
In-Depth Research
2026 State of AI Security Report
AI Security Findings from 1,200+ Production Organizations

AI Adoption Has Outpaced Your Security Playbook
Leveraging real-world telemetry from over 1,200 production organizations, this report examines the current state of AI security across cloud environments. The findings reveal a widening gap between the speed of AI adoption and the maturity of AI security practices.
of organizations with AI packages have at least one known vulnerability.
of AI package vulnerability alerts have a public exploit available.
of SageMaker organizations run with all default settings enabled.
of users across Anthropic, OpenAI, and HuggingFace have at least one API key stored in an unsecure location.
of Bedrock organizations run agents without guardrails.
of AI cloud service users operate four or more distinct AI service types.
AI is in Production.
Security Isn’t.
AI has fundamentally reshaped how organizations build, deploy, and operate in the cloud, but security has not kept pace.
In just two years, AI has moved from experimental pilots to production infrastructure. The controls needed to govern these systems exist but adoption lags AI deployment by a wide margin, and basic hygiene practices are still being skipped under the pressure of the speed-to-deploy cycle.
This report is designed to help teams understand where these risks are emerging and what to do about them.
Key Trends Defining AI Security in 2026
AI adoption is mainstream, but security remains an afterthought
AI workloads are being deployed at scale with the same lack of hardening that defined early cloud adoption years ago.
51%
of organizations have adopted AI to build custom applications.
80%
Yet
of organizations still contain Log4Shell-affected dependencies.
AI package vulnerabilities are pervasive, exploitable, and unpatched
81% of organizations with AI packages have at least one known vulnerability, with an average CVSS score of 8.79.
50%
of all AI vulnerability alerts now have a public exploit available, a dramatic surge from just 0.2% from our 2024 report.
99%
of alerts with an available fix remain unpatched.
Encryption is effectively absent across all clouds
This gap spans all three major cloud providers and leaves AI training data, models, and inference pipelines protected only by default provider-managed encryption.
87%
of organizations using AI services have not configured customer-managed encryption keys (CMEK).
98%
of SageMaker notebooks lack CMEK, the highest rate of any AI service.
AI sprawl is outpacing governance
With a fragmented vector database market, consistent security policy across this landscape is nearly impossible for most organizations.
55%
of AI cloud service users operate four or more distinct AI service types.
19%
use seven or more.
A Message from Orca Security CEO Gil Geron

AI has led to exponential growth in the employees shipping to production and security teams are not keeping up. When the way people build changes, the way security works has to change with it. This report measures that gap, and closing it starts with giving security teams the context to understand AI risk and act.”
Gil Geron
CEO and Co-Founder of Orca Security
Explore the full 2026 State of AI Security Report
Based on aggregated, anonymized telemetry collected during Q2 2026, this report provides a comprehensive analysis of real-world artificial intelligence security risks.
Discover the most urgent AI security trends and challenges, including:
- AI credential exposure across OpenAI, Anthropic, and HuggingFace deployments
- Supply chain attacks targeting AI packages and model registries
- Autonomous agents operating in production without guardrails or policy controls
- AI infrastructure misconfigurations and insecure defaults at scale
- Encryption gaps spanning SageMaker, Azure OpenAI, and Vertex AI
- RAG pipelines connecting foundation models to sensitive enterprise data
- AI service sprawl outpacing security governance and visibility
- Key recommendations to prioritize and reduce real production risk