Site icon Back End News

Tenable report links AI adoption to growing cloud security risks

Tenable - Back End News

Organizations are facing growing cyber risks as artificial intelligence (AI) becomes more embedded in applications, infrastructure, and cloud environments, according to the Cloud and AI Security Risk Report 2026 released by Tenable, an exposure management company.

The report said many organizations are developing and deploying systems faster than security teams can evaluate and fix vulnerabilities. The gap between rapid AI adoption and the ability to manage risks is creating what Tenable calls an “AI exposure gap.”

This exposure can appear across applications, infrastructure, identities, AI agents, and data. The report noted that many security teams still lack the tools and visibility needed to manage these risks effectively.

“AI systems embedded in infrastructure pose a critical risk that CISOs and defenders must address, in addition to anticipating emerging threats from both AI and cloud technologies,” said Liat Hayun, senior vice president of product management and research at Tenable. “Lack of visibility and governance means teams are at the mercy of new exposures, including over-privileged identities in the cloud.” 

Tenable’s analysis of cloud environments found concerns in four areas: AI security posture, software supply chain risks, least-privilege access controls, and exposure of cloud workloads.

The study showed that 70% of organizations have integrated at least one AI or Model Context Protocol (MCP) third-party package. These packages embed AI capabilities into applications and infrastructure, often without centralized security oversight.

The report found that 86% of organizations host third-party code packages with critical vulnerabilities. Also, 13% have deployed packages that previously had security incidents, including those linked to the s1ngularity or Shai-Hulud worms.

About 18% of organizations grant AI services administrative permissions that are rarely reviewed. These permissions can create ready access points that attackers may exploit.

The report also found that non-human identities, such as AI agents and service accounts, pose higher risk than human users. Tenable estimates that 52% of security risks involve non-human identities, compared with 37% linked to human accounts.

Unused credentials also remain common. About 65% of organizations have “ghost” secrets, or cloud credentials that are unused or not regularly updated. Around 17% of these credentials are tied to administrative privileges.

Also, 49% of identities with critical excessive permissions are dormant, meaning they remain active despite not being used.

The Tenable Research team based the report on anonymized telemetry from public cloud and enterprise environments collected from April to October 2025, with AI-related findings extending through December 2025.

The report said organizations should improve visibility into AI integrations, apply stricter identity controls, and monitor third-party code to reduce risks in cloud and AI environments.

“By focusing on the unified exposure path, organizations can stop managing ‘security debt’ and start managing actual business risk,” Hayun said.

Exit mobile version