The 2026 State of Secure AI Access report reveals security leaders are under near-universal pressure to deploy AI, yet just 15% are confident their current tools can protect it — with non-human identity and machine workloads emerging as the critical gap
NetFoundry, the leader in Zero Trust Workload Connectivity, today released its 2026 State of Secure AI Access report, an independent survey of 200 CISOs and CTOs at enterprises across industries and company sizes. The findings paint a picture of security and technology leaders caught between intense pressure to ship AI and a growing recognition that the way machines connect to one another — not the way humans connect to applications — is the part of their environment they are least equipped to secure.
The headline is stark: every leader surveyed (100%) says AI is expanding their organization’s attack surface, and on average they expect that attack surface to grow another 14% over the next 12 months. The timing couldn’t be worse, as attackers have made this same growing attack surface their dominant vector for initial compromise. Just 8% said their current identity systems are very sufficient for securing and monitoring AI-driven or non-human workloads, and 85% of respondents are either actively evaluating or exploring new approaches to secure non-human identities.
Analyst perspective
As per the Gartner® 2025 Machine Identity survey, “Despite 94% of organizations reporting an increase in machine identities driven by AI/ML adoption and cloud expansion, 42% lack a formal machine IAM strategy. Organizations struggle with fragmented ownership, lack of risk awareness and limited visibility into machine identities, and 58% of organizations have experienced security events due to that lack of machine identity oversight.”
Source: Gartner, “Hype Cycle
for Digital Identity, 2026,” Zachary Smith, Nayara Sangiorgio, 6 July 2026 GARTNER and HYPE CYCLE are trademarks of Gartner, Inc. and/or its affiliates.
The pressure is on — but the confidence isn’t there
78% of respondents are under high or very high pressure to securely deploy AI capabilities. Yet that urgency collides with deep unease: 93% of leaders are concerned about new security risks introduced by AI deployments, and more than half (53%) say they are very concerned.
Most striking is the confidence gap. Despite that near-universal concern, only 15% of leaders are very confident their current security solutions can adequately protect their AI deployments. CISOs are even more sober than their peers: just 10% are very confident, versus 18% of CTOs.
Executive perspective
“AI has fundamentally changed what enterprises need to secure. For a decade we built security around human identity, but the fastest-growing risk today is machines connecting to machines — agents, models, MCP servers, APIs, and data moving across clouds, edges, and partners. This survey confirms what we hear from customers every day: leaders know their VPN- and firewall-era tools weren’t designed for this, and they’re urgently looking for an identity-first approach that gives every workload a verifiable identity and eliminates the reachable attack surface entirely.”
— Galeal Zino, CEO, NetFoundry
The full report is available at https://info.netfoundry.io/lp-survey-august-2026
The post Survey: AI Expands Attack Surfaces, M2M Security Is Blind Spot first appeared on AI-Tech Park.


