Americans believe businesses share the blame for AI data breaches
Core finding
In a Verasight survey of 1,500 U.S. adults conducted September 16 to 21, 2026, 60.7% assign a great deal of responsibility to a company whose AI agent is exploited to steal customer information. A similar 59.6% assign that responsibility to the company that built the agent.
The scenario is hypothetical: criminals exploit an agent built by an outside technology company. Respondents assess each party separately, so responsibility can be shared.
Businesses using the agent share responsibility
For the company using the agent, 60.7% assign a great deal of responsibility and 23.6% assign some.
Another 7.4% assign not much responsibility, 3.4% none at all and 5.0% are unsure. The question concerns the company’s role in the scenario, not a finding of legal liability.
Topline
60.7% say companies using AI agents would bear a great deal of responsibility if criminals exploited an AI agent to steal customers’ personal information.
n = 1,500 · Sep 16–21, 2026 · MoE ±2.6%
Developers face similar expectations
For the outside technology company that built the agent, 59.6% assign a great deal of responsibility and 24.2% assign some.
These responses closely resemble those for the company using the agent. The survey does not ask respondents to divide a fixed amount of blame between the two businesses.
Topline
59.6% say AI agent developers would bear a great deal of responsibility if criminals exploited an AI agent to steal customers’ personal information.
n = 1,500 · Sep 16–21, 2026 · MoE ±2.6%
Attackers bear the greatest responsibility
Criminal attackers receive the strongest response: 81.0% assign them a great deal of responsibility.
Government regulators also face scrutiny for not setting clearer rules. Some 47.1% assign them a great deal of responsibility and 30.6% assign some.
Topline
81.0% say criminal attackers would bear a great deal of responsibility if criminals exploited an AI agent to steal customers’ personal information.
n = 1,500 · Sep 16–21, 2026 · MoE ±2.6%
Topline
47.1% assign government regulators a great deal of responsibility for not setting clearer rules in the scenario where criminals exploit an AI agent to steal customers’ information.
n = 1,500 · Sep 16–21, 2026 · MoE ±2.6%
Methodology
Full methodology →| Mode | Verasight panel recruited via random address-based sampling, random person-to-person text messaging, and dynamic online targeting |
|---|---|
| Population | US adults age 18+ |
| Field dates | Sep 16–21, 2026 |
| Base (unweighted) | 1,500 |
| Margin of error | ±2.6% |
| Module | Current Events Survey #2026-243 |
| Sponsor | Verasight |
| Weight variable | weight |
| Weighting targets | age, race/ethnicity, sex, income, education, region, metropolitan status |
Sources
- reports.verasight.io/r/2026-243-current-events-report
- The company that was using the AI agent
Cite this topic
September Verasight National Survey: Current Events and Prediction Markets, fielded September 16-21, 2026, N=1,500 US adults age 18+, +/- 2.6%.