Orca Security’s 2026 State of AI Security Report reveals that 99.9% of fixable AI vulnerabilities remain unpatched as organizations prioritize rapid deployment over essential cybersecurity hygiene and infrastructure protection.
Key Points
- Orca Security found that 81.2% of companies running AI packages have at least one known vulnerability, with 74.1% containing at least one critical CVE.
- Between 87% and 98% of organizations using major cloud providers fail to configure customer-managed encryption keys for their AI services.
- Approximately 30% of AI adopters store sensitive API keys in insecure locations, creating significant risks for data theft and unauthorized access.
- Over half of AI adopters have deployed agent frameworks into production, often without proper runtime separation or restricted permissions.
- Businesses utilizing retrieval-augmented generation (RAG) operate an average of 3.78 vector databases, complicating consistent security policy enforcement across enterprise environments.