Every CISO feels the pressure to secure AI.
Almost none feel ready.
We surveyed 200 CISOs, CTOs, CAOs, and CIOs at companies with 1,000+ employees to learn how they're securing AI deployments — and uncovered a widening gap between the pressure to move fast and the identity infrastructure needed to do it safely.
6-minute read of the findings. No fluff — just the data.
Download the Full Report
The problem isn't AI. It's that machines don't have identities.
Zero trust architectures like SASE and ZTNA were built on one assumption: every connection has a human behind it with a verifiable identity. Agents, models, and the services behind them break that assumption — and the survey shows security leaders know it.
point to complex non-human identity and authentication as a major driver of attack surface change.
rank insufficient access controls for non-human identity as their top security concern with AI.
describe their current identity systems as very sufficient for securing non-human workloads.
are now actively evaluating or exploring new approaches to secure non-human identities.
Change management is slowing AI down as much as any technical barrier.
Firewall rules, NAT, routing, DNS, access exceptions — every new model, API, or data path an AI deployment touches triggers another round of network change control.
- Orgs where routine firewall changes now take a week or more 54%
- Orgs reporting 1–2 weeks of delay from network changes alone 51%
- Cite risk/compliance approvals as a top contributor to delay 55%
- Cite cross-team dependencies (network, security, cloud, app) as a top contributor 55%
Twelve findings. Every one benchmarked by industry, company size, and role.
CISOs and CTOs don't always see the same risk the same way — the full report breaks out where they agree, where they diverge, and why.
Built for the people actually closing this gap.
This isn't a report written for the boardroom. Every finding maps to a decision someone in infrastructure, security, or platform engineering is making right now.
Only 10% of CISOs report high confidence in their current AI security posture.
See how your peers are answering the questions your board is about to ask you.
CTOs are more worried about infrastructure vulnerabilities than CISOs are.
60% vs. 41% — the people building AI infrastructure see the risk up close. The report shows where.
Cross-team dependencies are tied for the #1 cause of connectivity delays.
Benchmark your change management cycle time against 200 peer organizations.
8 days, on average, from request to implementation for a single network change.
Find out what's actually driving the delay — and where automation would help most.
54% point to new AI-specific services — MCP servers, LLM gateways — as attack surface drivers.
Get the breakdown on what's expanding your exposure as you ship more agents.
85% of organizations are rethinking how they secure non-human identity.
Understand where your organization stands relative to the rest of the market.
Read the full 2026 State of Secure AI Access report.
All 20 pages, every chart, and the full breakdown by industry, company size, and role — including the findings your peers are already acting on.
