Expanding the battlefield: Corporate AI as the new cyberattack vector
The cybersecurity platform Zscaler warns in Mythos 2026 that the rapid adoption of generative artificial intelligence (AI) tools is creating a new attack surface for companies, which are incorporating these technologies much faster than their capacity for protection.
This is one of the highlighted conclusions of the study, which analyzes 38 large organizations in sectors such as banking, healthcare, industry, energy, or technology. The report indicates that 100% of the examined companies keep their corporate AI tools exposed to potential external attacks, while the average security score specific to AI barely reaches 10.5 points out of 100. Not even the best-prepared organization is above 15 points, a fact that highlights the low maturity of AI governance strategies in the business field.
Access doors, increasingly open
The research also indicates that many organizations are developing AI tools without incorporating basic security controls. Corporate chatbots, Model Context Protocol (MCP) interfaces, or inference APIs remain accessible from the internet without the installation of authentication or identity verification mechanisms, making it easier for cybercriminals to identify them and use them as entry points to corporate systems.
The speed at which organizations are adopting generative AI causes these risky situations. In many cases, new applications are deployed by business departments or development teams outside the usual review processes by cybersecurity officials. This unintentionally expands the attack surface.
Zscaler's study shows that artificial intelligence has ceased to be solely a productivity tool to become a new critical asset that must be managed with the same security principles as any other corporate infrastructure.
More conclusions: the lack of specific controls over AI is not only due to a technological deficiency but also to the absence of governance processes adapted to this new reality. The rapid proliferation of copilots, virtual assistants, and applications based on language models is widening the exposure surface of companies much faster than their protection strategies evolve.
Zscaler concludes that organizations must address AI security from a comprehensive perspective that includes visibility over all deployed AI assets, access authentication, identity control, traffic inspection, and specific governance policies with the capacity to keep pace with the adoption rate of this technology.
Related Stories
AI News
OpenAI Projects $20 Billion Jump in Annualized Revenue Before Year End
1 minute ago
AI News
AI won’t empty the software factory: Why the new engineers act like foremen
1 minute ago
AI News
Trump declares anyone who calls artificial intelligence "artificial intelligence" to be enemy of White House
1 minute ago
AI News
ChatGPT for Teens an 'unacceptable risk to kids,' new report states
1 hour ago
AI News
OpenAI fires 3 safety researchers in dispute over AI risks
1 hour ago
AI News
Mathematicians React With Fury as OpenAI Releases Hundreds of New AI
1 hour ago
AI News
OpenAI reports three new incidents of misalignment
1 hour ago
AI News
“Consensus Truth” in the Age of AI
1 hour ago