Summary: AI has multiplied the rate of vulnerability discovery tenfold while giving attackers the same capability. Patching alone can no longer close the gap. Enterprises need a purpose-built control plane covering Discovery, Visibility, and Governance.
Monday morning. Your inbox has 47 new vulnerability tickets. Last week it had four.
You didn’t change the scanner. AI did.
In May 2026, Anthropic’s Project Glasswing ran one AI model against critical enterprise software for thirty days. It surfaced more than 10,000 high or critical severity vulnerabilities. One partner organization found 2,000 bugs in its own systems in a single month, with a false positive rate its security team rated better than human testers. Discovery rates increased tenfold across the board.
That is not a research result. That is your queue, multiplied by ten, delivered overnight, with no extra headcount to clear it.
The bottleneck is no longer finding vulnerabilities. It’s patching them. The average time to remediate a high-severity vulnerability is two weeks. For complex software ecosystems, much longer. Open-source maintainers are already asking Anthropic to slow down disclosures because they cannot absorb the volume.
Defenders are not the only ones running this capability. Attackers have the same models. Using AI, they can chain attack paths like never before. What once took weeks of skilled manual effort now takes minutes. The economics of exploit development have changed permanently.
The result: your risk posture just shifted up and to the right. What was once a vulnerability with medium or low likelihood is now high or very high. Your patch window has always been a race. AI just made that race faster, the field larger, and the finish line farther away.
And you will never patch fast enough. Not because your teams aren’t capable, but because the surface is now infinite and the adversary is running at machine speed. The vulnerabilities you know about are only part of the problem. The expanding surface of what you don’t know exists yet is the other part. And what once sat comfortably within your risk appetite no longer does.
This is why the question can no longer be “have we patched everything?” It has to become “can we control what can be reached, and by whom, right now, before the patch lands?” Real-time access control is not a workaround for slow patching. In a world of infinite exploitable vulnerabilities, it is a non-negotiable layer of defense-in-depth: the mitigation that works even when patching lags. And it always will.
Which raises a bigger question. Because the same AI that floods your patch queue from the outside is now operating inside your perimeter. And the controls you built to keep intruders out were never designed to govern what AI does once it’s in.
An AI agent that passes your access controls does not stop there, and the architecture you built to govern people was never designed to govern what AI does next.
The security industry has spent the better part of a decade building access controls. Zero trust. Zero trust network access (ZTNA). Security service edge (SSE). Secure access services edge (SASE). Least-privilege architecture. These investments were necessary, and they were right. The perimeter was dead. We built accordingly.
But something fundamental changed, and most security strategies have not caught up.
The controls your organization built to govern who gets in are not sufficient to govern what AI does once it’s inside. An AI agent that clears an access checkpoint does not stop there. It makes API calls continuously. It chains to other agents. It queries databases, processes documents, reads email threads, touches code repositories. Each interaction is a potential injection point. Each data access a potential exposure.
The blast radius from a misconfigured or compromised agent does not live at the access boundary. It lives inside the session, at the data layer, in the transactions that perimeter controls were never designed to see.
And there is a second dimension that makes this acute: authority drift. Permissions provisioned for one use case expand through inheritance, integration, and convenience across months of deployment. No single approval process sanctioned the aggregate. The authorization boundaries are dissolving in production, right now, without an alert firing.
When an employee misconfigures or an attacker leverages an agent with that kind of footprint, lateral movement does not just increase. It moves at machine speed, across everything that agent was authorized to touch. The September 2025 state-sponsored attack that hijacked enterprise AI agent instances across thirty targets in defense, energy, and technology, handling 80 to 90% of tactical operations autonomously, was not a forecast (Anthropic: “Disrupting the first reported AI-orchestrated cyber espionage campaign”). It was a proof of concept. The lateral movement that once took a skilled attacker days happened in minutes.
Securing access is necessary. It is not sufficient. Exploitation is easier and faster now, which means the case for zero trust is stronger than it has ever been.
So the work splits into three questions every security leader now has to answer. What exists in your environment? What happens inside it? And what can you prove when something breaks? Discovery. Visibility. Governance.
98% of organizations have employees using unsanctioned AI tools that security teams never approved, evaluated, or can see, and most cannot draw a map of what those tools connect to.
Ninety-eight percent of organizations report unsanctioned AI use. Not most. Not many. Virtually every enterprise on earth has employees using AI tools that security teams did not approve, did not evaluate, and cannot see.
