Here’s a fun little contradiction to start your week with: NetFoundry asked 200 CISOs and CTOs whether they feel pressure to secure the AI they’re deploying. Unsurprisingly, and to my considerable relief, every single one said “yes”.
We then asked how confident they are that their current tools can actually handle the new risks, and 15% said “very.” 15% is very slightly less that the odds for rolling six on a 1d6. More specifically, among the CISOs, whose entire job is to be the professional pessimist in the room, that figure dropped to 10%.
That’s the current situation: Universal pressure, near-universal doubt.
Disclaimer and where the survey comes from

I work at NetFoundry as a developer advocate, and NetFoundry commissioned this report. So yes, this is a vendor survey, and you’re correct to raise an eyebrow. (I’d be worried if you didn’t).
In our defense, we did the thing you’re supposed to do: the survey itself was run by an independent research firm (Global Surveyz), the respondents were 200 US-based security and technology leaders at companies with 1,000+ employees, and it was fielded this past May and June. The full thing is linked at the bottom so you can check my arithmetic and decide for yourself whether I’m cherry-picking.
I’m going to try very hard to separate what the survey found from what I think it means. The first category is data. The second category is me, a guy on the internet, having opinions, which won’t always be the same as NetFoundry’s Marketign department (it happens). I’ll flag which is which.
The number that reframed the whole thing for me
Of everything in here, this is the one I keep coming back to:
Security leaders are nearly 10x more likely to worry about securing machine-to-machine workloads than human access to applications.
Specifically: 69% said machine workloads (service-to-service, API-to-API, agent-to-whatever) are where they’re least confident today. Just 7% said human user access. The remaining 24% said “both equally,” which I read as “please don’t make me pick.”
That tracks perfectly, and it’s a compliment to the last decade of security work. Think about what we spent the 2020s doing. COVID sent everyone home, remote access became the whole ballgame, and the industry poured an enormous amount of money and brainpower into VPNs, Zero Trust access, and all sorts of security measures for a world that was suddenly more online that ever. It worked, and hman access to applications is, comparatively, a solved-ish problem. We got good at authenticating people. (I should know; it was during that time that I worked at Auth0!)
The issue of identity
The catch is that all of that machinery is built on one quiet assumption: that the thing connecting to your app is a human being with a unique identity. You authenticate the person, then you grant the access.

Agents and models don’t work like that. They don’t have identities the way humans do. So the tooling we built for the last problem doesn’t cleanly transfer to this one, and the volume is going the wrong direction, fast. Machine traffic is now growing several times faster than human traffic year over year. We got really good at guarding a door that fewer and fewer of the visitors are actually using.
A few more stats worth your attention:
- 100% agree their attack surface is growing. Not a plurality. Not a strong majority. Everyone. The average projected increase was 14% over the next 12 months, and that figure only counts AI deployments already underway or planned. 14% is probably the minimum.
- 93% are concerned about the new risks AI introduces, but only 15% are highly confident their current tools can handle them. That’s the gap I opened with. When the level of concern and the level of confidence are that far apart, something structural is going on.
- 99% admit they don’t have full visibility into their own AI deployments. That remaining 1%, which would have to be one respondent? I would like to buy that person a coffee (or beer! or bourbon!) and ask them a lot of questions.
- 90% are worried about shadow AI, the unsanctioned tools employees adopt on their own because the approved options don’t cut it. This is not a technology problem, it’s a human-nature problem. I will neither confirm nor deny my own contributions to the shadow AI at previous organizations, but in my defense, I was getting things done! When a tool is genuinely useful, people use it, memo or no memo.
- Only 8% call their current identity systems “very sufficient” for non-human workloads. 85% are now actively evaluating or exploring new approaches. That second number is the tell. When five out of six organizations are shopping for a new approach at the same time, that’s teh surest indicator that the industry is collectively coming to the realization that the existing tools weren’t built for this.
- Oh, and it’s slow. 55% cited risk and compliance review as a top contributor to delays in the network changes AI deployments need, and those changes add an average of 8 days from request to implementation. And that’s now, while AI-specific scrutiny is still warming up.
My read (this part is me, not the data)
In this section, I’m switching from reporting to speculating.
I think almost every number above traces back to one root cause: machines don’t have real identities. They have internal names so that developers and devops people can talk about them, but when it comes to having reasonably canonical identities like we humans do (full name, usernames, an email address, a government-issued unique ID number), we haven’t really created these for machines.
In the absence of machine identities, we have workarounds. On the less secure end, we have IP addresses; on the (relatively) more secure end, there are shared secrets, API keys, long-lived service-account credentials. As with most workarounds, they quietly rot. The credentials we give machines tend to carry more permission than they need. They rarely get rotated. After a while nobody’s entirely sure which agent a given key even belongs to, or why it exists.
Once you’re in that world, everything downstream gets harder. Visibility is hard because you can’t tell one agent’s actions from another’s. Access control is hard because a secret isn’t an identity, it’s some piece of data that happens to belong to a robot (and all too easily duplicated). Auditing is hard for both of those reasons at once. The identity gap is the root problem of most of the other security problems in the AI age.
NetFoundry — who are made of some very smart people, a few of whom are literal greybeards! — obviously has opinions about how to close that gap, and the report gets into them. That’s the vendor part, and you can take it or leave it.
But strip the logo off and the underlying observation stands on its own: we spent a decade giving humans strong identities and largely ignored the machines, and now the machines are the fastest-growing thing on the network. That bill was always going to come due. It’s just arriving faster than most people planned for.
|
In case you saw the em-dashes in the paragraph above and thought “Aha! AI!’, I assure you that I typed them in myself, because this is my relationship with AI: Entering em-dashes is dirt simple on macOS: option-shift-minus. On Windows it’s a little more work: alt+0151. On Linux: control-shift-U, then release and type 2014, then return/enter. Let me have just a couple of em-dashes in my article. Please. |
The stat I want ask you about
That 14% attack-surface increase feels low to me. If you’re actually running agents in production right now, watching them spawn sub-agents and reach across cloud boundaries and pick up new tool integrations every sprint, does 14% over a year match what you’re seeing, or is it wildly optimistic?
(That’s a genuine question, not a rhetorical one. I’d rather hear it from people living it than trust my own gut.)
Read the full 2026 State of Secure AI Access report!
Download it here. (You have to provide a little info to get it.)






































































































































