Expanding the battlefield: Corporate AI as the new cyberattack vector
The cybersecurity platform Zscaler warns in Mythos 2026 that the rapid adoption of generative artificial intelligence (AI) tools is creating a new attack surface for companies, which are incorporating these technologies much faster than their capacity for protection.
This is one of the highlighted conclusions of the study, which analyzes 38 large organizations in sectors such as banking, healthcare, industry, energy, or technology. The report indicates that 100% of the examined companies keep their corporate AI tools exposed to potential external attacks, while the average security score specific to AI barely reaches 10.5 points out of 100. Not even the best-prepared organization is above 15 points, a fact that highlights the low maturity of AI governance strategies in the business field.
Access doors, increasingly open
The research also indicates that many organizations are developing AI tools without incorporating basic security controls. Corporate chatbots, Model Context Protocol (MCP) interfaces, or inference APIs remain accessible from the internet without the installation of authentication or identity verification mechanisms, making it easier for cybercriminals to identify them and use them as entry points to corporate systems.
The speed at which organizations are adopting generative AI causes these risky situations. In many cases, new applications are deployed by business departments or development teams outside the usual review processes by cybersecurity officials. This unintentionally expands the attack surface.
Zscaler's study shows that artificial intelligence has ceased to be solely a productivity tool to become a new critical asset that must be managed with the same security principles as any other corporate infrastructure.
More conclusions: the lack of specific controls over AI is not only due to a technological deficiency but also to the absence of governance processes adapted to this new reality. The rapid proliferation of copilots, virtual assistants, and applications based on language models is widening the exposure surface of companies much faster than their protection strategies evolve.
Zscaler concludes that organizations must address AI security from a comprehensive perspective that includes visibility over all deployed AI assets, access authentication, identity control, traffic inspection, and specific governance policies with the capacity to keep pace with the adoption rate of this technology.
Related Stories
AI News
The Results of Middle and High School Students Using AI Are Extremely Ominous
48 minutes ago
AI News
‘We are hitting a different chapter’: OpenAI leader warns of threat of ‘persistent’ AI cyber
49 minutes ago
AI News
Jeffrey Wenger Named RAND's Distinguished Chair, AI, Workers, and the Economy
1 hour ago
AI News
Opinion | Asia is reaching for the open road that Chinese AI offers
1 hour ago
The Generalitat activates artificial intelligence to track the 87,906 empty apartments that official records ignore in Tarragona
5 hours ago
AI News
iAsk AI Launches New Education
5 hours ago
AI News
The Enterprise Journey, Reimagined with AI Agents
8 hours ago
AI News
This Is Probably Not the AI
8 hours ago