Orca Security has released its 2026 State of AI Security Report, offering a first-hand view into how AI is being deployed across more than 1,200 production cloud environments. The findings show that AI is no longer limited to isolated pilots or developer experiments. Organizations are embedding AI into production applications, cloud services, and autonomous workflows faster than security programmes can adapt.
More than half (56%) of organizations have already deployed AI agents into production, while 51% use AI to build custom applications. At the same time, Orca found that 81% of organizations run vulnerable AI packages, and 99.9% of fixable AI vulnerabilities remain unpatched, highlighting how quickly AI has become operational infrastructure without corresponding security maturity.
The report also reveals that AI environments are rapidly becoming more interconnected and business-critical. Among organizations adopting AI, 64% now run vector databases, 55% operate four or more AI services simultaneously, and between 87% and 98% of AI workloads across the three major cloud providers lack customer-managed encryption. Together, these findings show that organizations are no longer securing standalone AI tools. They are securing complex AI ecosystems connected to enterprise data, cloud services, identities, and production workflows.
“What surprised us wasn’t simply how fast AI adoption has grown. It was how deeply AI is now woven into production cloud environments,” said Gil Geron, CEO and Co-Founder of Orca Security. “We aren’t just seeing isolated models. We’re seeing AI agents connected to enterprise data, interacting with identities, calling cloud services, and becoming part of business-critical workflows. AI is no longer an experiment. It’s production infrastructure.”
Progress is measurable when organizations treat AI like production infrastructure
The research highlights that meaningful progress happens where organizations have focused security investments. Since Orca’s previous AI report, the percentage of Amazon SageMaker environments running with root access has declined from 98% to 76%, while insecure IMDSv2 configurations dropped from 77% to 48%. These improvements demonstrate that applying production-grade operational discipline to AI environments produces measurable security gains.
The report recommends that organizations treat AI as production infrastructure by extending existing security practices across the AI lifecycle, including vulnerability management, credential protection, least-privilege access, encryption, AI-specific monitoring, and governance.
“The organizations making the most progress are treating AI like every other critical production system,” added Geron. “That means applying consistent visibility, governance, least-privilege access, and remediation across the entire AI lifecycle. Security can’t be something you add after deployment. It has to be built into how teams develop and scale AI.”
About the report
The 2026 State of AI Security Report analyses aggregated, anonymised telemetry from more than 1,200 production organizations collected during Q2 2026. The research examines AI cloud services, AI package vulnerabilities, identities and secrets, AI agents, vector databases, encryption, and governance across AWS, Microsoft Azure, and Google Cloud.






