Onapsis Finds ERP AI Security Readiness Lagging
Onapsis published The State of AI, Security and ERP on July 30, 2026, reporting that 86% of 204 surveyed U.S. cybersecurity leaders said their organizations had integrated or would soon integrate AI into ERP code. Only 30% were fully confident they could detect an AI-based attack, underscoring a readiness gap within this specific large-enterprise sample.
Onapsis published The State of AI, Security and ERP on July 30, 2026, describing a wide gap between planned AI use in enterprise resource planning systems and confidence in defending those systems. The company reports that 86% of surveyed organizations had integrated, or expected shortly to integrate, AI directly into ERP code, while only 30% were fully confident they could detect an AI-based attack.
What the survey measured
The findings are based on 204 completed responses from senior-level cybersecurity leaders at U.S. organizations with more than 1,000 employees. Every respondent's organization ran SAP, Oracle, or Salesforce, according to Onapsis. That makes the report relevant to large enterprise environments, but it is not a representative measure of every company using ERP software.
Onapsis also says 70% of respondents lacked confidence in AI securing critical business data. The report examines adoption of AI agents and AI-generated code, security confidence, internal resistance, and exposure to compliance obligations. These figures describe respondents' reported plans and confidence; they do not measure observed attack rates or independently test the effectiveness of their defenses.
Why ERP integration raises the stakes
ERP systems sit close to finance, procurement, supply chain, identity, and other business-critical workflows. Adding generated code or agents can expand the set of permissions, integrations, and automated actions that security teams must review. A model-generated change may be syntactically valid while still creating excessive access, weak validation, or an unaudited path into sensitive data.
For data and AI teams, the practical response is to treat ERP-connected AI as production software: define the agent's allowed actions, review generated code, test authorization boundaries, log tool use, and plan how to detect and stop abnormal behavior. Those steps are LDS interpretation grounded in the deployment pattern described by the report, not measured outcomes from the survey. The strongest conclusion supported by the evidence is a confidence gap inside the surveyed population, not proof that 86% of all enterprises have secure or insecure AI deployments.
Key Points
- 1Onapsis reports that 86% of 204 surveyed large-enterprise cybersecurity leaders had integrated or expected soon to integrate AI into ERP code.
- 2Only 30% were fully confident they could detect an AI-based attack, a self-reported readiness measure rather than a technical test of defenses.
- 3The sample covers U.S. organizations with more than 1,000 employees using SAP, Oracle, or Salesforce, so the findings should not be generalized to every enterprise.
Scoring Rationale
The report supplies timely survey evidence about AI adoption and defensive confidence in business-critical ERP environments. Its value is operational and governance-oriented rather than a vulnerability disclosure or independent benchmark, and the article keeps conclusions bounded to the 204-person large-enterprise sample.
Sources
Primary source and supporting public references used for this report.
Practice interview problems based on real data
1,625 SQL & Python problems across 15 industry datasets — the exact type of data you work with.
Try 250 free problems
