Organizations are rapidly embedding artificial intelligence (AI) into enterprise resource planning (ERP) systems, but many cybersecurity leaders remain unconvinced that their organizations are prepared to secure these environments.
According to the 2026 Onapsis State of AI, Security, and ERP report, AI adoption is accelerating across SAP, Oracle, and Salesforce environments even as concerns about security, compliance, and AI-driven attacks continue to grow.
Based on survey responses from 204 senior cybersecurity leaders at large U.S. organizations, the 2026 Onapsis report found that AI deployment is outpacing security readiness as organizations prioritize business efficiency.
Key takeaways of the State of AI, Security, and ERP report
- Enterprise AI adoption is accelerating, with 58% of organizations deploying AI applications that interact with ERP systems within the past six months.
- Security readiness is lagging behind AI adoption, as nearly 69% of cybersecurity leaders lack confidence that their current defenses can detect AI-based attacks.
- AI is becoming deeply embedded in ERP environments, with more than 62% already using AI-generated code and 76% implementing agentic AI workflows.
- Organizations are concerned about AI-related security risks, including AI vulnerabilities, compliance challenges, and AI-assisted attacks targeting business-critical systems.
- Access management, data protection, and AI governance emerged as the top priorities for improving trust in AI-enabled ERP environments.
Summary of key findings from the State of AI, Security, and ERP report
| Key Finding | Survey Result | Why It Matters |
| Organizations deploying AI in ERP | 58% | AI adoption is accelerating across business-critical systems. |
| Organizations using AI-generated ERP code | 62.3% | AI is becoming embedded directly into enterprise applications. |
| Organizations using agentic AI | 75.6% | Autonomous AI workflows are becoming mainstream in ERP. |
| Organizations reporting confirmed AI-assisted attacks | 21.6% | AI-enabled threats are already affecting enterprise environments. |
| Leaders lacking confidence in detecting AI attacks | 68.6% | Security readiness is not keeping pace with AI adoption. |
| Organizations with little to no trust in AI securing critical data | 70.6% | Confidence in AI governance remains low. |
| Top improvement priority to trust AI touching ERP systems (Access control) | 61.8% | Stronger access management is viewed as the most important security enhancement. |
Enterprise AI adoption accelerates across ERP systems
More than half (58%) of respondents said their organizations began deploying AI applications or agents that interact with ERP systems within the past six months, while 18.5% expect deployments before the end of the year.
Approximately 78% identified operational efficiency as the primary reason for integrating AI into ERP platforms.
Additionally, 56.1% reported that their organizations are currently undergoing or planning an ERP transformation, creating opportunities to incorporate AI during modernization initiatives.
Organizations expand AI integration across ERP systems
AI is also becoming deeply integrated into core enterprise applications.
More than 62% of respondents said they are already using AI-generated code within their ERP systems, and another 26% plan to do so by the end of 2026.
Organizations plan to combine vendor-provided, third-party, and internally developed AI capabilities.
Approximately 83% expect to use AI capabilities embedded by their ERP vendor, while roughly 61% plan to incorporate third-party AI applications.
Agentic AI adoption raises visibility challenges
Agentic AI is emerging as another significant trend.
Nearly 76% of respondents said their organizations have already implemented agentic workflows that interact with ERP systems.
However, 15.1% reported they believe agentic AI may already be interacting with their ERP environment but lack visibility into where or how it is being used, highlighting ongoing governance and visibility challenges.
ERP security challenges grow as AI adoption increases
Despite widespread adoption, confidence in securing AI-enabled ERP environments seems limited.
While 54% of organizations primarily rely on their own cybersecurity capabilities to protect ERP systems, nearly 46% expect ERP vendors to provide sufficient built-in security protections.
At the same time, more than 84% ranked deploying AI to help defend ERP environments against AI-based risks to ERP systems as one of their highest cybersecurity priorities for 2026.
Security and compliance concerns slow AI adoption
Internal resistance also reflects ongoing concerns about AI security.
Nearly 57% of respondents said at least one business unit has objected to allowing AI access to ERP systems, with cybersecurity teams representing the largest source of resistance (41.4%), followed by IT departments (20.7%).
The leading concerns included a lack of confidence in AI security and AI security vulnerabilities (75%), compliance risks (71.6%), and the potential for inaccurate or hallucinated data (68.1%).
AI-powered attacks increase enterprise risk
Survey respondents also reported growing concern about AI-powered cyber threats targeting business-critical systems.
More than one in five organizations (21.6%) said they had already experienced confirmed security incidents in which threat actors leveraged AI to compromise critical business platforms.
An additional 15.2% suspected AI-assisted attacks but could not confirm them, while 55% expressed concern that such incidents remain a realistic future possibility.
How organizations can improve AI security for ERP environments
One of the report’s key findings is the gap between AI adoption and cybersecurity confidence.
Nearly 69% of cybersecurity leaders said they are only somewhat or not very confident that their existing security controls could detect AI-based attacks targeting ERP systems.
Likewise, 70.6% reported having only some or no trust that AI applications and agents can adequately secure their organization’s most sensitive business data.
What organizations need to build trust in AI for ERP
Respondents identified several capabilities that would increase confidence in AI-enabled ERP environments.
The most frequently cited priorities included stronger access management controls (61.8%), enhanced protection for sensitive data (45.8%), and the ability to isolate sensitive workloads within sandboxed or digital twin environments (36.8%).
Nearly one-third (32.6%) also wanted AI applications to undergo direct validation by the organization’s CISO or CIO before deployment.
The findings suggest that enterprise organizations are moving aggressively to capture AI-driven productivity gains, even as cybersecurity leaders acknowledge significant gaps in visibility, governance, and detection capabilities.
AI is becoming increasingly embedded within ERP platforms that process financial, operational, and customer data.
To reduce enterprise risk, organizations may need to strengthen access controls, continuously monitor AI interactions, and clearly define shared security responsibilities between internal teams and ERP vendors.