The inventory problem is severe. Only 12% of companies can detect all shadow AI usage in their environment (Netskope/Cybersecurity Insiders: 2026 AI Risk and Readiness Report). Forty-seven percent of enterprise genAI users access tools through personal accounts, completely outside organizational controls, a figure drawn from Netskope’s own telemetry across millions of users worldwide (Netskope Cloud and Threat Report 2026). The number of enterprise genAI users tripled in a single year (Netskope Cloud and Threat Report 2026). The volume of prompts sent to AI services rose 500% (Netskope Cloud and Threat Report 2026). And 43% of large firms still lack an AI risk framework of any kind (Gallagher’s AI Adoption and Risk Benchmarking 2026 report).
The agent layer is arriving faster than the visibility controls designed to see it. Gartner projects that by the end of 2026, 40% of enterprise applications will incorporate task-specific AI agents, up from under 5% in 2025. More than 60% of organizations plan to deploy AI agents within the next two years, according to the 2026 Gartner CIO and Technology Executive Survey, with AI agents showing the most aggressive adoption curve among all emerging technologies measured.
Can you name every AI tool, model, and agent operating in your environment, including the ones IT didn’t approve?
Only 43% of organizations have any AI governance policy at all (PEX Network 2025/26). Engineering is the highest-adoption function: 84% of developers now use AI tools in their workflows (Stack Overflow Developer Survey, 2025), and Netskope’s own telemetry shows that nearly half of enterprise genAI users access these tools through personal accounts, outside organizational controls entirely (Netskope Cloud and Threat Report 2026). Verizon’s 2025 DBIR confirms the same pattern industry-wide: 15% of employees routinely access genAI on corporate devices, and 72% of those do so through personal accounts (Verizon DBIR 2025). The attack surface expanding through shadow AI is not theoretical exposure: It is the active attack surface.
Do you know which identities, human and machine, are connected to those AI systems, and what permissions they hold?
Eighty percent of IT workers report having already seen AI agents perform tasks they were not explicitly authorized to perform (セイルポイント: AI agents: The new attack surface). This is authority drift, and it is not an edge case. An organization that cannot inventory its agent identities cannot govern them.
Do you know which data stores, workflows, and downstream systems your AI agents can reach, are permitted to reach, and whether those permissions are clearly defined?
An agent’s blast radius is not defined by what it was designed to do. It is defined by everything it has been given access to. Modern AI governance failures emerge through integrations and connectivity, not direct system compromise. An organization that cannot map its agent access topology, the tools, services, data sources, and accounts each agent touches, cannot begin to defend it.
Topology is the precondition. You cannot govern what you cannot see, and right now most organizations cannot even draw the map. Getting that map right is the foundational step: which agents connect to which systems, what those systems expose, and where the chains of reachability extend beyond what any single team reviewed or approved.
Discovery is not the end state. It is the precondition for everything that follows.
The average organization recorded 223 genAI-linked data policy violations last month. Organizations without visibility controls aren’t recording zero; they’re recording zero detections.
The average organization recorded 223 GenAI-linked data policy violations last month. Among the top quartile, organizations with the highest AI adoption, that number was 2,100 incidents per month. Source code accounted for 42% of those violations. Regulated data (customer records, financial information, healthcare data) accounted for 32%. Intellectual property, 16% (Netskope Cloud and Threat Report 2026).
These are not potential incidents. They are actual violations, detected by organizations that had the controls in place to detect them. The organizations without those controls are not recording zero violations. They are recording zero detections.
Can you see what data is moving through your AI systems in real time, and whether any of it is sensitive?
An employee pastes notes from a patient interaction into an AI assistant to produce a visit summary. The model summarizes it efficiently. The patient’s PII, the patient’s PHI, and post-visit medication instructions all left the company perimeter, exposing it to potential HIPAA fines. No alert fired. No policy tripped. The interaction was productive and completely invisible. Netskope’s research shows that 54% of data policy violations tied to GenAI tools involve regulated data, exactly the category that triggers regulatory notification when it is lost (Netskope Cloud and Threat Report 2026). The average organization now sends 18,000 prompts per month to GenAI tools (Netskope Cloud and Threat Report 2026). If you cannot inspect those prompts in real time, you are not governing AI data exposure. You are hoping it isn’t happening.
When an AI agent takes an action, can you trace who authorized it, when, and whether that authorization is still valid?
