AI Security Gaps Widen as 99.9% of Fixable Vulnerabilities Go Unpatched
Event summary
- 56% of organizations have deployed AI agents into production, with 81% running vulnerable AI packages.
- 99.9% of fixable AI vulnerabilities remain unpatched, up from 62% in 2024.
- 50% of AI package vulnerabilities now have publicly available exploits, a 250-fold increase over 2024.
- 64% of organizations using AI run vector databases, with 87-98% of AI workloads lacking customer-managed encryption.
The big picture
AI has transitioned from experimental to production infrastructure faster than security programs can adapt. The interconnected nature of AI ecosystems—spanning cloud services, vector databases, and enterprise data—expands the attack surface in ways traditional security measures were never designed to address. Organizations must now treat AI as critical production infrastructure to mitigate growing risks.
What we're watching
- Regulatory Compliance
- How the EU AI Act's high-risk obligations (August 2, 2026) and Colorado's amended AI law (January 1, 2027) will pressure organizations to address unpatched vulnerabilities.
- Security Maturity
- Whether organizations can adapt security programs fast enough to match the rapid deployment of AI into production environments.
- Operational Discipline
- The pace at which companies will extend existing security practices across the entire AI lifecycle, including vulnerability management and least-privilege access.
Related topics
