Survey Report · August 2026

Every CISO feels the pressure to secure AI.
Almost none feel ready.

We surveyed 200 CISOs, CTOs, CAOs, and CIOs at companies with 1,000+ employees to learn how they're securing AI deployments — and uncovered a widening gap between the pressure to move fast and the identity infrastructure needed to do it safely.

6-minute read of the findings. No fluff — just the data.

Download the Full Report

93%
are concerned about the new security risks AI deployments introduce
85%
aren't fully confident their current security stack can protect AI deployments
69%
say machine workloads are where their security confidence is lowest
14%
average projected growth in external attack surface over the next 12 months
// The Core Finding

The problem isn't AI. It's that machines don't have identities.

Zero trust architectures like SASE and ZTNA were built on one assumption: every connection has a human behind it with a verifiable identity. Agents, models, and the services behind them break that assumption — and the survey shows security leaders know it.

76%

point to complex non-human identity and authentication as a major driver of attack surface change.

72%

rank insufficient access controls for non-human identity as their top security concern with AI.

8%

describe their current identity systems as very sufficient for securing non-human workloads.

85%

are now actively evaluating or exploring new approaches to secure non-human identities.

// Deployment Velocity

Change management is slowing AI down as much as any technical barrier.

Firewall rules, NAT, routing, DNS, access exceptions — every new model, API, or data path an AI deployment touches triggers another round of network change control.

  • Orgs where routine firewall changes now take a week or more 54%
  • Orgs reporting 1–2 weeks of delay from network changes alone 51%
  • Cite risk/compliance approvals as a top contributor to delay 55%
  • Cite cross-team dependencies (network, security, cloud, app) as a top contributor 55%
8 days
average time added per request, from network change to implementation
 
request submitted51% land at 1–2 weeks
// What's Inside

Twelve findings. Every one benchmarked by industry, company size, and role.

CISOs and CTOs don't always see the same risk the same way — the full report breaks out where they agree, where they diverge, and why.

01Organizational pressure to securely deploy AI capabilitiesp.7
02Level of concern regarding new security risks from AI deploymentsp.8
03Confidence in current security solutions to protect AI deploymentsp.9
04Types of connectivity and access with the lowest security confidencep.10
05Expected attack surface increase over the next 12 monthsp.11
06Key aspects of AI deployments contributing most to attack surface changep.12
07Primary security concerns related to AI deploymentsp.13
08Level of concern regarding shadow AI and unsanctioned usagep.14
09Typical delays added by network change management processesp.15
10Main contributors to network or connectivity change delaysp.16
11Active evaluation of new approaches to secure non-human identitiesp.17
12Full demographic breakdown & methodologyp.18
// Why This Matters To You

Built for the people actually closing this gap.

This isn't a report written for the boardroom. Every finding maps to a decision someone in infrastructure, security, or platform engineering is making right now.

CISO

Only 10% of CISOs report high confidence in their current AI security posture.

See how your peers are answering the questions your board is about to ask you.

CTO

CTOs are more worried about infrastructure vulnerabilities than CISOs are.

60% vs. 41% — the people building AI infrastructure see the risk up close. The report shows where.

VP, Network Infrastructure

Cross-team dependencies are tied for the #1 cause of connectivity delays.

Benchmark your change management cycle time against 200 peer organizations.

Head of DevOps

8 days, on average, from request to implementation for a single network change.

Find out what's actually driving the delay — and where automation would help most.

AI Platform Engineer

54% point to new AI-specific services — MCP servers, LLM gateways — as attack surface drivers.

Get the breakdown on what's expanding your exposure as you ship more agents.

CIO / CAO

85% of organizations are rethinking how they secure non-human identity.

Understand where your organization stands relative to the rest of the market.

200senior security & technology leaders
CISO / CTO / CAO / CIOtitles surveyed
1,000+employees, United States
Global Surveyzindependent research firm
May–Jun 2026fielding period
// Get The Report

Read the full 2026 State of Secure AI Access report.

All 20 pages, every chart, and the full breakdown by industry, company size, and role — including the findings your peers are already acting on.

  12 data-backed findings, benchmarked by industry and role
  CISO vs. CTO perspective breakdowns on every major question
  Full methodology and demographic detail for internal citation
Get the Full Report
NetFoundry State of Secure AI Connectivity Report