What 200 CISOs and CTOs Reveal
At A Glance
- 69% of security leaders say machine workloads are their least confident security area today, compared to just 7% for human users.
- 76% point to complex non-human identity and authentication as a major driver of AI’s expanding attack surface.
- Only 8% of organizations describe their current identity systems as very sufficient for securing non-human workloads.
- New AI-specific infrastructure is introducing risk that’s already been exploited in the wild.
If you’re the one fielding the firewall change request for the latest AI agent rollout, you already know the frustration these numbers put a figure on. A new survey of 200 CISOs and CTOs confirms it isn’t just your organization: machine workloads have become the biggest confidence gap in AI security, and the identity problem underneath it is the reason every connectivity change takes longer than it should.
Why Are Machine Workloads Harder to Secure Than Human Users?
For the past decade, security investment has gone almost entirely toward securing human access to applications. VPNs, ZTNA, and SASE were all built around a single assumption: that every connection has a person behind it with a verifiable identity. That investment shows. When asked which type of connectivity they’re least confident securing today, 69% of respondents pointed to machine workloads (service-to-service or API connectivity across distributed environments), compared to just 7% for human users and 24% for both equally.
The reason is structural, not a maturity gap that will close on its own. VPNs and SASE authenticate a person, then grant access. Machines don’t have identities in the same way, which means the tools that secured the last decade of remote work simply don’t translate to machine-to-machine connectivity. Automated traffic is also growing roughly eight times faster than human traffic year over year, so this gap is widening, not narrowing.
What’s Driving AI’s Expanding Attack Surface?
Every respondent (100%) agrees their external attack surface is growing, with an average projected increase of 14% over the next 12 months alone, and that’s before accounting for anything beyond what’s already underway or planned.
Two factors stand out as the biggest contributors:
- Increased requirement for internet-facing APIs and workloads: a direct consequence of AI’s distributed, cross-environment architecture. Agents, models, and data constantly cross enclaves, cloud, edge, SaaS, and partner environments, and every crossing is a new connection.
- Complex non-human identity and authentication (76%): the deeper issue. IP addresses can’t reliably serve as identity (NAT, DHCP, and ephemeral IPs make consistent tracking nearly impossible), which leaves most organizations defaulting to static secrets and service accounts. Those credentials tend to carry excessive permissions, persist indefinitely, and go unrotated, creating exactly the kind of blind spot attackers look for.
Together, these two factors point to the same root cause: AI’s architecture is inherently more distributed than what came before it, and the identity systems meant to secure those connections haven’t caught up.
Why Are MCP Servers a Growing Security Risk?
New AI-specific services, like MCP servers and LLM gateways, are a meaningful and growing contributor to this attack surface, and this isn’t theoretical. In July 2025, JFrog’s security research team disclosed CVE-2025-6514, a critical (CVSS 9.6) OS command injection vulnerability in mcp-remote, a widely used proxy that lets MCP clients connect to remote MCP servers. A malicious server could craft a response that triggered arbitrary command execution on the connecting client, resulting in full system compromise. It was patched in version 0.1.16, but it’s a clear, concrete example of exactly the risk this survey’s respondents are describing in the abstract: new AI-specific infrastructure, deployed quickly, without the identity and access controls to contain what happens when something goes wrong.
These identity workarounds don’t just create blind spots for attackers, they also show up as approval friction. Network and firewall changes for AI deployments now average over a week from request to implementation, which means the same identity gap that expands the attack surface is also what’s slowing deployment down.
How to Close the Non-Human Identity Gap
Only 8% of organizations describe their current identity systems as very sufficient for securing or monitoring non-human workloads, and that gap isn’t going unnoticed. Across the organizations we surveyed, there’s a clear shift underway toward rethinking how non-human identity gets handled, less as a monitoring problem and more as an architecture problem to solve at the root.
This is the gap NetFoundry’s Identity-First Reachability™ is built to close: giving every AI agent, MCP server, API, and workload its own verifiable, governable identity, with no open inbound ports, no VPNs, and no firewall changes required. Instead of granting broad, long-lived access through shared secrets, every machine-to-machine connection gets the same level of identity assurance we’ve spent a decade building for human users, without adding another change request to the queue.
If you’re evaluating your own approach to non-human identity, the full survey breaks these findings down by industry, company size, and role, including where CTOs and CISOs disagree on where the real risk sits.
Download the Full 2026 State of Secure AI Connectivity Report
Frequently Asked Questions
Why are machine workloads harder to secure than human users?
Security tools built over the last decade, like VPNs and SASE, were designed around authenticating a human, then granting access. Machine workloads don’t have identities in that same sense, and IP-based tracking is unreliable due to NAT, DHCP, and ephemeral addressing. Our research found 69% of security leaders cite machine workloads as their least confident area of security, compared to just 7% for human users.
What is non-human identity in Zero Trust security?
Non-human identity refers to a distinct, verifiable identity assigned to an AI agent, API, service, or other machine workload, rather than that workload inheriting a shared credential or the identity of the human who deployed it. At NetFoundry, we treat non-human identity as foundational to Zero Trust, since without it, organizations can’t reliably govern, monitor, or audit what an autonomous system is doing.
What is an MCP server?
An MCP server is infrastructure that supports the Model Context Protocol, allowing AI agents and LLM clients to connect to external data sources, tools, and services. We’ve seen these emerge as a fast-growing category of AI infrastructure and, per this survey, a meaningful contributor (54%) to organizations’ expanding attack surface.
How can organizations reduce network change delays for AI deployments?
Delays typically stem from risk and compliance approvals and cross-team dependencies across networking, security, and application teams. We approach this by removing the need for firewall changes and open inbound ports altogether, giving every AI agent and workload its own identity-based access rather than routing every connectivity change through a traditional network change management cycle.
