logo
Talk to an Expert
Share:

72% of IT Leaders Say AI Is Expanding Their Attack Surface — Is Anyone Actually Watching It?

July 11, 2026 Newsletter

image

72% of IT Leaders Say AI Is Expanding Their Attack Surface — Is Anyone Actually Watching It?

A new Cisco survey of 3,472 IT leaders reveals AI-driven network expansion is outpacing security visibility. Here's what mid-sized enterprises need to know.

Here's a number worth sitting with: 71% of IT leaders now expect AI-driven threats to outpace their existing security controls. Not eventually. Not in some distant future scenario — now, as a present-tense expectation from the people running enterprise networks today.
 
That figure comes from a new Cisco survey of 3,472 CIOs and technology leaders conducted in early 2026, and it paints a clear picture of an industry racing to modernize its networks for AI while quietly admitting its security posture isn't keeping pace. Seventy-two percent of respondents cited increased security risk or an expanded attack surface as a direct motivating factor behind their network modernization efforts. More than three-quarters said they expect AI-related security risk to keep growing as adoption expands beyond basic generative use cases. Nearly 70% reported a rising number of blind spots on their networks — places where they simply can't see what's happening.
 
One senior IT executive summed up the mood in a single line: "We're just playing catch-up at the moment."
 
If that sentence sounds familiar, it should — it's the same tension mid-sized organizations in finance, healthcare, and manufacturing have been navigating all year as AI adoption accelerates faster than security programs can absorb it. This article breaks down what the Cisco data actually shows, why visibility — not just controls — is the real gap, and what mid-sized enterprises can do to close it without slowing down the AI adoption their business needs.
 
 

What the Data Actually Shows

A 2026 Cisco survey of 3,472 IT leaders found that 72% cited increased security risk or expanded attack surface as a key driver of AI-related network modernization, while 71% expect AI-driven threats to outpace their current security controls. Nearly 70% of respondents reported a growing number of blind spots limiting their ability to monitor and block suspicious network activity.
 

The headline numbers

  • 72% of IT leaders said expanded attack surface and increased security risk motivated their network modernization for AI
  • 76%+ expect AI-related security risk to grow further as adoption moves beyond basic generative use cases into more advanced, agentic applications
  • 71% expect AI threat evolution to outpace their existing security controls
  • Nearly 70% report a growing number of network blind spots — areas where visibility into traffic and activity has degraded
  • Nearly 90% have added security controls specifically for their AI tools, but a majority of that group still isn't confident those controls are sufficient

What's actually driving the concern

Cisco's analysts pointed to four specific factors: expanded attack surfaces, shadow AI activity, inconsistent policy enforcement, and limited visibility into how AI-driven traffic moves across the environment.
 
One retail-sector executive captured the operational reality plainly: it's difficult to build consistent guardrails for every AI tool an organization ends up using, especially as adoption spreads faster than formal approval processes can track.
61% of respondents said they're deliberately waiting for greater confidence in their security posture before expanding AI use further — meaning security uncertainty is now an active brake on business initiatives, not just a background risk.
 

Why Visibility Is the Real Gap — Not Just Controls

You can't secure what you can't see

The Cisco data draws an important distinction that's easy to miss: nearly 90% of organizations have added security controls for AI tools, yet blind spots are still increasing for most of them
 
That gap matters. Adding controls without adding visibility is a bit like installing more locks on a house while losing track of how many doors it actually has — the controls may be sound, but they can't protect what they can't see happening.
 
Gaps that once caused minor operational friction can now create significant governance and security exposure, because AI systems generate continuous activity across distributed networks in a way traditional periodic monitoring wasn't built to catch.
 

Shadow AI is a visibility problem before it's a policy problem

Shadow AI — tools adopted by teams or individuals without formal security review — was named directly by Cisco's analysts as one of the top drivers of expanding blind spots
 
Most organizations' AI governance conversations start with policy ("what tools are we allowed to use") when the more urgent starting question is visibility ("what tools are actually running in our environment right now, approved or not")
 
You can't govern, vet, or monitor a vendor relationship you don't know exists.
 
Machine-speed activity breaks human-speed monitoring.  AI systems and AI agents generate and act on data continuously, at a pace and volume that periodic or manual review processes were never designed to keep up with. The compression isn't limited to attacker speed, it applies to the sheer volume of legitimate AI-driven activity your security team now has to make sense of.
 
 
 

What This Means by Industry

Financial Services

Network modernization for AI often touches core transaction and payment infrastructure directly — an expanding attack surface here carries both breach risk and regulatory exposure if visibility gaps go unaddressed.

Healthcare

AI-driven network expansion frequently runs adjacent to systems touching PHI, and shadow AI adoption among clinical or administrative staff can create blind spots security teams don't discover until an incident forces the issue
 

Manufacturing

As OT and IT networks converge to support AI-driven operational tooling, visibility gaps take on physical and operational stakes — a blind spot in this environment isn't just a data risk, it's a potential safety and uptime risk
 
 

Closing the Visibility Gap Without Slowing AI Adoption

 

1. Get expert-validated visibility into your actual AI footprint.

Before adding more controls, know what's actually running — approved AI tools, shadow AI, and everything in between. 
 

2. Extend continuous monitoring to AI-driven network activity specifically.

Periodic scans and quarterly reviews can't keep pace with machine-speed traffic. Continuous, expert-monitored coverage can. Explore Purple Team SOCaaS.
 

3. Validate that your added controls are actually closing gaps, not just checking boxes.

Nearly 90% of organizations added AI-specific controls, but most still lack confidence they're sufficient — a pentest-style validation tells you which is true for your environment. Learn about AI Penetration Testing.
 

4. Treat AI network visibility as an ongoing operational discipline, not a one-time project.

The organizations most confident in their AI security posture are the ones treating this as continuous work — matching the pace of AI adoption itself, not a single modernization initiative with a defined end date.
 
The Cisco data makes one thing clear: this isn't a fringe concern. The majority of IT leaders surveyed are already living with reduced visibility, growing blind spots, and a genuine expectation that AI-driven threats will outpace their current defenses. The organizations that move past "playing catch-up" won't be the ones that slow down AI adoption — they'll be the ones that pair it with real, continuous visibility into what's actually happening across their network.
 
Ready to see what's actually running in your environment? Talk to InfoSight about an AI Governance & Exposure Assessment and replace blind spots with real visibility — before an attacker finds the gap first.
Share This Post:

Stay ahead of evolving threats with expert insights

Subscribe to our newsletter to keep you updated on the latest cybersecurity insights & resources.

One follow-up from a security expert—no spam, ever.