Report by FireTail

The State of AI & API Security

19 FINDINGSPublished Jun 1, 2025
View Original Report →

Key Findings

The last two years have seen 150% year-over-year growth in AI-related incidents, with a significant inflection point coinciding with widespread cloud adoption in the late 2010s/early 2020s and the 2022 release of ChatGPT.

FireTailThe State of AI & API Security·Jun 1, 2025
AI

Recent research from Wiz highlights 6 known vulnerabilities with the underlying AI providers themselves.

FireTailThe State of AI & API Security·Jun 1, 2025
AIVulnerabilities

Recent research indicates that half of organizations reporting AI-related security incidents estimated losses exceeding $50 million. Using an industry-standard metric of $169 per breached record, this equates to approximately 300,000 data records per organization.

FireTailThe State of AI & API Security·Jun 1, 2025
AI

Analysis of FireTail's customer data revealed that nearly 39% of all API requests resulted in HTTP 429 (Too Many Requests) responses, suggesting potential abuse. Of these 429 responses, about 20% were linked to bot traffic.

FireTailThe State of AI & API Security·Jun 1, 2025
AIAPI

The AI Incident Database maintained by the Responsible AI Collaborative tracks AI-related issues dating back to the 1980s, with concentrated growth from 2010 onwards.

FireTailThe State of AI & API Security·Jun 1, 2025
AI

A scan of publicly accessible GitHub repositories found that the number of OpenAPI specifications decreased from 2,879 in 2023 to 2,160 in 2025.

FireTailThe State of AI & API Security·Jun 1, 2025
AIAPI

90% or more of generative AI usage falls into the "shadow AI" scenario, meaning it occurs without the knowledge of central IT and information security teams.

FireTailThe State of AI & API Security·Jun 1, 2025
AIShadow AI

Cumulatively, over 1.6 billion records have been exposed since 2017 due to API breaches.

FireTailThe State of AI & API Security·Jun 1, 2025
AIAPIBreach

In the last three years, there have been 79 documented API breaches, significantly more than the 22 cloud-related breaches in the same period, indicating APIs are a growing focal point for attackers.

FireTailThe State of AI & API Security·Jun 1, 2025
AIAPIBreach

Despite the rise in API security incidents, the number of breaches dropped from 18 to 93.

FireTailThe State of AI & API Security·Jun 1, 2025
AIAPIBreach

A vulnerability in the Irish Government COVID-19 Vaccination Portal, present since December 2021, was disclosed in March 2024 and exposed the vaccination records of approximately one million residents.

FireTailThe State of AI & API Security·Jun 1, 2025
AIVulnerabilitiesIreland

Approximately 9% of API traffic from Russia, China, and Iran was flagged as bot activity, particularly in January, November, and December 2024.

FireTailThe State of AI & API Security·Jun 1, 2025
AIAPI

The mean number of warnings per OpenAPI specification significantly increased, from an average of 215 warnings per spec in 2023 to 1,078 warnings per spec in 2025. Unrestricted String and Array Lengths emerged as the most common warning type.

FireTailThe State of AI & API Security·Jun 1, 2025
AIAPI

MIT's AI Risk Repository identifies over 1000+ risks from an academic perspective.

FireTailThe State of AI & API Security·Jun 1, 2025
AI

97% of organizations believe AI introduces unique security challenges.

FireTailThe State of AI & API Security·Jun 1, 2025
AI

Approximately 70% of AI data breaches have no secondary breach vector, deviating from typical multi-vector API breaches.

FireTailThe State of AI & API Security·Jun 1, 2025
AIAPIBreach

Nearly 60% of organizations report inadequate visibility into the APIs supporting their AI systems.

FireTailThe State of AI & API Security·Jun 1, 2025
AIAPI

The FireTail API Data Breach Tracker shows a rise in API security incidents, increasing from 22 in 2023 to 26 in 2024.

FireTailThe State of AI & API Security·Jun 1, 2025
AIAPI

TracFone Wireless faced a $16 million settlement and a comprehensive consent decree due to API vulnerabilities that exposed customer data.

FireTailThe State of AI & API Security·Jun 1, 2025
AIAPIBreach