Zscaler Finds Critical AI Security Gaps Across Enterprises  | eSecurity Planet

Zscaler Finds Critical AI Security Gaps Across Enterprises 

Zscaler found frontier AI exploited enterprise security weaknesses in as little as 16 minutes.

Written By
Ken Underhill
Ken Underhill
Jul 24, 2026
4 minute read
eSecurity Planet content and product recommendations are editorially independent. We may make money when you click on links to our partners. Learn More

As organizations rapidly adopt artificial intelligence (AI), security teams are racing to understand how frontier AI models could reshape enterprise cyber risk. 

Rather than relying on theoretical scenarios, Zscaler spent 90 days using frontier AI models from Anthropic and OpenAI to assess dozens of real enterprise environments from an adversarial perspective. 

The results suggest that AI is accelerating the exploitation of existing security weaknesses rather than creating entirely new ones.

According to Zscaler, every organization assessed contained critical vulnerabilities that AI-powered attackers could exploit. 

The company reported that 100% of organizations had ungoverned AI exposure, 90% still exposed VPN appliances to the internet, and 53% maintained internet-facing assets with vulnerabilities listed in the CISA KEV catalog. 

Under adversarial testing, the median time to first critical security failure was just 16 minutes, while 90% of environments were compromised in under 90 minutes.

Key takeaways of the Zscaler AI security gap findings

  • 100% of organizations assessed had ungoverned AI exposure, 90% exposed VPN appliances to the internet, and 53% had internet-facing CISA Known Exploited Vulnerabilities (KEVs).
  • Under adversarial testing, the median time to first critical security failure was 16 minutes, while 90% of environments were compromised in under 90 minutes.
  • Frontier AI rapidly chained existing security weaknesses into complete attack paths rather than relying on new zero-day exploits.
  • Organizations with stronger Zero Trust architectures, TLS inspection, and continuous monitoring demonstrated significantly greater resilience.
  • CISOs should prioritize continuous AI governance, exposure management, identity security, and regular AI red teaming to keep pace with AI-powered threats.

AI accelerates exploitation of existing weaknesses

Deepen Desai, Chief Security Officer and EVP of Research and Development at Zscaler, said organizations are exposing AI services without applying the same security controls expected for other enterprise applications.

“It looks like AI tools being put online without proper security in front of them, no login, no identity check, no real oversight,” Desai said in an email to eSecurityPlanet. 

He added, “This is happening so often because companies are moving fast to roll out AI, and security teams usually aren’t brought in early enough to keep up.”

Rather than relying on sophisticated zero-day vulnerabilities, frontier AI models rapidly identify and combine multiple low-risk weaknesses into successful attack paths.

“It’s usually not that security tools are completely missing — it’s that too many gaps are left open for attackers to move through quickly,” Desai explained. “AI can now find weak points fast, but more importantly, it can chain together small weaknesses that may not look critical on their own.”

Advertisement

He compared the process to someone entering an office without picking a single lock by tailgating through one entrance, finding an unattended badge at another, and moving through poorly monitored areas.

Individually, none of those issues appear catastrophic, but together they enable a successful intrusion. AI performs this process continuously and at machine speed.

Legacy exposures become larger AI risks

The research also highlights how longstanding security issues become significantly more dangerous when AI automates reconnaissance and exploitation.

Desai compared the shift to an increase in biological viruses: the biology hasn’t changed, but the speed and scale of exposure have. 

Likewise, the underlying security vulnerabilities remain the same, while AI dramatically accelerates how quickly attackers can exploit them. 

“Legacy weaknesses like exposed appliances aren’t new,” he said. “What’s new is that AI-powered attackers can identify them, test them, and break them together at a speed that completely changes the risk.”

Identity also emerged as one of the primary attack vectors during the assessments. According to Desai, frontier AI models consistently targeted compromised credentials and excessive user permissions.

“In over 90% of organizations, one stolen credential opens a path to thousands of assets or applications because of segmentation maturity,” he said.

Zero Trust execution separates resilient organizations

One finding that surprised Zscaler researchers was that many organizations believed they had already addressed foundational security controls, yet AI-driven testing repeatedly uncovered exploitable gaps.

“The biggest surprise is how much exposure exists in the fundamentals: inspection policies, external attack surface reduction, lateral movement,” Desai said. “These aren’t new concepts, but AI has dramatically raised the bar for getting them right.”

Organizations that demonstrated stronger resilience were not necessarily deploying entirely new technologies. 

Instead, they consistently executed established security practices, including Transport Layer Security (TLS) inspection, Zero Trust architectures, improved detection capabilities, and stronger monitoring for suspicious activity.

“The encouraging part is that many companies can do this today with what they already have,” Desai said.

Advertisement

Governance must keep pace with AI adoption

As AI deployments continue expanding across business functions, Desai recommends that CISOs first establish visibility into where AI services are operating before strengthening identity controls and reducing unnecessary internet exposure.

He also emphasized continuous governance through ongoing exposure monitoring, AI red teaming, stronger segmentation, data loss prevention, deception technologies, and tested incident recovery plans.

Looking ahead, Desai believes organizations should shorten their planning horizon from years to weeks because AI capabilities are advancing so quickly.

“I would encourage organizations to think 12-24 weeks versus months,” he said. “Threat actors will get their hands on frontier AI models, and this is no longer a theoretical problem.”

For security leaders, he recommends focusing on two questions: What does the organization look like from the perspective of an AI-powered adversary, and how far could an attacker move if a single internet-facing asset or identity were compromised? 

Organizations that cannot confidently answer both questions may have significant architectural and operational gaps that AI-powered attackers can rapidly exploit.

Ken Underhill

Ken Underhill is an award-winning cybersecurity professional, bestselling author, and seasoned IT professional. He holds a graduate degree in cybersecurity and information assurance from Western Governors University and brings years of hands-on experience to the field.

eSecurity Planet Logo

eSecurity Planet is a leading resource for IT professionals at large enterprises who are actively researching cybersecurity vendors and latest trends. eSecurity Planet focuses on providing instruction for how to approach common security challenges, as well as informational deep-dives about advanced cybersecurity topics.

Property of TechnologyAdvice. © 2026 TechnologyAdvice. All Rights Reserved

Advertiser Disclosure: Some of the products that appear on this site are from companies from which TechnologyAdvice receives compensation. This compensation may impact how and where products appear on this site including, for example, the order in which they appear. TechnologyAdvice does not include all companies or all types of products available in the marketplace.