AI is generating infrastructure code faster than teams can govern it, and the result is misconfigurations and breaches in production. Here's how AI penetration testing and Purple SOCaaS close the gap.
The headline number every security leader should be reading twice
A new survey of 406 IT and platform engineering leaders just put a hard figure on something many security teams have felt in their gut for the past year: 93% of organizations have experienced AI-caused infrastructure incidents, even as 89% plan to adopt agentic AI for infrastructure and only 19% have built the governance foundations needed for AI readiness.
93% of organizations have experienced AI-caused infrastructure incidents — yet only 19% have built the governance foundations they need for AI readiness.
The
research describes a widening "AI readiness gap": companies are adopting AI faster than they can govern it, and they're paying for it in production. As Spacelift CEO Paweł Hytry put it, organizations are using AI to generate infrastructure code at a rate their governance frameworks were never designed to handle.
For a managed security services provider that lives and breathes attack surface, this is not an abstract DevOps story. It's a direct expansion of the threat surface—and it's exactly the kind of shift InfoSight tracks so our clients don't have to.
"Vibe coding" reached the infrastructure layer, and the blast radius grew
The phrase the report uses is blunt: vibe coding has spread to infrastructure. 82% of respondents say between 25% and 74% of their code was created with help from AI. That code doesn't stay in the developer's editor—it flows downstream into the pipelines that provision and run production environments, and the teams deploying it aren't getting the same speed boost the developers got.
The consequences are already measurable. Respondents reported reworking AI-generated changes (37%), security misconfigurations that reached production (36%), compliance violations (36%), infrastructure drift attributable to AI changes (35%), and incidents caused by agentic systems (33%). More broadly, 40% say security vulnerabilities are showing up more frequently and 40% say governance has become more challenging.
There's a critical difference between a buggy application function and a bad infrastructure change. As Help Net Security summarized the findings, a misconfiguration that slips through is a resource problem in production, with a wider blast radius than a buggy application function. A single AI-generated Terraform misstep can expose a storage bucket, open a security group to the internet, or quietly grant excess IAM permissions across an entire environment.
The most dangerous gap is the one teams don't know they have
The most striking finding isn't the incident rate—it's the overconfidence behind it. The report calls out a near-textbook case of self-delusion: 86% say they can govern AI, while only 30% actually have a formal AI governance policy in place. Panterra's managing director framed the year-over-year shift cleanly: last year organizations overestimated their automation maturity; this year, they're overestimating their governance readiness.
That perception gap is the single most exploitable condition in security. Attackers don't need a zero-day when an organization has confidently shipped AI-generated infrastructure it never independently validated. The teams that came out ahead in the survey weren't the most aggressive AI adopters—they were the ones that built governance frameworks before AI increased the speed and complexity of infrastructure demands.
You cannot close a gap you can't see. Closing it requires two things working together: an offensive practice that finds what AI-generated changes actually exposed, and a defensive practice that watches the environment continuously as that code keeps shipping. That's precisely the pairing InfoSight built.
How InfoSight closes the AI readiness gap
AI Penetration Testing: validate what AI built before an attacker does
Traditional point-in-time pen testing was designed for a world where infrastructure changed on a quarterly release cadence. That world is gone. When a quarter of your infrastructure code is AI-generated and pushed continuously, an annual test is a snapshot of an environment that no longer exists by the time the report lands.
InfoSight's AI Penetration Testing is built for the AI-accelerated pipeline. We focus on the failure modes this survey surfaced:
- Misconfiguration discovery in AI-generated IaC. We hunt for the exact problems the report flagged—overly permissive IAM roles, exposed services, insecure defaults, and drift between what the code intended and what actually deployed.
- Agentic and AI-integration attack paths. As organizations wire in agentic systems, those integrations become new attack vectors. We test how an attacker could abuse them—prompt manipulation, over-scoped agent permissions, and the chained-action risks unique to autonomous workflows.
- Continuous penetration testing aligned to continuous deployment. Because AI-driven change is constant, testing should be too. Our continuous pen testing model keeps validation in step with the rate your environment actually changes, not the rate your old compliance calendar assumed.
- Closed-loop reporting your board can act on. Findings feed directly into InfoSight's Mitigator® platform for risk prioritization and board-level reporting—so "we think we govern AI well" becomes "here is exactly what we tested, what we found, and what we fixed."
This is the offensive half of closing the readiness gap: turning unknown, unvalidated AI output into a known, ranked, and remediated risk picture.
Purple SOCaaS: continuous detection for an environment that never stops changing
Finding the gaps once isn't enough when the environment is being rewritten daily. That's where InfoSight's **Purple SOCaaS**—our AI-enabled, human-led Security Operations Center as a Service—comes in.
Purple SOCaaS unites red-team thinking (how an attacker would exploit a fresh misconfiguration) with blue-team defense (detecting and responding the moment they try). For organizations shipping AI-generated infrastructure, that combination matters more than ever:
- 24/7 detection and response across the environments AI is now reshaping in real time, backed by InfoSight's US-based NOC.
- Behavioral monitoring tuned for AI-speed threats. Attackers are using generative AI to move faster than manual review can keep up. Purple SOCaaS is built to match that tempo—catching the misconfiguration-to-exploit window before it becomes an incident.
- Coverage where the blast radius is widest. OT/ICS, cloud, and IT environments alike, with detection logic informed by the same offensive testing that finds the gaps in the first place.
- A feedback loop, not a silo. What our pen testers find sharpens what the SOC watches for. What the SOC sees in the wild informs the next test. That red/blue loop is the "purple" in Purple SOCaaS—and it's how detection stays ahead of an evolving attack surface instead of chasing it.
The takeaway for manufacturing, finance, and healthcare leaders
The data is a North American, enterprise-wide signal, but the risk concentrates fastest in regulated, high-consequence verticals. All respondents were at organizations with 250 or more employees—the exact mid-to-large profile where AI-generated infrastructure now collides with HIPAA, PCI-DSS, NIST CSF, NERC CIP, and SEC scrutiny. A compliance violation born from an unreviewed AI change isn't just a technical problem; it's a reportable one.
The organizations that will weather this aren't the ones that slowed down their AI adoption. They're the ones that paired their speed with validation and continuous defense. AI will keep generating code faster than humans can review it. The answer isn't to unplug it—it's to test what it builds and watch what it runs.
That's the gap InfoSight was built to close.
Ready to find out what your AI-generated infrastructure actually exposed?
InfoSight has spent 27+ years keeping pace with how attackers actually operate. Our AI Penetration Testing identifies the misconfigurations and agentic-system risks hiding in your pipeline, and our Purple SOCaaS keeps watching long after the test is done.
Let's map your AI readiness gap before an attacker maps it for you.