Salt Security
Reports
All Statistics
90% of security leaders have active concerns about security risks introduced by AI-generated code.
38% of organizations still rely primarily on manual review for AI-generated code.
15% of security leaders cite misalignment with internal security policies as a major concern with AI-generated code.
66% of organizations report API growth of more than 50% in the past year
24% of organizations have a fully automated API inventory
99% of API attack attempts originate from authenticated sources
25% of organizations said APIs are used to create new revenue streams.
31% of organizations adhere to GDPR for API development and deployment.
3% of organizations do not know if Generative AI is perceived as a growing API security concern/risk within their organization.
Just 37% of organisations have a data privacy team overseeing AI initiatives.
19% of organisations deploy between 21 and 50 types of AI agents.
7% of organisations assess API risk monthly or less.
55% slowed the rollout of a new application due to API security concerns.
Regarding Generative AI (GenAI), 47% of respondents expressed concerns about securing AI-generated code, and 40% cited potential vulnerabilities introduced by AI-generated code as a top risk. Only 11% do not perceive the use of GenAI applications as a growing security concern.
Only 10% of organisations currently have an API posture governance strategy in place, but 43% plan to implement such a strategy within the next 12 months.
29% of security leaders identify insecure coding patterns as the leading risk introduced by AI coding assistants.
67% of organizations report that AI coding assistants are now widely adopted across development teams.
47% of organizations have delayed production releases due to API security concerns
32% of organizations experienced an API security incident in the past year
Nearly 90% of organizations are already using or planning to use GenAI in API development
18% of boards and executive teams are extremely confident in their ability to detect API attacks leveraging Generative AI
65% of API attacks exploit Security Misconfiguration (OWASP API8)
8% of organizations report advanced API security maturity
79% of boards and executive teams have increased scrutiny of AI security risks
92% of organizations lack the advanced security maturity required to defend agentic AI environments
15% of organizations are very confident in detecting and responding to attacks leveraging Generative AI.
80% of security leaders lack continuous, real-time API monitoring.
28% of organizations identify partner enablement as a main driver behind the use of APIs.
48% of organizations identify platform or system integrations as a main driver behind the use of APIs.
25% of organizations identify monetization of functionality or data as a main driver behind the use of APIs.
A small but notable 6% of organizations indicated their API volume more than tripled (301%+) in just 12 months.
29% of organizations identified account misuse or other fraud as the most common API security problem.
18% of organizations cited brute forcing or credential stuffing as the most common API security problem.
13% of organizations cited enumeration and scraping as the most common API security problem.
12% of organizations cited a lack of investment in pre-production security for their API programs.
25% of respondents pointed to budget limitations as the primary barrier to implementing a strong API security program.
7% of respondents identified that it’s difficult to know if their company's API program is compliant with new policies/regulations.
2% of respondents identified 'Other' as their biggest concern about their company’s overall API program.
Only 19% of organizations were 'very confident' in the accuracy of their API inventories.
9% of organizations have no formal API security strategy in place.
41% of organizations cited vulnerabilities as the most common API security problem.
39% of organizations adhere to the NIST Cybersecurity Framework for API development and deployment.
56% of organizations perceive GenAI as a growing security concern for APIs.
45% of organizations identify digital transformation initiatives as a main driver behind the use of APIs.
45% of organizations pointed to digital transformation initiatives as a primary driver for modernizing legacy systems and accelerating new services.
50% of security leaders have slowed a new application rollout due to API security concerns.
14% of organizations oversee 1,001 or more APIs.
41% of organizations reported API growth of 51–100% over the past year.
33% of organizations flagged authentication problems as the most common API security problem.
17% of organizations were 'not very confident' in the accuracy of their API inventories.