Foreword
I have spent twenty-eight years in technology and cybersecurity. I have been through every major technological shift of the last two decades. Cloud, mobile, SaaS, containers, zero trust. Each one brought a new threat model, a new set of mistakes, and a period where adoption outpaced the controls needed to secure it. That pattern is familiar. What is happening with AI is not.
The pace of change is unprecedented. Every prior shift gave defenders months or years to observe, build frameworks, and catch up. AI has compressed that window into weeks. Twelve months ago, the question security leaders were asking was whether to allow AI tools. Now the question is how to find the ones already running, govern the agents their teams shipped without review, and explain to the board what could go wrong. The conversation moved from theoretical to operational faster than anything I have seen in my career.
The data in this report reflects that. 90% of enterprise AI usage is invisible to the security team responsible for it. 83% of organizations deployed AI agents this year, up from 16% twelve months ago. Only 29% say they have controls in place to secure what they shipped. That fifty-four-point gap between deployment and defense is the story this report exists to explain.
We built this report the same way we approach any security problem: start with the evidence. We tracked 302 publicly disclosed AI security incidents over the last twelve months, cross-referencing our own incident tracker with the AI Incident Database and the AIAAIC repository. Every attack walkthrough in this report is grounded in a CVE, a vendor disclosure, or published research.
AI is not optional. It is already in your infrastructure, your workflows, and your employees' browsers. The question is not whether to adopt it. The question is how to enable AI innovation with confidence. The organizations that get AI security right will not be the ones that moved slowest. They will be the ones that built visibility, governance, and response into their AI programs from the start, so they could move fast without losing control. That is the mission behind FireTail and the reason this report exists. AI adoption is accelerating whether security teams are ready or not. The work is to make sure they are.
Jeremy Snyder · Co-Founder and CEO, FireTail