Manufacturers are facing a rapidly evolving data security landscape as AI adoption, cloud migration and increasingly complex digital environments create new vulnerabilities, according to Thales’ 2026 Data Threat Report: Manufacturing Edition.
The report reveals that AI is emerging as a significant new security challenge for manufacturing organisations, with rapid changes in the technology ecosystem, sensitive data disclosure and AI-generated misinformation among the leading concerns. Thales describes AI as a potential “new insider threat” for manufacturers, as increasingly autonomous AI and agentic applications gain access to growing volumes of enterprise data.
Around two-thirds (67%) of manufacturing respondents identified the rapid pace of change in AI ecosystems as a top security risk, making it the leading AI-related concern. Trust in AI systems was the second-largest concern, cited by 63% of respondents, while agency – the ability of AI systems to act autonomously – was cited by 45%.
At the same time, manufacturers are seeing attackers adopt AI-enabled techniques. Sensitive information disclosure was identified by 59% of respondents as an increasing AI/LLM-based attack, followed by AI-generated misinformation and deepfakes at 54%, and system prompt leakage at 45%.
The report also highlights the growing investment being made to address these threats, with 83% of manufacturing organisations having invested in specific security tools or services because of concerns about AI. Meanwhile, 29% now have a dedicated AI security budget, up from 23% in 2025. However, 55% continue to fund AI security from existing security budgets.
Manufacturers struggle to locate and protect data
The rapid adoption of AI is exposing weaknesses in manufacturers’ ability to understand and protect their existing data. Indeed, just 31% of manufacturing respondents said they have complete knowledge of where their organisation’s data is stored, while just 37% said they can classify all their data.
The issue is particularly pronounced in the cloud. Although cloud security remains the highest security spending priority, manufacturers reported that just 42% of their sensitive cloud data is encrypted, down from 57% in 2025. Thales estimates that 58% of sensitive manufacturing data stored in the cloud remains unencrypted, creating a substantial potential attack surface as AI applications and agents gain greater access to enterprise data.
Cloud-based assets were also the three most commonly cited attack targets: cloud storage (36%), cloud-delivered applications (29%) and cloud management infrastructure (29%). Credential theft or compromise was the most commonly cited rising attack technique against manufacturing cloud environments, identified by 57% of respondents.
Human error remains a major weakness
Despite growing concern over sophisticated threats including nation-state attacks and AI-powered attacks, the report found that relatively conventional security failures continue to account for a significant proportion of breaches.
Human error or misconfiguration was the leading reported cause of data breaches among manufacturers, cited by 30% of respondents whose organisations had experienced a breach. Exploitation of known vulnerabilities followed at 20%, ahead of zero-day or previously unknown vulnerabilities at 13%.
The Thales research also identified a potential relationship between security complexity and human error. Manufacturing organisations use an average of eight data protection and monitoring tools, with 83% using five or more. Meanwhile, 63% use five or more tools specifically for AI/LLM security. Only 35% of respondents said they were confident in their understanding of their data security tools, highlighting the potential difficulties created by security-tool sprawl.
Audit failures linked to higher breach rates
A strong association exists between compliance audit failures and reported breaches. Among manufacturing organisations that had failed an audit, 65% reported experiencing a cloud breach, compared with 35% of those that had passed all audits. For on-premises breaches, the corresponding figures were 59% and 41%.
Meanwhile, 16% of manufacturing respondents reported experiencing a cloud breach during the previous 12 months, while 15% had experienced an on-premises breach.
Quantum risk moves up the agenda
Quantum computing is being increasingly utilised by manufacturers, with 35% of organisations having either identified potential quantum computing projects or begun experimenting with the technology. This reality exposes said businesses to a long-term threat.
Harvest-now, decrypt-later attacks were the leading quantum-related concern among manufacturing respondents, cited by 59%, followed by future compromise of encryption at 55%. Nevertheless, manufacturers are beginning to prepare, with 61% prototyping or evaluating post-quantum cryptographic algorithms, up from 59% in 2025. A further 45% are assessing current encryption strategies, while 39% are moving towards hybrid TLS.
AI adoption adds urgency to data security
Thales argues that the increasing autonomy of AI systems makes existing weaknesses in data visibility and protection more consequential. In a separate 451 Research study cited in the report, 27% of manufacturing enterprises said embedded AI agents were already in use, while a further 48% expected to use them within 12 months.
As these systems gain access to more enterprise data and become capable of taking actions on behalf of users, manufacturers will need greater visibility over where data resides, how it is classified and who or what can access it.
The report concludes that manufacturers should strengthen fundamental data security, improve breach prevention and response, reduce security-tool complexity, prepare for quantum-related risks and introduce specific controls for AI and agentic applications.
For manufacturers undergoing digital transformation, the findings suggest that the security challenge is no longer confined to protecting traditional IT infrastructure. As AI, cloud platforms, connected systems and industrial technologies become increasingly intertwined, the data flowing between them is becoming an increasingly critical part of the manufacturing security equation.
Speaking about the increasingly complex data security landscape faced by manufacturers, Todd Moore, VP of Data Security Products at Thales, said: “The highly distributed nature of manufacturing infrastructure and range of human entry points have made this industry particularly vulnerable to data breaches. To build effective security resilience without slowing down production, security teams need a practical approach that fits both the shop floor and IT. Digitalization only works when you can establish trust across your entire ecosystem, including between employees, partners, connected devices, and services.”
For more articles like this, visit our Data & AI channel



