Tenable Research Reveals Growing AI Exposure Gap

Report finds 86% of organisations have installed third-party code packages with critical-severity vulnerabilities; 65% expose high-value assets through forgotten cloud credentials

Published on Feb. 23, 2026

Tenable, the exposure management company, has released its Cloud and AI Security Risk Report, which reveals that organisations face a growing AI exposure gap as they inherit cyber risks faster than they can address them. The report identifies severe risks across AI security posture, supply chain attack vectors, least privilege implementation, and cloud workload exposure.

Why it matters

The AI Exposure Gap is a largely invisible form of exposure that emerges across applications, infrastructure, identities, agents and data, and that most security teams are not equipped to manage. This report highlights the critical risks that AI systems embedded in infrastructure pose, which CISOs and defenders must address in addition to emerging threats from both AI and cloud technologies.

The details

Key findings from the report include: 70% have integrated at least one AI or Model Context Protocol (MCP) third-party package, often without central security oversight; 86% host third-party code packages with critical-severity vulnerabilities; 18% have granted AI services administrative permissions that are rarely audited; non-human identities such as AI agents and service accounts now represent higher risk (52%) than human users (37%); and 65% possess "ghost" secrets, unused or unrotated cloud credentials, with 17% tied to critical administrative privileges.

  • The report presents findings from Tenable Research team's analysis of anonymised telemetry from April to October 2025, with AI findings extended through December 2025.

The players

Tenable

An American cybersecurity company that provides exposure management solutions.

Liat Hayun

Senior Vice President of Product Management and Research at Tenable.

Got photos? Submit your photos here. ›

What they’re saying

“AI systems embedded in infrastructure pose a critical risk that CISOs and defenders must address, in addition to anticipating emerging threats from both AI and cloud technologies. Lack of visibility and governance means teams are at the mercy of new exposures, including over-privileged identities in the cloud.”

— Liat Hayun, Senior Vice President of Product Management and Research (Tenable)

What’s next

To manage emerging risks, organisations must secure the AI integration process through comprehensive visibility and identity-centric controls, including enforcing least privilege for AI roles, neutralising "ghost" identity risk, and eliminating static secret exposure.

The takeaway

This report highlights the critical need for organisations to address the growing AI exposure gap, which has outpaced the human-led ability to assess, prioritise and remediate risks before threat actors can exploit them. By focusing on the unified exposure path, organisations can stop managing 'security debt' and start managing actual business risk.