Zscaler warns that the rapid adoption of generative AI tools is creating a new attack surface for enterprises, incorporating these technologies much faster than they are able to protect them.
This is revealed by Mythos 2026, the new Zscaler study based on the analysis of 38 large organizations from sectors such as banking, healthcare, industry, energy or technology. The report concludes that 100% of the companies analyzed keep their corporate AI tools exposed to possible external attacks, while the average security score specific to AI barely reaches 10.5 points out of 100. Not even the best prepared organization exceeds 15 points, which reflects the low maturity of AI governance strategies in the business environment.
Lack of basic security controls
Research shows that many organizations are deploying AI tools without incorporating basic security controls. Corporate chatbots, Model Context Protocol (MCP) interfaces or inference APIs remain accessible from the Internet without authentication or identity verification mechanisms, making it easier for cybercriminals to identify them and use them as an entry point into corporate systems.
This situation responds, to a large extent, to the speed with which organizations are adopting generative AI. In many cases, new applications are deployed by business departments or development teams outside the usual review processes by those responsible for cybersecurity, significantly expanding the attack surface.
AI is now part of the business security perimeter
For Zscaler, artificial intelligence has ceased to be solely a productivity tool and has become a new critical asset that must be managed under the same security principles as any other corporate infrastructure.
«AI is entering organizations at an unprecedented speed, but security is not evolving at the same pace. Many companies continue to protect their traditional applications while leaving unattended a new generation of AI tools that already handle sensitive information and critical business processes. AI governance needs to become a priority from the get-go, not when a security breach has already occurred,” said Sam Curry, Chief Information Security Officer at Zscaler.
According to the study, the lack of specific controls over AI does not respond only to a technological lack, but also to the absence of governance processes adapted to this new reality. The rapid proliferation of copilots, virtual assistants, and language model-based applications is expanding companies’ exposure surfaces much faster than their protection strategies are evolving.
AI governance should be a priority from the get-go, not when a security breach has occurred
For Zscaler, organizations must approach AI security from a comprehensive perspective that includes visibility over all deployed AI assets, access authentication, identity control, traffic inspection and specific governance policies capable of keeping up with the pace of adoption of this technology.
