The State of AI and ERP Security: 2026 Threat Research

Share

Enterprise AI adoption inside SAP, Oracle, and Salesforce environments is outpacing the cybersecurity controls built to defend them. According to The State of AI, Security and ERP report, a study conducted by Onapsis in June 2026 surveying 204 senior cybersecurity leaders at U.S. enterprises with 1,000+ employees, enterprise code is moving significantly faster than network defenses.

The rapid convergence of AI technologies and core business platforms has created a widening exposure gap directly inside business-critical systems. Organizations are aggressively deploying AI agents and generative code to drive operational efficiency, yet adoption is proceeding well ahead of unresolved security, compliance, and trust concerns.

The State of AI in ERP: Rapid Adoption Meets Unresolved Risk

The Study on the state of AI in ERP environments reveals that enterprise AI adoption in core business applications is dramatically accelerating. Over 86% of surveyed security leaders report their organizations have integrated, or will shortly integrate, AI directly into enterprise resource planning (ERP) code. This rapid integration creates a critical exposure gap inside core business platforms.

Efficiency goals serve as the primary driver behind this aggressive rollout. Organizations are rushing to capture productivity gains, often introducing AI agents into changing environments without fully evaluating the underlying attack surface.

  • Accelerated Deployment Timelines: 58% percent of enterprise organizations deployed AI-based applications or agents into ERP systems within the last six months alone.
  • The Pursuit of Efficiency: Over 78% of cybersecurity leaders cite improving corporate efficiency as the primary reason their business demands AI integration.
  • Compounding System Transformation: 56% percent of organizations are actively executing or planning a near-term transformation of their ERP system. 
  • External Reliance: More than 83% of enterprises rely on native vendor code, while 60.6% source AI tools from third-party application providers.

The AI Confidence Gap: Why Cybersecurity Leaders Are Pushing Back

Cybersecurity leaders exhibit low confidence in current defensive capabilities against artificial intelligence threats targeting critical business applications. Nearly 69% of security executives admit current defenses cannot reliably detect AI-based attacks against core systems, prompting mounting internal pushback from security and information technology teams against unchecked AI access.

While non-technical lines of business favor rapid adoption, internal resistance is escalating among the technical teams responsible for safeguarding enterprise systems. Almost 57% of organizations report that at least one business unit has formally objected to granting AI agents access to sensitive ERP environments.

Business Unit Resistance to AI Integration in ERP:

  • Security Teams: 41.4% (Leading Resistant Group)
  • Information Technology : 20.7%
  • Finance: 15.5%
  • Executive C-Suite: 8.6%

The top drivers for internal resistance highlight deep-seated concerns surrounding application safety and regulatory compliance:

  • Lack of Confidence in AI Security: 65% percent of resistant groups express skepticism toward current AI security capabilities and vulnerability controls.
  • Regulatory and Compliance Risks: Over 71% of respondents cite compliance risks as a primary reason for pushing back against AI integration. 
  • Data Integrity and Hallucinations: 68% percent fear corrupted system data or automated decision-making errors resulting from model hallucinations.

Despite these concerns, 70.6% of security leaders state they have little to no trust in AI applications to secure business-critical data. Furthermore, 41.5% rely heavily on their primary ERP vendors to deliver security controls, transferring trust without possessing independent verification capabilities.

Autonomous Threat Vectors: How AI Exploits SAP and Enterprise Applications

Threat actors leverage artificial intelligence models to automate complex attacks against business-critical platforms at machine speed without requiring proprietary system knowledge. Autonomous agents autonomously map application landscapes, identify ACL misconfigurations or unpatched vulnerabilities, and execute database commands to commit financial fraud or disrupt operational continuity.

The threat of AI-driven exploitation is no longer hypothetical. Nearly 22% of surveyed organizations confirmed experiencing one or more security incidents in the past 12 months where bad actors used AI to exploit critical business platforms, while an additional 15.2% suspected unconfirmed incidents.

AI Security Incidents in the Last 12 Months:

██████████░░░░░░░░░░░░░░░░░░░░ 21.6% Confirmed Incident(s)

███████░░░░░░░░░░░░░░░░░░░░░░░ 15.2% Suspected Incident(s)

█████████████████████████░░░░ 55.4% Concerned / Potential Risk

In laboratory research conducted by Onapsis, Pablo Artuso, Security Researcher Tech Lead, demonstrated live attack loops showing how AI models hack SAP applications without human intervention. Advanced large language models (LLMs) now possess native knowledge of proprietary SAP protocols (such as RFC, DIAG, and Gateway ACLs). 

The Four-Step Autonomous AI Attack Loop:

[1. MAP]     → AI fingerprints reachable services (Message Server, Gateway, HANA)

[2. REASON]  → AI ranks entryways by reliability and selects the optimal path

[3. EXPLOIT] → AI adapts public PoCs and executes zero-day/unpatched exploits

[4. IMPACT]  → AI alters database tables (e.g., bank routing) or shuts down system

Through plain English prompts, malicious AI agents can exploit emergency default accounts (such as the SAP* kernel password), leverage permissive Gateway secinfo access control lists to rewrite vendor banking details directly in database tables, or drop persistent webshells to execute system shutdowns.

Securing the Control Plane: Strategic Requirements for Enterprise Resilience

Securing artificial intelligence inside core enterprise applications requires implementing robust access management, application-layer threat detection, and continuous code inspection. Organizations must establish specialized control plane visibility over business-critical application environments to verify permissions, sandbox autonomous workflows, and prevent unauthorized data exfiltration.

To bridge the exposure gap, security teams must deploy dedicated safeguards before new AI capabilities go live. Surveyed cybersecurity leaders identified three core technical capabilities required to earn trust in AI-driven enterprise workflows over the next 12 months:

Top Enterprise Requirements to Build AI Trust:

1. Robust Access Management Controls (61.8%)

2. Strong Personal Data Protections (45.8%)

3. Sandboxing / Digital Twin Environments (36.8%)

  1. Gain Application-Layer Visibility: Implement dedicated SAP vulnerability management via Onapsis Assess to continuously evaluate system configurations, misauthorizations, and unpatched vulnerabilities before AI agents interact with production data.
  2. Deploy Real-Time Threat Detection: Integrate real-time SAP threat detection into your existing SOC workflow. Deploying Onapsis Defend enables continuous application-layer monitoring, feeding zero-day threat intelligence and user behavior anomaly scoring directly into enterprise SIEMs like Splunk or Microsoft Sentinel.
  3. Automate Code Scanning and DevSecOps: Establish automated inspection for all custom code and transports entering production. Utilizing Onapsis Control provides automated SAP code testing across ABAP, SAP BTP, and UI5 environments, catching AI-generated code errors before deployment.
  4. Leverage Specialized Threat Research: Stay ahead of machine-speed attacks by grounding your security strategy in intelligence from Onapsis Research Labs. As reflected in SAP’s security researcher acknowledgments, deep application-layer intelligence is mandatory for defending critical business processes.

Benchmark Your Security Posture

The exposure inside core ERP environments is documented, measurable, and actively targeted. Download the full State of AI, Security and ERP report to benchmark your organization against 204 enterprise peers and prioritize the critical gaps in your business-critical application defenses.