Eskenzi PR ad banner Eskenzi PR ad banner
  • About Us
Thursday, 11 June, 2026
IT Security Guru
Eskenzi PR banner
  • Home
  • Features
  • Insight
  • Channel News
  • Events
    • Most Inspiring Women in Cyber 2026
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us
No Result
View All Result
  • Home
  • Features
  • Insight
  • Channel News
  • Events
    • Most Inspiring Women in Cyber 2026
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us
No Result
View All Result
IT Security Guru
No Result
View All Result

The More Confident Organizations Are in Their AI Security, the More Likely They’ve Been Breached, New Research Finds

by Guru Writer
June 11, 2026
in Featured
artificial-intelligence
Share on FacebookShare on Twitter

Nearly two-thirds of organizations have suffered a confirmed AI identity-related security incident in the past 12 months, and the companies that feel most secure are being hit the hardest, according to new research from FusionAuth.

The 2026 State of AI and Identity Report, which surveyed 312 technology and security leaders, including CTOs, CISOs, and VPs of engineering, security, and platform, found that 65% of organizations reported a confirmed AI identity breach in the past year, with a further 23% reporting a near miss. Just 12% came through the year unscathed.

But the report’s most striking finding is not the breach rate itself; it is who is being breached. Among respondents who rated themselves “extremely confident” in their AI security posture, 84% had already experienced a confirmed incident. That figure falls to 64% for those “very confident” and just 17% for those who described themselves as “not so confident”. In other words, confidence and breach rates rise together.

The organizations at the top of the confidence scale share a common profile: broad AI deployment, comprehensive governance policies, formalized lifecycle processes, and heavy investment. On paper, they are doing everything right and they are still being breached at the highest rates.

“Confidence appears to be tracking deployment velocity and governance activity, not actual protection,” said Brian Bell, CEO of FusionAuth. “The faster organizations move, the more confident they feel. The faster they move, the larger their attack surface. Written policies don’t answer the questions that matter: Can you scope what each agent can access? Can you see what it’s doing? Can you prove what it accessed after the fact? Can you revoke access before a near miss becomes something worse? Architecture answers those questions. Policy alone does not.”

The report suggests self-reported maturity has become an unreliable signal of actual security posture, with implications for how the industry benchmarks AI readiness. It also notes that organizations with mature security programs may simply be better at detecting incidents, meaning lower-confidence organizations are not necessarily safer, just blind to what is already happening.

Shadow AI is now the norm

The findings paint a picture of AI adoption racing ahead of the controls meant to govern it. Some 88% of respondents say AI deployment is outpacing their identity and security infrastructure, while 80% report shadow AI, employees connecting AI tools to internal systems without security or IT review. In the highest-risk cohort, organizations that combine production AI features, widespread employee AI use, and multi-tenant SaaS identity platforms see shadow AI reach 96%, and the confirmed incident rate hits 90%.

Architecture emerged as the variable that most clearly separates outcomes. Organizations running multi-tenant SaaS identity platforms reported confirmed incidents at more than twice the rate of self-hosted deployments – 83% versus 38%. In a shared environment, the report argues, a single compromised token or misconfigured policy can cascade across every AI workflow connected to the identity layer, creating a far larger blast radius than in an isolated deployment.

The weakest lifecycle controls were auditing what AI agents accessed (formalized at just 70% of organizations) and revoking access when no longer needed (73%), precisely the controls that matter once agents begin acting autonomously.

Identity becomes a commercial problem

AI identity risk is also showing up in the sales cycle. Eighty-five percent of respondents have faced customer, partner, or regulatory demands to demonstrate tenant isolation, with 56% facing such demands frequently, turning what was once a backend implementation detail into a requirement that determines whether enterprise deals close.

The result is a market-wide investment cycle. Ninety-three percent say AI is causing or contributing to a reevaluation of identity infrastructure, and 91% expect identity investment to increase in the next 12 to 18 months. The top evaluation criteria, machine identity at scale (72%), deployment flexibility (57%), and fine-grained authorization (54%), point to an architectural reset rather than a budget refresh. Total cost of ownership ranked last, cited by just 11%.

“This isn’t a normal budget refresh — market-wide, organizations are resetting their identity architecture,” Bell added. “They’re prioritizing deployment flexibility, tenant isolation, and architectural control as defining the next era of identity. That means organizations are demanding more than policies or governance — they want actual runtime enforcement over who and what can access their systems.”

ShareTweet
Previous Post

Check Point Expands MSP Platform with AI Security Capabilities and Unified Bundles

Recent News

artificial-intelligence

The More Confident Organizations Are in Their AI Security, the More Likely They’ve Been Breached, New Research Finds

June 11, 2026
Check Point Expands MSP Platform with AI Security Capabilities and Unified Bundles

Check Point Expands MSP Platform with AI Security Capabilities and Unified Bundles

June 11, 2026
Why KYC and transaction monitoring training matters for security and risk teams

Why KYC and transaction monitoring training matters for security and risk teams

June 11, 2026
ai-image-writing

Check Point joins OpenAI’s Trusted Access for Cyber programme as AI arms race intensifies

June 11, 2026

The IT Security Guru offers a daily news digest of all the best breaking IT security news stories first thing in the morning! Rather than you having to trawl through all the news feeds to find out what’s cooking, you can quickly get everything you need from this site!

Our Address: 10 London Mews, London, W2 1HY

Follow Us

© 2015 - 2024 IT Security Guru - Website Managed by Dessol

  • About Us
Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}
No Result
View All Result
  • Home
  • Features
  • Insight
  • Channel News
  • Events
    • Most Inspiring Women in Cyber 2026
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us

© 2015 - 2024 IT Security Guru - Website Managed by Dessol