Foreword
I have spent twenty-eight years in technology and cybersecurity. I have been through every major technological shift of the last two decades. Cloud, mobile, SaaS, containers, zero trust. Each one brought a new threat model, a new set of mistakes, and a period where adoption outpaced the controls needed to secure it. That pattern is familiar. What is happening with AI is not.
The pace of change is unprecedented. Every prior shift gave defenders months or years to observe, build frameworks, and catch up. AI has compressed that window into weeks. Twelve months ago, the question security leaders were asking was whether to allow AI tools. Now the question is how to find the ones already running, govern the agents their teams deployed without review, and explain to the board what could go wrong. The conversation moved from theoretical to operational faster than anything I have seen in my career.
The data in this report reflects that. 90% of enterprise AI usage is invisible to the security team responsible for it, and only 29% of organizations say they have controls in place to secure it. That 61-point gap, between how much AI is running unseen and how much is under control, is the story this report exists to explain. In the same period, 83% of organizations deployed AI agents, up from 16% twelve months ago.
We built this report the same way we approach any security problem: start with the evidence. We tracked 302 publicly disclosed AI security incidents over the last twelve months, cross-referencing our own incident tracker with the AI Incident Database and the AIAAIC repository. Every attack walkthrough in this report is grounded in a CVE, a vendor disclosure, or published research.
AI is not optional. It is already in your infrastructure, your workflows, and your employees' browsers. The question is not whether to adopt it. The question is how to enable AI innovation with confidence. The organizations that get AI security right will not be the ones that moved slowest. They will be the ones that built visibility, governance, and response into their AI programs from the start, so they could move fast without losing control. That is the mission behind FireTail and the reason this report exists. AI adoption is accelerating whether security teams are ready or not. The work is to make sure they are.
Jeremy Snyder · Co-Founder and CEO, FireTail