Intelligent CISO Issue 101 | Page 28

O
AI VULNERABILITIES

Orca report highlights security gaps as AI moves into production

2026 State of AI Security Report finds that more than half of organisations have deployed AI agents into production, while most fixable AI vulnerabilities remain unpatched.
rca Security has released its

O

2026 State of AI Security Report, analysing more than 1,200 production cloud environments to examine how organisations are deploying Artificial Intelligence and the security challenges that accompany its adoption.
The report found that 56 % of organisations have deployed AI agents into production environments, while 51 % are using AI to develop custom applications. However, 81 % of organisations were found to be running vulnerable AI packages and 99.9 % of AI vulnerabilities with an available fix remained unpatched.
According to the report, AI is becoming increasingly integrated into production environments. Among organisations adopting AI, 64 % are using vector databases, 55 % operate four or more AI services simultaneously, and between 87 % and 98 % of AI workloads across the major cloud providers do not use customer-managed encryption.
What surprised us wasn’ t simply how fast AI adoption has grown. It was how deeply AI is now woven into production cloud environments.
“ What surprised us wasn’ t simply how fast AI adoption has grown. It was how deeply AI is now woven into production.
“ What surprised us wasn’ t simply how fast AI adoption has grown. It was how deeply AI is now woven into production cloud environments,” said Gil Geron, Chief Executive Officer and Co-Founder, Orca Security.“ We aren’ t just seeing isolated models. We’ re seeing AI agents connected to enterprise data, interacting with identities, calling cloud services, and becoming part of business-critical workflows. AI is no longer an experiment. It’ s production infrastructure. The number of builders has increased exponentially and organisations need security that provides complete visibility and the confidence to innovate at AI speed without introducing unnecessary risk.”
The report also found that 50 % of AI package vulnerabilities now have a publicly available exploit, representing a significant increase since Orca’ s 2024 report.
“ AI has introduced an entirely new operational layer into cloud environments,” said Nir Mashal, Chief Information Security Officer, Orca Security.“ Organisations now have agents making decisions, vector databases connected to enterprise data, and AI services spread across multiple cloud providers. Security teams need unified visibility across that entire environment, paired with automated prevention, to understand where risk actually exists and stop attackers before damage is done.”
Despite the findings, the report identifies improvements in some areas. Since Orca’ s previous AI report, the proportion of Amazon SageMaker environments running with root access has fallen from 98 % to 76 %, while insecure IMDSv2 configurations have declined from 77 % to 48 %.
Orca recommends organisations apply the same governance, vulnerability management, least-privilege access, encryption and monitoring practices used for other production systems throughout the AI lifecycle, particularly as new AI regulations come into force in Europe and the US.
28 WWW. INTELLIGENTCISO. COM