In June 2025, researchers discovered a zero-click prompt injection in Microsoft 365 Copilot, CVE-2025-32711, CVSS severity 9.3 (EchoLeak: The First Real-World Zero-Click Prompt Injection Exploit in a Production LLM System). No user interaction required. One crafted email. When Copilot ingested it during routine summarization, it extracted data from OneDrive, SharePoint, and Teams, then exfiltrated it through a trusted Microsoft domain. Antivirus, firewalls, and static scanning were entirely ineffective. The exploit operated in natural language, not code.
This is authority drift at the moment of consequence. The agent had legitimate credentials. The actions looked like normal agent behavior. There was no anomaly visible to tools watching for known-bad signatures, because the malicious instructions arrived in the same channel as normal content.
Can you enforce a consistent policy across every AI interaction: every tool, every action, every user, every data type?
Eighty-two percent of executives report confidence that their existing policies protect against unauthorized agent actions (Gravitee). Only 14.4% of organizations send agents to production with full security or IT approval (Gravitee). Policy documentation and runtime enforcement are not the same thing.
Enforcement has to happen at the point of the transaction: at the moment of the API call, the MCP request, the data retrieval, with full context, in real time. AI agent transactions are fast, distributed, data-intensive, and non-deterministic. They do not pause for a central inspection point. If enforcing policy requires routing traffic through a centralized architecture, one of two things happens. The workflow breaks, or the security gets bypassed. Either way, governance fails.
A control plane without enforcement infrastructure is a dashboard. Dashboards do not stop data from leaving.
88% of organizations running AI agents reported a security incident in the past twelve months. The ones that survived it cheapest had the audit trail. The ones that didn’t had the explanation bill.
Eighty-eight percent of organizations running AI agents reported a confirmed or suspected security incident in the past twelve months (Gravitee). In healthcare, that number is 92.7% (Gravitee). These are not theoretical risks. They are production incidents, happening now, in organizations that believed their controls were adequate.
The mean time to identify a data breach is 181 days. The time to contain it, 60 days. The total breach lifecycle is 241 days, nearly eight months from initial intrusion to full eviction. At $4.44 million average cost globally and $10.22 million in the United States, every day of undetected compromise has a precise financial weight. Shadow AI breaches are costlier still, averaging $4.63 million, because unconstrained AI extends the surface and the visibility gap extends the dwell time (IBM/Ponemon Institute 2025).
Given this, how does a CISO become an architect of tomorrow, improving the return-on-risk equation? Through the strength of the AI security program and practices behind them.
If an AI model or agent were compromised or behaving anomalously today, how long before you’d know?
Agent compromise does not announce itself. A manipulated agent sends the same requests, with the same credentials, through the same channels it always used. Detection requires behavioral baselines built specifically for AI systems: not just whether an agent authenticated correctly, but whether what it is doing matches what it should be doing. Currently, only 6% of security budgets are allocated to AI agent security (Arkose Labs’ 2026 Agentic AI Security Report). That gap is producing the incident statistics above.
When something goes wrong, can you contain the blast radius before it becomes a reportable event?
Organizations with extensive AI and automation in their security operations identified and contained breaches in 204 days versus 284 days for those without, an 80-day difference that translates directly to reduced exposure and cost. The 200-day threshold matters: breaches contained within it average $3.87 million; those that exceed it average $5.01 million (IBM/Ponemon Institute 2025).
For AI agent incidents, containment is structural. An over-privileged agent touches everything it was authorized to touch before anyone intervenes. Least-privilege scoping at the agent level, automated containment triggers, and pre-defined blast radius controls are the architecture that determines whether an incident stays in one system or becomes an enterprise-wide breach. Under GDPR and emerging AI regulation, your organization is liable for data exposed by your agents regardless of whether a human explicitly authorized the release.
Do you have a complete, auditable record of AI-driven decisions that would hold up to a regulator or a board?
For regulated data breaches involving AI agents, the exposure is structural and stacked. Under the EU AI Act, prohibited AI practices can trigger fines of up to €35 million or 7% of global turnover, with high-risk system violations reaching €15 million or 3% of turnover. GDPR fines for the same incident can add up to 4% of global revenue. State-level AI laws — Illinois HB3773, Texas TRAIGA, Colorado SB 24-205 — apply per-violation, per-affected-individual penalties that compound rapidly. A single undocumented incident produces compounded exposure: the breach cost itself, multiple regulatory fines, and the reputational damage of being unable to explain what your AI systems did or why.
