Enterprise AI
NetFoundry Survey Shows AI Expanding Enterprise Attack Surfaces by 14 Percent
Data from 200 CISOs and CTOs at large enterprises reveals universal recognition of AI-driven risks, low confidence in legacy tools, and urgent calls for machine identity governance to address shadow AI and non-human workloads.
Enterprise AI security is the set of controls, visibility mechanisms, and governance practices required to protect non-human identities, AI agents, models, and machine-to-machine connections from unauthorized access across distributed enterprise environments.
The 2026 State of Secure AI Access report from NetFoundry, fielded by Global Surveyz Research, polled 200 CISOs and CTOs at enterprises with at least 1,000 employees during May and June 2026. Every participant stated that AI deployments are enlarging organizational attack surfaces. The average projected increase reaches 14 percent within the coming year.
What scale of attack surface growth accompanies AI deployments?
Respondents uniformly acknowledged expansion driven by new AI connections to applications, data repositories, and external services. This growth stems from agents, models, and APIs that operate without traditional human oversight. The 14 percent figure represents an aggregate expectation across the sample and signals accelerating exposure in hybrid cloud and edge settings.
Security teams must now account for machine-to-machine traffic that bypasses perimeter defenses designed for user sessions. The addition of non-human workloads multiplies potential entry points for lateral movement. Enterprises therefore face pressure to map these new vectors before they compound existing vulnerabilities.
How widespread are concerns about shadow AI?
Ninety percent of leaders expressed worry over employees deploying unapproved AI tools without central oversight. Such shadow usage introduces unmonitored data flows and model interactions that evade corporate policy. The concern aligns with broader findings that 93 percent of respondents worry about novel risks created by AI systems overall.
Shadow AI complicates efforts to maintain an accurate inventory of authorized workloads. Without visibility, organizations cannot apply consistent identity or access policies. The resulting blind spots increase the likelihood of data exfiltration or model poisoning through unofficial channels.
What confidence levels exist in current security solutions?
Only 15 percent of leaders indicated they are very confident that existing tools can safeguard AI deployments. The split shows 10 percent of CISOs versus 18 percent of CTOs holding this high level of assurance. The majority therefore operate with acknowledged gaps in protection for AI-specific threats.
Legacy solutions built around human identity management struggle to scale to the volume and velocity of machine identities. This shortfall leaves organizations exposed as AI adoption accelerates under 78 percent high or very high internal pressure to deliver capabilities securely.
How adequate are existing identity systems for AI workloads?
Eight percent of respondents rated their current identity systems as very sufficient for securing and monitoring AI-driven or non-human workloads. The remaining 85 percent are actively evaluating or exploring alternative approaches. This near-universal reassessment reflects recognition that VPN-era and firewall-centric models were not engineered for agentic and model-to-model interactions.
| Key Finding | Statistic |
|---|---|
| Attack surface growth from AI | 14 percent average over 12 months |
| Concern over shadow AI | 90 percent of leaders |
| Confidence in current security tools | 15 percent very confident |
| Pressure to deploy AI securely | 78 percent high or very high |
| Concern over new AI risks | 93 percent of leaders |
| Identity system sufficiency for AI | 8 percent very sufficient |
| Actively exploring new identity approaches | 85 percent of respondents |
What organizational pressures drive AI security decisions?
Seventy-eight percent of participants described high or very high pressure within their organizations to implement AI capabilities while maintaining security. This mandate coincides with the 93 percent who anticipate fresh risks from these deployments. Decision makers must therefore balance rapid adoption against expanding threat surfaces.
The data indicate that security leaders recognize the mismatch between human-centric tools and the machine identity demands of AI. Enterprises are consequently prioritizing visibility into AI workloads and governance frameworks that can scale beyond traditional perimeter controls.
- Map all AI agents, models, and APIs to establish a complete inventory of non-human identities.
- Assign verifiable, workload-specific identities to every machine connection.
- Deploy continuous monitoring to detect unauthorized shadow AI usage.
- Evaluate identity-first architectures that eliminate reachable attack surfaces for machine-to-machine traffic.
- Establish cross-functional governance to align security, compliance, and business AI objectives.
What expert perspectives address the survey findings?
Galeal Zino, CEO of NetFoundry, emphasized the shift from human to machine identity risks. His assessment draws directly from customer feedback and the survey results showing widespread reevaluation of legacy controls.
AI has fundamentally changed what enterprises need to secure. For a decade we built security around human identity, but the fastest-growing risk today is machines connecting to machines — agents, models, MCP servers, APIs, and data moving across clouds, edges, and partners. This survey confirms what we hear from customers every day: leaders know their VPN- and firewall-era tools weren’t designed for this, and they’re urgently looking for an identity-first approach that gives every workload a verifiable identity and eliminates the reachable attack surface entirely.Galeal Zino, CEO, NetFoundry
What market and stakeholder implications follow from these results?
The findings point to sustained demand for solutions that deliver machine identity management at enterprise scale. Vendors offering visibility, zero-trust controls for non-human workloads, and governance overlays stand to benefit as 85 percent of organizations explore new approaches. CISOs in particular face accountability for closing the gap between 15 percent confidence and the 100 percent acknowledgment of expanded surfaces.
Stakeholders across procurement, compliance, and operations must integrate these metrics into roadmap planning. The 14 percent average growth projection provides a quantifiable baseline for measuring progress in attack surface reduction over the next year.
What developments are expected next in enterprise AI security?
With 85 percent of leaders actively assessing new identity strategies, adoption of workload-centric controls is likely to accelerate. Organizations that implement verifiable identities and eliminate unnecessary exposure pathways can reduce the effective attack surface even as AI usage grows. Continued monitoring of shadow AI prevalence will remain essential to close visibility gaps identified in the survey.
The survey underscores that security architectures must evolve in tandem with AI deployment velocity. Enterprises prioritizing these adjustments position themselves to meet both internal pressure for AI capabilities and external regulatory expectations around data protection.
Frequently asked
What is the average expected attack surface growth from AI deployments according to the survey?
The NetFoundry 2026 survey reports an average expected growth of 14 percent over the next 12 months, with 100 percent of CISOs and CTOs confirming expansion.
How many leaders are concerned about shadow AI?
Ninety percent of surveyed leaders expressed concern about employees using unapproved AI tools outside formal oversight.
What percentage of respondents find current identity systems sufficient for AI workloads?
Only 8 percent rated their current identity systems as very sufficient, prompting 85 percent to explore new approaches.
Sources
- NetFoundry — The 2026 State of Secure AI Access report reveals security leaders are under near-universal pressure to deploy AI, yet just 15% are confident their current tools can protect it — with non-human identity and machine workloads emerging as the critical gap. CHARLOTTE, N.C. — August 11, 2026
- Help Net Security — CISOs and CTOs expect AI deployments to increase their organizations’ attack surface by an average of 14% over the next year. Nearly all lack visibility into AI deployments, and 90% are concerned about employees using unapproved AI tools outside formal oversight, according to NetFoundry’s 2026 State of Secure AI Access survey.