidence detecting AI-based attacks.
- 2The survey covered 204 cybersecurity leaders at large US organizations running SAP, Oracle, or Salesforce, limiting conclusions to that respondent population.
- 3Across comparable enterprise AI deployments, generated code and agents expand review needs around permissions, auditability, integrations, and automated actions.
Scoring Rationale
The report provides timely survey evidence of a security-confidence gap around AI embedded in ERP code and workflows. It is relevant to practitioners deploying agents or generated code against business-critical enterprise systems, although it is not a product release, vulnerability disclosure, or independent technical benchmark.
Sources
Primary source and supporting public references used for this report.
Practice interview problems based on real data
1,625 SQL & Python problems across 15 industry datasets — the exact type of data you work with.
Try 250 free problems
