FireTail State of AI Security 2026: Adoption Has Outpaced Control

FireTail Research tracks AI security incidents continuously, maintaining an incident tracker alongside the AI Incident Database and the AIAAIC repository. Each year the team compiles what that record shows into the State of AI Security report.

FireTail State of AI Security 2026: Adoption Has Outpaced Control

Organisations deployed AI faster than the controls needed to secure it, and the gap between the two is now the defining exposure of the year.

Every major technology shift of the last two decades has followed the same pattern. Adoption runs ahead, the threat model changes, and defenders spend a year or two catching up. Cloud did it. Mobile, SaaS and containers did it. What is different about AI is the compression. Each prior shift gave security teams months or years to observe the problem and build controls for it. AI has reduced that window to weeks.

FireTail Research tracks AI security incidents continuously, maintaining an incident tracker alongside the AI Incident Database and the AIAAIC repository. Each year the team compiles what that record shows into the State of AI Security report. Looking back over the twelve months to June 2026, the clearest trend was not a novel attack technique. It was the distance between how much AI is now running inside organisations and how much of it anyone is watching.

The FireTail State of AI Security 2026 report covers what changed, the incidents that defined the year, six attack patterns reconstructed step by step, the frameworks converging on a common set of controls, and the ninety days of work that closes the most ground. This year it is published as an interactive report rather than a PDF, open and with no form to complete.

Read the report: FireTail State of AI Security 2026

The gap between adoption and control

Around 90% of enterprise AI usage is untracked, ungoverned or unsecured by the security team responsible for it. Only 29% of organisations report having the controls in place to secure what they have deployed. That 61-point gap is the central finding of the report and the condition underneath almost every incident in the dataset.

Adoption is what widened it. The share of organisations running AI agents moved from 16% to 83% in twelve months, the fastest enterprise adoption curve since cloud. In June 2026, Cloudflare confirmed that automated traffic had exceeded human traffic on the web for the first time, with 57.4% of requests now non-human. The attack surface is no longer a subset of the network.

Existing controls do not close the gap because they were built for a different set of assumptions. DLP inspects egress channels and fingerprints known-sensitive content, so it cannot read the semantic intent of an AI interaction or measure exposure by token count. SIEM correlates normalised telemetry, but inference calls and tool invocations emit no native audit event. A SOC triages known tactics and tuned signatures, and a prompt injection carried in natural language leaves few of the indicators it is tuned to catch. Lateral movement has collapsed into a single tool call, and the motion defenders were trained to recognise no longer happens.

What the incident record shows

The combined and de-duplicated dataset documents 302 publicly disclosed incidents over the twelve months to June 2026, a run rate tracking above the fourfold year-on-year increase recorded from 2024 to 2025. Data exfiltration is the largest category by a wide margin at 35% of incidents, ahead of prompt injection, rogue agents and supply chain compromise combined.

The mechanisms are mostly unremarkable. Employees uploading sensitive data to unauthorised tools. Credentials left in agent code. Agent endpoints shipped without authentication. The exposure sits in the infrastructure around the model rather than in the model itself, in the packages, cloud environments, APIs and service connections that hold the environment together, and in the permissions nobody re-examined after deployment day. IBM found that 68% of breached organisations had no AI governance policy in place at the time of the incident.

Three incidents defined the year, and the report reconstructs each in full. OpenClaw, where an unauthenticated agent API server and an unsigned skills marketplace produced the first mainstream agentic security crisis. The Mythos episode, where a frontier model proved effective enough at vulnerability discovery that its maker restricted the capability behind a vetting programme. And the Hugging Face breach in July, where an autonomous agent chained two zero-days to escape a sandbox and reach remote code execution across two organisations' infrastructure, with no human directing any step of it.

Further findings examined in this year's report:

  • Prompt injection accounts for 16% of incidents, rogue agents 12%, shadow AI 11% and API or endpoint exposure 11%, with OAuth abuse, supply chain and MCP tool poisoning making up the remainder
  • AI runtime monitoring is associated with $1.93M less per breach and containment 65 days faster, according to IBM
  • Enterprise SaaS and healthcare account for nearly 40% of tracked incidents, with government trailing in volume but leading in severity
  • Average breach cost by threat vector ranges from $4.32M to $6.07M, set against the primary control for each vector and the time required to stand it up
  • The two highest-reduction controls are also among the quickest to deploy, with an authenticated AI API gateway at roughly 91% and input sanitisation ahead of the model at roughly 82%, both inside four weeks
  • Six frameworks now converge on the same short list of controls, including the EU AI Act, whose Article 50 transparency obligations took effect on 2 August 2026

Every attack walkthrough in the report is grounded in a CVE, a vendor disclosure or peer-reviewed research and cited in place. Market statistics come from independent research by organisations including Cisco, IBM and Gartner. First-party findings draw on aggregated, de-identified data from FireTail customer environments.

Where the work starts

The report closes with twelve actions across three horizons, ordered by how quickly they pay back. Most of the first thirty days is configuration rather than procurement, and much of it runs on tooling organisations already own. That order is deliberate, because every incident in the dataset traces back to the same starting condition. AI that has not been found cannot be governed, logged or secured.

FireTail builds for that first problem. The report explains why it is still the one most organisations have not solved.

Read the FireTail State of AI Security 2026 report · Benchmark your own organisation

Discover your AI exposure now

See how FireTail provides a single platfrom to discover, assess, and protect all AI usage across your organization.