Report by Salt Security
The State of AI and API Security: Navigating the Agentic Era
Key Findings
99% of API attack attempts originate from authenticated sources
66% of organizations report API growth of more than 50% in the past year
24% of organizations have a fully automated API inventory
47% of organizations have delayed production releases due to API security concerns
32% of organizations experienced an API security incident in the past year
Nearly 90% of organizations are already using or planning to use GenAI in API development
18% of boards and executive teams are extremely confident in their ability to detect API attacks leveraging Generative AI
65% of API attacks exploit Security Misconfiguration (OWASP API8)
8% of organizations report advanced API security maturity
79% of boards and executive teams have increased scrutiny of AI security risks
92% of organizations lack the advanced security maturity required to defend agentic AI environments