2026年AI安全态势报告(英文原版)_第1页
2026年AI安全态势报告(英文原版)_第2页
2026年AI安全态势报告(英文原版)_第3页
2026年AI安全态势报告(英文原版)_第4页
2026年AI安全态势报告(英文原版)_第5页
已阅读5页,还剩121页未读 继续免费阅读

下载本文档

版权说明:本文档由用户提供并上传,收益归属内容提供方,若内容存在侵权,请进行举报或认领

文档简介

2026

STATEOF

AISECURITYREPORT

AISecurityFindingsfrom1,200+ProductionCloudEnvironments

©2026ORCASECURITY.ALLRIGHTSRESERVED.

AIhasledtoexponentialgrowthintheemployees

shippingtoproductionandsecurityteamsarenot

keepingup.Whenthewaypeoplebuildchanges,the

waysecurityworkshastochangewithit.Thisreport

measuresthatgap,andclosingitstartswithgiving

securityteamsthecontexttounderstandAIriskandact.

GILGERON,

CEOANDCO-FOUNDEROFORCASECURITY

2026STATEOFAISECURITYREPORT

InsideThisReport

Foreword01

AbouttheOrcaResearchPod

02

ExecutiveSummary

03

KeyFindings

04

1.AIAdoption:From

ExperimenttoInfrastructure

07

2.TheAISupplyChainUnderAttack

16

3.AIAgentsandRAG:

TheUngovernedAttackSurface

25

4.AISprawlandtheGovernanceGap30

5.AICredentialsandInsecureAccess35

6.AIInfrastructureExposure37

7.AIEncryption:TheMissingLayer42

8.WhatThisMeansforYourOrganization46

9.KeyRecommendations48

10.Conclusion52

AboutOrcaSecurity53

2026STATEOFAIREPORT|TOC|

01

2026STATEOFAISECURITYREPORT

Foreword

AIhasfundamentallyreshapedhoworganizationsbuild,deploy,andoperateinthecloud,

butsecurityhasn'tkeptpace.Intwoyears,AIhasmovedfromexperimentalpilotstoproductioninfrastructure.Foundationmodels,autonomousagents,andRAGpipelinesnowconnectto

sensitivedata.Thecontrolstogovernthisexist,butadoptionlagsdeployment,andbasichygienelikeleastprivilege,authentication,andnetworkisolationisstillbeingskippedforspeed.

AIworkloadsrunondefaultconfigurations,APIkeyssitinplaintext,andcriticalvulnerabilitiesinAIpackagesgounpatchedevenwhenfixesexist.MorethanhalfoforganizationsbuildingwithAI

havedeployedagentframeworkswithcloudpermissionsandwithoutguardrails.Thesearestructuralrealities,nottheoreticalrisks.

Thethreatlandscapehasshiftedtoo.2025–2026broughtsupplychainattacksonAI-specificpackages,modelsautonomously

discoveringandexploitingzero-days

,andagenticsystems

causingrealdamagewhensafetycontrolsfailed.Thesametoolsacceleratingdevelopmentareacceleratingtheattacksurface.

Thisreport,groundedintheOrcaResearchPod'sanalysisof1,200+productionorganizations,quantifiesthegapbetweenAIadoptionandAIsecurityadoption,namesthecontrols

organizationsaren'tconfiguring,andofferspracticalguidanceforclosingthegapbeforeregulationforcestheissue.

GilGeron

CEOandCo-FounderofOrcaSecurity

2026STATEOFAIREPORT|TOC|

02

2026STATEOFAISECURITYREPORT

AbouttheOrcaResearchPod

TheOrcaResearchPodisagroupofsecurityresearcherswhodiscoverandanalyzesecurityrisksandvulnerabilitiestostrengthentheOrca

SecurityPlatformandadvancecloudsecuritybestpractices.ThePodregularlypublishesoriginalresearchthathasbeenfeaturedacrossthesecurityindustry.Theirfindingsarereferencedthroughoutthisreportalongsidebroaderresearchtelemetryandanalysis.

Beyondanalyzingtelemetryfromproductionenvironments,theResearchPodconductsoriginaloffensivesecurityresearchintoAI-specificattack

vectors.Recentpublicationsinclude

RoguePilot:ExploitingGitHubCopilot

foraRepositoryTakeover

,whichdemonstratedapassiveprompt

injectionchainachievingfullrepotakeoverviaGitHubCodespaces,and

AI-InducedLateralMovement(AILM)

,whichintroducedtheAIlayerasanewpivotvector,athirddimensionoflateralmovementalongside

networkandidentity.Together,thesefindingsillustratehowquicklytheAIattacksurfaceisevolving.

