NetFoundry's 2026 State of Secure AI Access survey, fielded by Global Surveyz in May and June, found that 200 U.S.-based enterprise security and technology leaders expect AI deployments to expand their external attack surface by an average of 14% over the next 12 months. Help Net Security reports that 90% were concerned about unapproved AI tools, while only 8% considered their identity systems very sufficient for non-human workloads.
NetFoundry's vendor-commissioned 2026 State of Secure AI Access survey found that 200 U.S.-based security and technology leaders at organizations with more than 1,000 employees expect AI deployments to increase their external attack surface by an average of 14% over the next year. NetFoundry says the independent research firm Global Surveyz fielded the survey in May and June 2026. The vendor reports that 93% of respondents are concerned about new risks introduced by AI deployments, and 85% are not fully confident that their current security stack can protect those deployments.
Help Net Security, reporting on the survey, states that nearly all respondents lacked visibility into AI deployments and that 90% were concerned about employees using unapproved AI tools outside formal oversight. The publication also reported that only 15% were very confident that existing security tools could adequately protect AI deployments.
Non-human identity is the central reported concern
NetFoundry found that 69% of respondents had their lowest confidence in securing machine workloads, compared with human-access controls. It reported that 76% identified complex non-human identity and authentication as a major driver of attack-surface change, while 72% ranked insufficient access controls for non-human identity as their top AI security concern.
The survey distinguishes that broader tool-confidence measure from identity readiness: only 8% described their current identity systems as very sufficient for securing non-human workloads. NetFoundry frames the issue around agents, models, APIs, and supporting services that communicate across cloud environments and data sources, creating connections that conventional human-centric access controls were not designed to govern.
For ML and platform teams, the practical implication is that an AI application's exposure is not confined to a model endpoint. Service accounts, API credentials, retrieval systems, tool integrations, and agent-to-agent or agent-to-service calls can each create authorization and observability requirements. Inventorying those paths and applying workload-specific identity controls are recurring considerations in production AI architectures.
Network change processes add deployment friction
NetFoundry also reported that network change management is a material operational constraint. Fifty-four percent of surveyed organizations said routine firewall changes take a week or longer, 51% reported one to two weeks of delay from network changes alone, and the average time added per request from network change to implementation was eight days.
According to the survey, risk and compliance approvals and cross-team dependencies were each cited by 55% of respondents as leading contributors to delay. These reported bottlenecks matter because AI systems commonly connect multiple services across network and organizational boundaries. In comparable deployments, security review workflows can become part of the delivery path alongside model evaluation, data governance, and application testing.
The findings describe respondent expectations and confidence, not independently measured breach outcomes. The sample is also limited to 200 U.S.-based leaders at large organizations. Those constraints make the percentages a vendor-sponsored benchmark rather than a universal measure, but the survey still provides a useful checklist for teams assessing whether human-focused identity and network controls cover non-human AI workloads.
Key Points #
- 1NetFoundry's survey reports 14% average projected attack-surface growth as respondents add AI-connected services and external interfaces.
- 2Only 8% rated identity systems very sufficient for non-human workloads, highlighting a reported gap around machine authentication and authorization.
- 3Fifty-four percent said routine firewall changes take a week or longer, and network changes added eight days per request on average.
Scoring Rationale #
The survey offers timely enterprise benchmarks on AI attack-surface growth, shadow AI concerns, and non-human identity controls. Its vendor-commissioned methodology and 200-person U.S. enterprise sample limit generalizability, but the findings are directly relevant to ML platform, security, and infrastructure teams operating AI services.
Sources #
Primary source and supporting public references used for this report.
Practice with real FinTech & Trading data
90 SQL & Python problems · 15 industry datasets
[Active Verified Users by Income TierEasy](/problems/sql/active-verified-users-by-income)
[Technology Stocks with High BetaMedium](/problems/sql/technology-stocks-with-high-beta)
[Portfolio Performance ScorecardHard](/problems/sql/portfolio-performance-scorecard)
250 free problems · No credit card
See all FinTech & Trading problems