NetFoundry Survey Finds AI Security Visibility Gaps
Non-human identity and shadow AI concerns surfaced here are directly relevant to APS agencies deploying AI services across cloud and API boundaries.
Key points
- A vendor-commissioned US survey of 200 enterprise leaders reports AI deployments are projected to expand attack surfaces by 14% on average.
- Only 8% rated identity systems sufficient for non-human workloads - machine authentication is the central reported gap.
- Vendor-commissioned methodology and US-only sample limit generalisability; useful as a checklist, not a universal benchmark.
Implications for Australian agencies
- Consider APS agencies deploying AI services could assess whether their identity and access management frameworks adequately cover non-human workloads such as service accounts, API credentials, and agent-to-agent calls.
- Monitor Security and platform teams may want to monitor emerging guidance on non-human identity controls as AI agent deployments become more common across government environments.
Implications are AI-generated. Starting points, not advice — see methodology for how they're framed.
View original source
Copied.
Appeared in:
Weekly digest, 10 August 2026
"NetFoundry Survey Finds AI Security Visibility Gaps"
Source: Let's Data Science – AI Governance
Published: 12 August 2026
URL: https://letsdatascience.com/news/netfoundry-survey-finds-ai-security-visibility-gaps-6beea0eb
NetFoundry's 2026 State of Secure AI Access survey, conducted among 200 US enterprise security and technology leaders, reports that AI deployments are expected to grow external attack surfaces by an average of 14% over the next year. Key findings include that 90% of respondents are concerned about unapproved AI tools, only 8% consider their identity systems sufficient for non-human workloads, and routine firewall changes take a week or longer for 54% of organisations. The survey highlights that conventional human-centric access controls are not well suited to governing agent-to-agent calls, API credentials, and service accounts in production AI architectures. As a vendor-commissioned study with a US-only sample, findings should be treated as indicative rather than definitive.
Implications for Australian agencies:
- [Consider] APS agencies deploying AI services could assess whether their identity and access management frameworks adequately cover non-human workloads such as service accounts, API credentials, and agent-to-agent calls.
- [Monitor] Security and platform teams may want to monitor emerging guidance on non-human identity controls as AI agent deployments become more common across government environments.
Retrieved from SIMS, 16 September 2026.