ResearchMethodology

Thisreportisbasedonaggregated,anonymizedsecuritytelemetryfromover1,200productionorganizationsusingOrcaSecurity's

cloudplatform.Metricsrepresentthepercentageoforganizationsexhibitingeachfinding,weightedacrossthedataset.DatawascollectedinQ22026fromproductionenvironmentsonly,toreflectreal-worldsecuritypostures.

FindingsspanAIcloudserviceconfiguration,packagevulnerabilitymanagement,secretsexposure,agentandRAGinfrastructure

security,encryptionposture,andAIworkloadidentitymanagement.

ReportDataSet:

●Cloudworkloadandconfigurationdatafromover

1,200organizations

●AI-specifictelemetrycoveringmodels,packages,agents,vectordatabases,andinfrastructureconfiguration

●DatareferencedinthisreportwascollectedinQ22026

2026STATEOFAIREPORT|TOC|

03

2026STATEOFAISECURITYREPORT

ExecutiveSummary

AIhasmovedfrompilottoproductionfasterthanmostsecurityprogramshavefollowed.Drawingonreal-worldtelemetryfromover1,200organizations,thisreportfindsawideninggapbetweenthespeedofAIadoptionandthematurityofAIsecuritythatresultsinmisconfigurations,unpatchedvulnerabilities,

exposedcredentials,andungovernedagentsrunninginproduction.Belowareourkeyfindings:

AIadoptionismainstream,butsecurityisanafterthought

51.5%oforganizationshaveadoptedAItobuildcustomapplications,yet80%ofSageMakerdeploymentsstillrunwithallfivecoreinsecure

defaultsenabled.

AIpackagevulnerabilitiesarepervasiveandunpatched

81%oforganizationswithAIpackagescarryatleastoneknownHighvulnerability.Publicexploitsnowexistfor50.1%ofalerts,upfrom0.2%inour

2024report

.99.9%offixablealertsremainunpatched.

WidelyexposedAIcredentialsenabledirectcompromise

28.4%ofOpenAIusersstoreAPIkeysinunsecurelocations(40%for

AnthropicSDKusers),and94%ofAzureOpenAIdeploymentsstillrelyonkey-basedauthinsteadofmanagedidentities.

Agentsareinproduction,butguardrailsarenot

56%ofAIadoptersrunagentframeworksinproduction,including786

Bedrockagentsacross8%oforganizations,yet57%ofBedrockusershavenosafetyguardrailsconfigured.

Encryptioniseffectivelyabsentacrossallclouds

87–98%oforganizationsusingAIserviceshaven'tconfiguredcustomer-managedencryptionkeys(CMEK);SageMakernotebooksholdthehighestrateat98.4%,

leavingtrainingdata,models,andpipelinesreliantondefaultproviderencryption.

AIsprawlisoutpacinggovernance

55.3%ofAIcloudusersrunfourormoreAIservicetypes,and19.6%runsevenormore.Consistentsecuritypolicyacrossthislandscapeisnearlyimpossibleformostorganizations.

AIregulationisona2026calendar

TheEUAIAct'shigh-riskobligationstakeeffectAugust2,2026(finesupto€35Mor7%ofglobalturnover),andColorado'samendedAIlaw(S.B.26-189)takes

effectJanuary1,2027.Thesemisconfigurationsarenowregulatoryrealities.

Forpracticalnextsteps,seeChapter9—KeyRecommendations.

2026STATEOFAISECURITYREPORT

50.1%

ofAIpackagevulnerability

alertshaveapublicexploitavailable,a250xincreasefrom0.2%in2024.

HalfofallAIvulnerabilitiesarenowactively

exploitable,yet99.9%ofalertswithafixavailableremainunpatched.Thelow-exploitabilityexcusenolongerholds.

81%

oforganizationswithAIpackages

haveatleastoneknownvulnerability,upfrom62%in2024.

AverageCVSSscoresjumpedfrom6.9to8.79,and74%nowcarryatleastonecriticalCVE(9.0+).TheAIdependencytreeisdeeperandmoreseverethantwoyearsago.

25%to40%

ofusersacrossAnthropic,

OpenAI,andHuggingFacehaveatleast

oneAPIkeystoredinanunsecurelocation.

Anthropicexposuremorethantripled(13%→

40%),OpenAIrose(20%→28.4%),HuggingFaceimproved(35%→24.9%).Exposureiswidespread,provider-agnostic,andworseningwhereadoptionisgrowingthefastest.

