Technology · Artificial intelligence
Luxury brands accelerate AI adoption as security risks mount
Bain survey shows 22% of luxury houses now rank AI a top-three priority, up from 5% in 2024, while Kering, Dior and Harrods breaches highlight exposure to AI-enabled attacks.
Luxury houses are pouring money into artificial intelligence at the same moment that AI-enabled cyberattacks are cutting the time between vulnerability disclosure and exploitation to hours. A 2026 Bain & Co. survey of 35 executives across 23 luxury groups found that 22% now rank AI adoption among their top three strategic priorities, a jump from 5% two years earlier, while 61% place it in their top ten. The investment push aims to revive operational efficiency and growth after a fragile demand recovery, but security specialists warn that the rush to deploy consumer-facing and internal AI tools is opening doors that criminals are learning to exploit.
The sector has already absorbed a string of high-profile breaches. In 2025, hackers stole the private details of potentially millions of customers from Gucci, Balenciaga and Alexander McQueen in an attack on their French parent Kering, which disclosed the incident to data protection authorities. Dior, Harrods and Marks & Spencer were also hit during the same period. Those intrusions relied on conventional tactics, but the next wave is being accelerated by the very technology luxury companies are adopting.
Criminals weaponise AI at discrete points
Cynthia Kaiser, senior vice president at anti-ransomware firm Halcyon and a former FBI cyber deputy director, says established criminal groups are not handing entire operations to autonomous AI agents. Instead, they insert the technology at specific stages: crafting more convincing phishing lures, automating social-engineering scripts, and scanning for vulnerabilities faster than human operators can. "They're using AI at really discrete points to attack," she says. The window between a flaw becoming public and criminals exploiting it has shortened dramatically, and ransomware campaigns can now unfold in as little as an hour.
Kari Koskinen, a senior university lecturer at the Aalto University School of Business, draws a distinction that many boards have yet to internalise. AI safety asks whether a system behaves as expected under normal conditions; AI security asks whether it can withstand deliberate manipulation, unauthorised access attempts or being turned against its operator. For brands, that means deciding precisely which tools each model may call, what actions it may execute, and how quickly those permissions can be revoked when something goes wrong.
EU AI Act shapes liability landscape
Charles Kerrigan, a partner at law firm CMS who specialises in emerging technologies, says liability for AI harm typically falls into three buckets. Contractual liability governs the relationship between a fashion house and its technology vendors. Third-party liability covers harm to individuals or entities with no contractual link, where courts will weigh foreseeability. Regulatory liability stems from the EU AI Act, cybersecurity directives and data protection law. The most contentious cases, Kerrigan says, will involve third-party harm where no contract exists.
For luxury companies buying general-purpose models rather than training their own, the AI Act provides a degree of clarity. The legislation draws on product safety principles and "deliberately pushes responsibility onto the model providers", Kerrigan explains, because providers such as OpenAI, Anthropic or Google possess the expertise to assess their own systems. That does not grant downstream users a blanket shield. A failure may stem from poor proprietary data supplied by the fashion house or from deploying a model for a task it was never designed to perform.
Kerrigan adds that multinational groups with substantial EU operations are likely to adopt the AI Act as a global compliance baseline, applying its standards across jurisdictions to simplify oversight. The European Commission has signalled that consistent enforcement across member states will be a priority once the Act's main provisions take full effect.
Vestiaire Collective models scoped access
At resale platform Vestiaire Collective, chief technology officer Rémi Bouchez has implemented a principle of least privilege for every AI deployment. Tools are confined to information the relevant employee or system was already authorised to see. "The goal is not broad access," he says. "It's enabling useful, well-scoped use cases, while maintaining the same standards we expect of any other system." Bouchez separates an agent's permission to read data from its ability to take consequential actions, placing an order, changing a price, shipping a product, and treats every third-party connector as an additional exposure point: more data moving, more credentials, more vendor dependency, more potential failure modes.
Security teams need earlier seat at table
Kaiser argues that chief information security officers are routinely brought into AI projects too late, after architectural decisions have locked in risk. Early involvement forces explicit trade-offs between functionality and security before code reaches production. "You just have to have security at the table from day one," she says. Basic hygiene remains the bedrock: timely patching, strong authentication, network segmentation and continuous monitoring for anomalous behaviour. Ironically, defending against AI-accelerated attacks also requires AI, security tooling that can operate at machine speed to detect and contain intrusions before they spread.
Sources
People mentioned
Cynthia Kaiser
Kari Koskinen
Charles Kerrigan
Rémi Bouchez
Organisations
Bain & Co. · Halcyon · Aalto University School of Business · CMS · Vestiaire Collective · Kering