The organizations that can produce a complete audit trail (what every AI system did, under whose authorization, with which data, at what time) spend those regulatory conversations on strategy. The ones that cannot spend them on explanation, after months of discovery and legal cost.
No SIEM, no endpoint solution, no data security posture management tool answers all nine questions. They were built for human users, human patterns, and human timescales. What enterprises need, and what most have not yet built, is a purpose-built control plane: Discovery, Visibility, and Governance as a unified capability, not three products bolted together.
The security leaders who will define the next decade are not the ones who block AI most effectively, they are the ones who make it trustworthy enough to deploy at scale.
There is a conversation happening inside every enterprise right now. The business wants to move faster. Security wants to understand the risk first. The business calls security the bottleneck. Security calls the business reckless. Both are right. Both are arguing from inside the wrong frame.
The security leaders who will define the next decade are not the ones who block AI most effectively. They are the ones who build the governance layer that makes AI trustworthy enough to deploy at scale. Security organizations that have integrated AI deeply into their detection and response workflows already see the operational dividend; they save $1.9 million per breach and contain incidents 80 days faster than those that haven’t (Verizon DBIR 2025). That is the easier half of the argument. The harder half is structural.
Governance is not the cost of enabling AI. It is the mechanism by which AI becomes a competitive advantage rather than a liability. The organizations doing this well are the ones who can deploy new AI capability in hours rather than months. Not because they skipped the security review, but because they built the governance layer that made the review answerable. They know what AI is running in their environment. They know what data is moving through it. They can prove what their agents did and under whose authorization. When the business comes to them with the next AI initiative, the answer is not let me check, it is yes, and here’s how we’ll do it safely.
The organizations that don’t build this will spend the next decade trapped between business pressure to move faster and security pressure to know what’s happening. The way out is not less governance. It is governance that operates at the speed of the business: discovery, visibility, and enforcement under a single control plane, applied at the moment of every transaction, with a complete audit trail of every decision.
When discovery, visibility, and governance are answered (when every model is found, every data transaction governed, every agent action auditable) deploying new AI capability moves from a months-long security review to a risk-informed decision made in hours. The security function stops rationing AI and starts enabling it.
That is a different job than the industry has been doing. It is a considerably more important one.
The perimeter protected the building. Zero trust protected the network. AI governance protects what’s happening inside it. And most organizations haven’t built it yet.
The last decade of enterprise security produced something genuinely valuable: an architecture that governs how people interact with digital systems. That foundation is not wasted. But it is the floor not the ceiling.
Netskope was born in 2012, built for the cloud era from the first line of code, not retrofitted onto a network that assumed everything important lived inside a building. That heritage matters now, because AI is already acting inside enterprise environments. It is already finding your vulnerabilities faster than you can patch them, moving data through channels you cannot inspect, and accumulating authority that no single approval process sanctioned. The statistics in this piece are not projections. They are current-state measurements from enterprise telemetry, breach reports, and live incident data.
Monday morning. Your queue is ten times longer. Your window is narrowing. And the organizations that answer all nine questions are already building the governance layer that turns that pressure into advantage.
Discovery. Visibility. Governance. The organizations that can answer all nine questions are being built by the Architects of Yes.
Netskope’s AI Command Center, running over the NewEdge, the world’s most performant private cloud infrastructure, gives security leaders the unified visibility, runtime enforcement, and audit capability to answer every question in this piece. It discovers every agent identity operating in your environment, maps the access each one holds, enforces scoped permissions, and monitors every action in real time, flagging the behavioral anomaly that signature-based detection cannot see. The agent still runs. The legitimate work still gets done. The exfiltration attempt does not.
Netskope is the only unified fabric that controls data across every way human and non-human identities communicate, and the only platform already doing this at scale. No bolt-ons. No service chaining.
Request a briefing with your Netskope team to run the nine questions against your environment and map your path to governed AI adoption.
netskope.com/ai-security | Contact your Netskope representative
All figures current as of Q2 2026.
Statistics sourced from Netskope Threat Labs telemetry, IBM Cost of a Data Breach Report 2025, Gartner AI Forecast 2025 to 2026, Project Glasswing field report (Anthropic, May 2026), and publicly disclosed CVE records. All figures current as of Q2 2026.
