Organizations are rapidly increasing their adoption of artificial intelligence (AI) technologies, but security measures are failing to keep pace, resulting in a widening exposure gap. Surveys from Red Canary and Tenable highlight that while security budgets and tool sophistication have grown, incident response times are slowing, and the attack surface is expanding—particularly as AI becomes embedded in business operations. Key targets remain email, identity, and endpoints, with a significant portion of organizations experiencing incidents in these areas. Despite efforts to consolidate security tools, most teams report longer detection-to-resolution times, and the business impact includes substantial financial losses, data breaches, and service disruptions.
The rush to integrate AI has outstripped the ability to secure it, with most organizations adopting AI faster than they can implement effective protections. While many are aligning with frameworks like the EU AI Act and NIST AI RMF, few are translating these into practical controls such as data encryption, system testing, or robust identity management for AI systems. As AI pipelines and connections proliferate across productivity apps, browsers, and cloud services, new attack vectors emerge, leaving critical systems and data increasingly vulnerable. Proactive defense and continuous visibility are recommended to close the gap between AI innovation and enterprise security readiness.

Track how attackers are adapting to this technology.
1 event from the most recent confirmed update back to the earliest known activity.
Initial story creation
Follow how adversaries are adapting to this technology, and where it touches your stack today.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.