AI is expanding organizations’ attack surface, and on average security and technology professionals expect that attack surface to grow another 14 percent over the next 12 months, according to a report from zero trust security provider NetFoundry entitled, “2026 State of Secure AI Access,” an independent survey of 200 CISOs and CTOs at enterprises across industries and company sizes.
Attackers continue to make this growing attack surface their dominant vector for initial compromise.
In looking at the scenario, only 8 percent of respondents said their current identity systems very sufficient for securing and monitoring AI-driven or non-human workloads, and 85 percent said they are either actively evaluating or exploring new approaches to secure non-human identities.
High Pressure
Furthermore, 78 percent of respondents are under high or very high pressure to securely deploy AI capabilities. Yet that urgency collides with deep unease where 93 percent of leaders remain concerned about new security risks introduced by AI deployments, and 53 percent said they remain very concerned.
Despite that concern, only 15 percent of respondents are very confident their current security solutions can adequately protect their AI deployments. CISOs are more concerned as 10 percent are very confident, versus 18 percent of CTOs.
“AI has fundamentally changed what enterprises need to secure,” said Galeal Zino, chief executive at NetFoundry. “For a decade we built security around human identity, but the fastest-growing risk today is machines connecting to machines – agents, models, MCP servers, APIs, and data moving across clouds, edges, and partners. This survey confirms what we hear from customers every day: Leaders know their VPN- and firewall-era tools weren’t designed for this, and they’re urgently looking for an identity-first approach that gives every workload a verifiable identity and eliminates the reachable attack surface entirely.”
Click here to register for the full report.