86%

ofSageMakerorgshaveat

leastonepredictably-namedbucket.

Thelegacynamingpatternisbrute-forceable,

exposingtrainingdata,modelartifacts,andpipelineoutputs.Adoptionnearlydoubledfrom45%in

2024,despiteAWSrandomizingthedefaultconvention.

KeyFindings

51.5%

oforganizationshaveadoptedAItobuildcustomapplications.

AIisnolongerexperimental.Overhalfof

organizationsrunAIinproductionbutadoptionhasshifted:frompre-builtmodelstoagents,RAG

pipelines,andcustomAIinfrastructure.

80%

ofSageMakerorganizations

runwithalldefaultsettingsenabled.

ThemostwidelyadoptedAIcloudserviceships

insecurebydefault,andorgsrarelyreconfigureit.Whilesettingshaveimproved,themajoritystillrunallfiveinsecuredefaults.

2026STATEOFAIREPORT|TOC|

04

2026STATEOFAIREPORT|TOC|

05

2026STATEOFAISECURITYREPORT

57%

ofBedrockorganizationsrunagentswithoutguardrails.

MorethanhalfoforganizationsusingAmazon

Bedrockhavenotconfiguredanysafetyguardrails,leavingAIagentsoperatingwithoutcontent

filtering,groundingchecks,orpolicycontrols.

56%

ofAIadoptershavedeployedagentframeworksinproduction

LangGraphleads,with786Bedrockagentsholdingcloudpermissionsand879knowledgebases

connectedtodata—newcategoriessince2024,reflectingtheAIstack'srapidexpansioninto

autonomous,data-connectedsystems.

55.3%

ofAIcloudserviceusersoperate

fourormoredistinctAIservicetypes.

19.6%usesevenormore.WithAIworkloadsspreadacrossmultipleservicesandclouds,

maintainingconsistentsecuritygovernanceisagrowingchallengeforsecurityteams.

KeyFindings

98%

ofSageMakernotebookinstanceslackcustomer-managedencryption.

AzureOpenAI(91.6%)andVertexAIModels

(94.8%)followclosebehind.WhileVertexAI

improvedslightlysince2024,mostorganizations

stillrelyondefaultprovider-managedencryptionforAIworkloads.

64%

ofAIadoptershavedeployedvectordatabases.

WidespreadRAGadoptionacrosssevenmajorvectordatabasescreatesanewandfragmentedattacksurfacefordatapoisoningandprompt

injectionthroughretrieveddocuments.

Year-over-YearComparisonSummary

METRIC

2024REPORT

2026REPORT

TREND

OrgswithatleastonevulnerableAIpackage

62%

81%

Worsened

AverageCVSSacrossAIpackages

6.9

8.79

Worsened

AIvulnerabilitieswithpublicexploit

0.2%

50.1%

Worsened(250x)

SageMakerwithrootaccess

98%

75.8%

Improved

SageMakerwithoutIMDSv2

77%

47.9%

Improved

SageMakerusingdefaultbucketnames

45%

86%

Worsened

OpenAIkeysinunsecurelocations

20%

28.4%

Worsened

HuggingFacekeysinunsecurelocations

35%

24.9%

Improved

Anthropickeysinunsecurelocations

13%

40%

Worsened(3x)

VertexAIwithoutCMEK

98%

92.9%

SlightlyImproved

AzureOpenAIadoption(%ofAzureorgs)

39%

50.5%

Increased

SageMakeradoption(%ofAWSorgs)

29%

31%

Increased

VertexAIadoption(%ofGCPorgs)

24%

32%

Increased

TopAImodel

GPT-3.5(79%)

GPT-4o(37.6%)

Generationalshift

Agentframeworksdeployed

Nottracked

56%ofAIadopters

Newcategory

Vectordatabasesdeployed

Nottracked

64%ofAIadopters

Newcategory

01

AIAdoption:

FromExperimenttoInfrastructure

2026STATEOFAIREPORT|TOC|

07

1.AIAdoption:

FromExperimenttoInfrastructure

In2024,AIadoptionmeantdeployingamodel,wiringupacopilot,andcallinganAPI.MostenterpriseAIlivedbehindasingleintegrationpoint,andsecurityquestions

centeredonthemodelitself.

2025changedtheshapeoftheproblem.AgenticAImovedfromdemotodefault:

McKinsey's

2025StateofAI

putenterpriseusageat78%,and62%oforganizationswereeitherscalingorpilotingAIagents.TheModelContextProtocollaunchedby

Anthropicinlate2024becamethedefactointegrationlayer,withadoptionfromeverymajormodelproviderand8M+serverdownloadsbyApril.Meanwhile,the

security

picturedarkened

:90%ofsecuritypractitionersreportedusingAItoolsbutonly32%oforganizationshadformalcontrols,and

morethanhalf

sawAIagentsexceedtheir

intendedpermissions.

