Onapsis Finds ERP AI Security Readiness Lagging
ERP systems underpin finance, procurement, and identity workflows in many agencies - this survey signals a confidence gap worth noting as agencies consider AI integration into business-critical platforms.
Key points
- Onapsis surveyed 204 US large-enterprise cybersecurity leaders; 86% had integrated or planned to integrate AI into ERP code.
- Only 30% were fully confident they could detect an AI-based attack - a self-reported confidence gap, not a technical benchmark.
- Sample is US-only, large-enterprise, SAP/Oracle/Salesforce users; findings should not be generalised broadly.
Implications for Australian agencies
- Monitor Agencies using SAP or similar ERP platforms may want to monitor emerging guidance on AI agent permissions, generated code review, and authorisation boundaries in business-critical systems.
- Consider Risk and assurance teams could consider whether current AI security assessments explicitly address ERP-connected AI agents and AI-generated code pathways.
Implications are AI-generated. Starting points, not advice — see methodology for how they're framed.
View original source
Copied.
"Onapsis Finds ERP AI Security Readiness Lagging"
Source: Let's Data Science – AI Governance
Published: 31 July 2026
URL: https://letsdatascience.com/news/onapsis-finds-erp-ai-security-readiness-lagging-3bd2cf36
Onapsis published The State of AI, Security and ERP on 30 July 2026, reporting that 86% of 204 surveyed US cybersecurity leaders at large enterprises had integrated or expected to integrate AI into ERP code, while only 30% felt fully confident they could detect an AI-based attack. The survey covers organisations running SAP, Oracle, or Salesforce with more than 1,000 employees, making it a large-enterprise signal rather than a universal benchmark. The findings point to a self-reported readiness gap between AI adoption pace and defensive confidence in systems that sit close to sensitive business workflows. The article notes these are perceived confidence measures, not independently tested defence outcomes.
Implications for Australian agencies:
- [Monitor] Agencies using SAP or similar ERP platforms may want to monitor emerging guidance on AI agent permissions, generated code review, and authorisation boundaries in business-critical systems.
- [Consider] Risk and assurance teams could consider whether current AI security assessments explicitly address ERP-connected AI agents and AI-generated code pathways.
Retrieved from SIMS, 16 September 2026.