# NetFoundry Survey Shows AI Expanding Enterprise Attack Surfaces by 14 Percent

> Data from 200 CISOs and CTOs at large enterprises reveals universal recognition of AI-driven risks, low confidence in legacy tools, and urgent calls for machine identity governance to address shadow AI and non-human workloads.

*Published 2026-08-12 · By Diane Okafor*

Enterprise AI security is the set of controls, visibility mechanisms, and governance practices required to protect non-human identities, AI agents, models, and machine-to-machine connections from unauthorized access across distributed enterprise environments.

The 2026 State of Secure AI Access report from NetFoundry, fielded by Global Surveyz Research, polled 200 CISOs and CTOs at enterprises with at least 1,000 employees during May and June 2026. Every participant stated that AI deployments are enlarging organizational attack surfaces. The average projected increase reaches 14 percent within the coming year.

## What scale of attack surface growth accompanies AI deployments?

Respondents uniformly acknowledged expansion driven by new AI connections to applications, data repositories, and external services. This growth stems from agents, models, and APIs that operate without traditional human oversight. The 14 percent figure represents an aggregate expectation across the sample and signals accelerating exposure in hybrid cloud and edge settings.

Security teams must now account for machine-to-machine traffic that bypasses perimeter defenses designed for user sessions. The addition of non-human workloads multiplies potential entry points for lateral movement. Enterprises therefore face pressure to map these new vectors before they compound existing vulnerabilities.

## How widespread are concerns about shadow AI?

Ninety percent of leaders expressed worry over employees deploying unapproved AI tools without central oversight. Such shadow usage introduces unmonitored data flows and model interactions that evade corporate policy. The concern aligns with broader findings that 93 percent of respondents worry about novel risks created by AI systems overall.

Shadow AI complicates efforts to maintain an accurate inventory of authorized workloads. Without visibility, organizations cannot apply consistent identity or access policies. The resulting blind spots increase the likelihood of data exfiltration or model poisoning through unofficial channels.

## What confidence levels exist in current security solutions?

Only 15 percent of leaders indicated they are very confident that existing tools can safeguard AI deployments. The split shows 10 percent of CISOs versus 18 percent of CTOs holding this high level of assurance. The majority therefore operate with acknowledged gaps in protection for AI-specific threats.

Legacy solutions built around human identity management struggle to scale to the volume and velocity of machine identities. This shortfall leaves organizations exposed as AI adoption accelerates under 78 percent high or very high internal pressure to deliver capabilities securely.

## How adequate are existing identity systems for AI workloads?

Eight percent of respondents rated their current identity systems as very sufficient for securing and monitoring AI-driven or non-human workloads. The remaining 85 percent are actively evaluating or exploring alternative approaches. This near-universal reassessment reflects recognition that VPN-era and firewall-centric models were not engineered for agentic and model-to-model interactions.

NetFoundry 2026 State of Secure AI Access Survey Results on Enterprise AI Security MetricsKey FindingStatisticAttack surface growth from AI14 percent average over 12 monthsConcern over shadow AI90 percent of leadersConfidence in current security tools15 percent very confidentPressure to deploy AI securely78 percent high or very highConcern over new AI risks93 percent of leadersIdentity system sufficiency for AI8 percent very sufficientActively exploring new identity approaches85 percent of respondents

## What organizational pressures drive AI security decisions?

Seventy-eight percent of participants described high or very high pressure within their organizations to implement AI capabilities while maintaining security. This mandate coincides with the 93 percent who anticipate fresh risks from these deployments. Decision makers must therefore balance rapid adoption against expanding threat surfaces.

The data indicate that security leaders recognize the mismatch between human-centric tools and the machine identity demands of AI. Enterprises are consequently prioritizing visibility into AI workloads and governance frameworks that can scale beyond traditional perimeter controls.

- Map all AI agents, models, and APIs to establish a complete inventory of non-human identities.
- Assign verifiable, workload-specific identities to every machine connection.
- Deploy continuous monitoring to detect unauthorized shadow AI usage.
- Evaluate identity-first architectures that eliminate reachable attack surfaces for machine-to-machine traffic.
- Establish cross-functional governance to align security, compliance, and business AI objectives.

## What expert perspectives address the survey findings?

Galeal Zino, CEO of NetFoundry, emphasized the shift from human to machine identity risks. His assessment draws directly from customer feedback and the survey results showing widespread reevaluation of legacy controls.

> AI has fundamentally changed what enterprises need to secure. For a decade we built security around human identity, but the fastest-growing risk today is machines connecting to machines — agents, models, MCP servers, APIs, and data moving across clouds, edges, and partners. This survey confirms what we hear from customers every day: leaders know their VPN- and firewall-era tools weren’t designed for this, and they’re urgently looking for an identity-first approach that gives every workload a verifiable identity and eliminates the reachable attack surface entirely.Galeal Zino, CEO, NetFoundry

## What market and stakeholder implications follow from these results?

The findings point to sustained demand for solutions that deliver machine identity management at enterprise scale. Vendors offering visibility, zero-trust controls for non-human workloads, and governance overlays stand to benefit as 85 percent of organizations explore new approaches. CISOs in particular face accountability for closing the gap between 15 percent confidence and the 100 percent acknowledgment of expanded surfaces.

Stakeholders across procurement, compliance, and operations must integrate these metrics into roadmap planning. The 14 percent average growth projection provides a quantifiable baseline for measuring progress in attack surface reduction over the next year.

## What developments are expected next in enterprise AI security?

With 85 percent of leaders actively assessing new identity strategies, adoption of workload-centric controls is likely to accelerate. Organizations that implement verifiable identities and eliminate unnecessary exposure pathways can reduce the effective attack surface even as AI usage grows. Continued monitoring of shadow AI prevalence will remain essential to close visibility gaps identified in the survey.

The survey underscores that security architectures must evolve in tandem with AI deployment velocity. Enterprises prioritizing these adjustments position themselves to meet both internal pressure for AI capabilities and external regulatory expectations around data protection.

## Sources

1. [The 2026 State of Secure AI Access report reveals security leaders are under near-universal pressure to deploy AI, yet just 15% are confident their current tools can protect it — with non-human identity and machine workloads emerging as the critical gap. CHARLOTTE, N.C. — August 11, 2026](https://netfoundry.io/press-release/survey-report-2026-state-of-secure-ai-access/)
2. [CISOs and CTOs expect AI deployments to increase their organizations’ attack surface by an average of 14% over the next year. Nearly all lack visibility into AI deployments, and 90% are concerned about employees using unapproved AI tools outside formal oversight, according to NetFoundry’s 2026 State of Secure AI Access survey.](https://www.helpnetsecurity.com/2026/08/12/netfoundry-securing-ai-deployments-report/)

---
Source: https://aiintelreport.com/enterprise-ai/netfoundry-2026-secure-ai-access-survey
Index: https://aiintelreport.com/llms.txt · Full text: https://aiintelreport.com/llms-full.txt