Asof2026,AIisnolongeraserviceyoucall,as51.5%oforganizationshaveadoptedAItobuildcustomapplications.It'sembeddedindevelopmentenvironments,security

platforms,businesssystems,andcloudinfrastructure.MeaningtheAIattacksurfacenowcanvaseseveryidentity,everyintegration,andeveryagentactingonbehalfofahuman.

2026STATEOFAIREPORT|TOC|

08

AIADOPTION:FROMEXPERIMENTTOINFRASTRUCTURE

1.1TheAIIDERevolution

AI-powereddevelopmenttoolsbecamethedefaultcodingexperiencein2025-2026.GitHubCopilot,Cursor,Windsurf,ClaudeCode,AmazonQDeveloper,andGeminiCodeAssistall

competeforthedeveloper'seditor.Cursorreachedunicornstatus.GitHubreportedover150milliondevelopersonitsplatformwithCopilotdeeplyintegratedintotheworkflow.

Orca'sdatareflectsthis:33%ofAIadoptershaveGitHubCopilotdeployed,andtheopenaipackageisusedby80.7%ofAIadopters,showinghowdeeplyAPI-basedAIisembeddedindevelopmentworkflows.

Thesetoolsoperatewithsignificantaccess:codebases,terminals,environmentvariables,andcredentials.Thataccesscreatesnewattacksurfaces.TheOrcaResearchPoddemonstratedthisdirectlywithRoguePilot,a

vulnerabilityinGitHubCodespaces

whereapassiveprompt

injectionhiddeninaGitHubIssuecouldsilentlyhijackCopilot,causingittocheckoutacrafted

pullrequest,readsensitiveenvironmentfilesviaasymboliclink,andexfiltrateaprivilegedGITHUB_TOKENthroughautomaticJSONschemadownloads,resultinginafull

repositorytakeover.

2026STATEOFAIREPORT|TOC|

0

150M

GitHubreportedover150

milliondevelopersonits

platformwithCopilotdeeplyintegratedintotheworkflow.

33%

33%ofAIadoptershaveGitHubCopilotdeployed

80.7%ofAIadopters,showinghowdeeplyAPI-basedAIis

embeddedindevelopmentworkflow

80.7%

AIADOPTION:FROMEXPERIMENTTOINFRASTRUCTURE

1.2AIAgentsgotoProduction

Byearly2026,AIagentsmovedfromdemostoproduction.LangGraph,AutoGen,CrewAI,AmazonBedrockAgents,andOpenAI'sAgentsAPIalllaunchedor

matured.56.2%ofAIadoptersnowhaveagentframeworksdeployed,withLangGraphdominant.TheLangChainecosystemhasbecomethebackboneofagenticAIdevelopment,whichcutsbothways:maturetoolingaccelerates

adoption,butasinglevulnerabilityinlangchain-corenowhasablastradiusacrossthemajorityofproductionagentstacks.

Everyproductionagentisanewnon-humanidentitywithitsownpermissions,memory,andblastradius.Mostarebeingdeployedfasterthansecurityteamscaninventorythem.Chapter3coversthegovernancegapindetail.

2026STATEOFAIREPORT|TOC|

56.2%

56.2%ofAIadoptersnowhaveagentframeworksdeployed

TheLangChainecosystem

langchain-core

60%

langchain-text-splitters

53.7%

langchain-community

51.7%

%OFORGANIZATIONS

AIADOPTION:FROMEXPERIMENTTOINFRASTRUCTURE

1.3RAGandtheEnterpriseDataConnection

Organizationsarenolongerjustqueryingmodels;theyareconnectingthemtotheirmost

sensitivedataincludingsourcecoderepositories,customersupporttranscripts,andinternalwikis.Retrieval-AugmentedGeneration(RAG)pipelines,poweredbyvectordatabases,

allowLLMstoaccessinternaldocuments,customerdata,andproprietaryknowledgeat

querytime.RAGfundamentallychangedtheAIriskmodel.Pre-RAG,a

promptinjection

couldresultincompanyexposure.Post-RAG,apromptinjectioncan

exfiltrateyourcustomer

records,sourcecode,orboarddocuments

nowthatthemodelhasauthorizedreadaccesstoallofit.

