Report by HiddenLayer
AI Threat Landscape 2026
Key Findings
76% of organizations cite shadow AI as a definite or probable problem.
73% of organizations report internal conflict over ownership of AI security controls.
34% of organizations partner externally for AI threat detection.
More than 40% of organizations allocate less than 10% of their budgets to AI security.
85% of organizations support mandatory breach disclosure.
Malware hidden in public model and code repositories accounts for 35% of AI-related breaches.
93% of IT and security leaders continue to rely on open repositories for innovation.
The share of organizations citing shadow AI as a definite or probable problem increased from 61% in 2025 to 76%, a 15-point year-over-year increase.
91% of organizations added AI security budgets for 2025.
31% of organizations do not know whether they experienced an AI security breach in the past 12 months.
53% of organizations admit they have withheld breach reporting due to fear of backlash.
Autonomous agents account for more than 1 in 8 reported AI breaches.