Back to ReportsReports
The State of Agentic AI Exposure, 2026
An early look at where AI-native attack surface is growing fastest across enterprise deployments we've assessed, and which failure modes recur most often.
We're publishing the first edition of this report as our AI Security assessment volume grows — this version is intentionally narrow in scope and will expand as more engagements complete.
Early observations
Across the systems we've assessed so far, two patterns recur more than any others:
- Authorization is checked at the API layer, not the agent layer. Backend endpoints correctly enforce per-user scoping, but the agent calling them is trusted to only ask for what it should — an assumption adversarial prompts break routinely.
- Tool permissions are provisioned for the integration, not the request. An agent's MCP or function-calling credentials are typically scoped to "everything this integration might ever need," not to what a single conversation should be allowed to touch.
What's next
Future editions will include comparative benchmarks across solution categories (chatbots, voice agents, MCP servers, internal agents) as our sample size grows. If you'd like your organization's assessment results considered for an anonymized future edition, get in touch.