cd /news/ai-safety/secure-ai-adoption-starts-with-api-b… · home topics ai-safety article
[ARTICLE · art-85917] src=csoonline.com ↗ pub= topic=ai-safety verified=true sentiment=· neutral

Secure AI adoption starts with API best practices

Gartner forecasts worldwide AI spending will reach $2.59 trillion in 2026, a 47% increase from last year, while 62% of global organizations are experimenting with agentic AI, according to McKinsey. The Cloud Security Alliance reports that two-thirds of organizations experienced a cybersecurity incident linked to AI agents in the past year, and 87% suffered API-related security incidents, with AI-linked APIs the most common type. Security leaders must prioritize API discovery, protection, and governance to secure AI adoption, as 439 new AI-related CVEs were recorded last year, a 1025% annual increase, nearly all linked to APIs.

read4 min views2 publishedAug 4, 2026

You don’t need to be a fortune teller to understand where enterprise IT is headed. McKinsey reported in November that 62% of global organizations were experimenting, piloting or scaling agentic AI projects. More recently, Gartner forecast that worldwide spending on AI will top $2.59 trillion in 2026 – an increase of 47% from last year. But with all the opportunity of AI comes risk.

Two thirds of organizations have suffered from a cybersecurity incident linked to AI agents over the past year, according to the Cloud Security Alliance (CSA) – highlighting that these risks are no longer hypothetical.

As they work to protect their organization by enforcing safe, governed adoption of AI, security leaders are overlooking the critical role of mature API management. Securing AI at the agent layer is only part of the solution. Without rigorous API discovery, protection and governance in place, other investments in AI security could be in vain.

AI is nothing without APIs. LLMs ingest and generate huge volumes of data, which is accessed via APIs, at incredible scale. APIs that once were called a hundred or so times per day receive thousands of requests every minute thanks to AI-powered workloads.

It’s easy to see why APIs have become such a key mechanism for threat actors to exploit AI systems, or to exfiltrate data in the other direction. The challenge is that APIs have a long history of posing a challenge for security teams.

Some 87% of organizations suffered API-related security incidents last year, with APIs linked to AI the most commonly cited incident type, according to one study. A separate study last year recorded 439 new AI-related CVEs over the previous 12 months, marking an annual increase of 1025%. Nearly all were directly linked to APIs; including injection flaws, misconfigurations and new memory corruption vulnerabilities.

Closing this security gap isn’t just important to mitigate the financial and reputational damage of the worst-case scenario of a data breach. It’s also increasingly important to keep regulators happy. Both NIS2 and DORA, while not AI-focused regulations, certainly make a strong case for looking at AI capabilities through the lens of resilience and security.

One of the most acute challenges with API security is the proliferation of shadow and zombie APIs. Modern cloud and microservices environments are highly distributed, with APIs scattered everywhere – many of which are forgotten or have never even been recorded. That doesn’t matter to an AI agent. They’re highly resourceful at discovering APIs that are accessible, even if they’ve not been specifically asked or authorized to use that approach. If APIs offer a route to complete the task that’s been assigned to them, AI agents will invariably find and use them.

The issue is that these shadow or zombie APIs may not have been designed securely or in line with the organization’s current governance policies, leading to data loss or other unintended consequences. This was a major challenge even before Mythos changed the game for systems defenders and adversaries alike. With frontier models capable of discovering vulnerabilities and chaining exploits at a whole new speed and scale, the task of securing APIs is even more urgent.

There’s plenty of opportunities for threat actors – whether armed with the latest AI models or not, to probe for API vulnerabilities. There are also mounting real-world examples of incidents of AI agents going rogue.

One of the most widely publicized occurred when a Cursor coding agent permanently deleted a customer’s production database in just nine seconds. To do so, it found an API token stored in an unrelated file, which carried blanket permissions. No confirmation was required by the API to perform the operation.In a similar incident, Replit’s AI agent deleted a live production database despite being instructed not to.

These are useful cautionary tales. There are three key measures security leaders can implement to ensure this never happens to their organization:

What will separate the winners from the losers going forward is the ability to manage risk in a way that doesn’t constrain the business. That means agile, unintrusive, secure-by-design approaches built around runtime protection and comprehensive visibility into API posture.

The automobile sector is a great example of what’s happening in AI right now. When the industry was in its early days, the focus was on the basics – features that enabled the owner to get from A to B. As speed increased, people demanded safety – seatbelts, ABS brakes and roll bars.

Today the AI world is also accelerating. Businesses have moved beyond the stage of wanting to see that it works. Now, they want security and control – and that starts at the API layer.

**This article is published as part of the Foundry Expert Contributor Network.**Want to join?

── more in #ai-safety 4 stories · sorted by recency
── more on @gartner 3 stories trending now
sponsored brought to you by zahid.host 4,200+ EU-deployed projects
reading about agents? ship yours in a single git push.

Run your AI side-project on zahid.host

EU-based hosting, git-push deploys, automatic HTTPS, no cold starts. Free tier with a custom domain — perfect for shipping the agent you just read about.

$git push zahid main
Live at https://your-agent.zahid.host
Get free account → Pricing
from €0/mo · no card required
LIVE [news/secure-ai-adoption-s…] indexed:0 read:4min 2026-08-04 ·