64%ofAIadoptershavedeployedvectordatabases,acrossahighlyfragmentedmarketofseven-plusvendors,eachwithitsownauthmodel,networkposture,andexposure

defaults.Chapter3coversthevendorbreakdownandtheRAG-specificattackresearchindetail.Mostenterprisedata-protectiontoolingwasnotbuilttoinventoryafootprintthis

fragmented.Embeddingsthemselvesaresensitivetoo:inversionresearchhasshownthe

originaltextcanbepartiallyreconstructedfromexposedvectors

,meaningaleakedvectordatabaseiseffectivelyaleakeddocumentstore.

EmbeddingmodeladoptionconfirmshowwidespreadRAGusagehasbecome.Theleading

embeddingmodelsareallOpenAI-hosted,meaningthesourcetextforeveryembeddinghas,bydefinition,traversedathird-partyAPI.Forregulatedcustomers,thatisa

data-residencydecisionbeingmadeimplicitlyattheengineeringlayer.

2026STATEOFAIREPORT|TOC|

1

TopEmbeddingModelsAmongAICloudServiceUsers

text-embedding-ada-002

29.1%

text-embedding-3-small

23.2%

text-embedding-3-large

22.3%

AIADOPTION:FROMEXPERIMENTTOINFRASTRUCTURE

1.4TheModelLandscapeShift

Themodellandscapeincloudserviceshasfragmented.In2024,GPT-3.5dominatedat79%

adoption.By2026,GPT-4oleadsatjust37.6%,withGPT-4.1-miniclosebehindat34.7%.TheGPT-5familyandreasoningmodelsarealreadyinmeaningfulproductionuselessthanayearafterrelease.NosinglemodelcommandsthemarketthewayGPT-3.5oncedid.Thegovernanceimplicationislargerthanthemarketshift.Whenonemodelcommanded79%ofdeployments,asinglepolicycoveredmostoftheexposure.Afive-modelmarketmeansfivesetsofcredentials,fiveAPIshapes,fivesafetyprofiles,andfiveaudittrailsleadingsecuritycontrolstomoveupthestack,abovethemodeltothegateway.

Meanwhile,modelcustomizationandself-hostingarewidespread:scikit-learnisusedby82.5%ofAIadoptersforclassicalMLandfeaturepipelines,PyTorchby63.8%,andtransformersandhuggingface-hubeachby60.8%whicharethestandardtoolchainforfine-tuningandrunningopen-weightmodelsin-house.Thistellsusorganizationsarerapidlyevolvingbeyondsolely

consumingpre-builtmodelsthroughAPIsandtowardsfine-tuningfoundationmodelson

proprietarydataandhostingopen-weightalternativesinsidetheirowncloudenvironments.

Thismattersforthesupplychain:when60.8%ofAIadopterspullartifactsfromHuggingFaceintoproductionenvironments,theMLregistrybecomesascriticalandasexposedasNode

PackageManager(npm)orPythonPackageIndex(PyPI)

.2024

and

2025

sawmultiple

documentedincidentsofmaliciousmodelsonHuggingFace,includingpickle-basedremotecodeexecutionpayloads.MostorganizationsstillinventorytheirPythonpackagesmorerigorously

thanthemodelweightstheyruninproduction.

LLMDeploymentSharebyModel

GPT-3.5(2024baseline)

79%

GPT-4o(2026leader)

37.6%

GPT-4.1-mini

34.7%

GPT-4.1

28.9%

GPT-4o-mini

28.6%

GPT-5.1

22.3%

GPT-5-mini

19.7%

o4-mini

17.8%

12

2026STATEOFAIREPORT|TOC|

01

TheTop10MostPopularAIModels

RANK

MODEL

ORGSW/AIMODELDEPLOYMENTS

1

gpt-4o

AzureOpenAI

37.6%

2

gpt-4.1-miniAzureOpenAI

34.7%

3

text-embedding-ada-002AzureOpenAI

29.1%

4

gpt-4.1

AzureOpenAI

28.9%

5

gpt-4o-mini

AzureOpenAI

28.6%

6

text-embedding-3-smallAzureOpenAI

23.2%

7

text-embedding-3-largeAzureOpenAI

22.3%

8

gpt-5.1

AzureOpenAI

22.3%

9

gpt-5-mini

AzureOpenAI

19.7%

10

o4-mini

AzureOpenAI

17.8%

Top10MostPopularAIModels

TheOpenAImodellineuphasfragmentedsince2024,buttheproviderhasnot.Inthe

2024

OrcaStateofAIreport

,GPT-3.5aloneaccountedfor79%ofmodeldeploymentinour

telemetry.Inthisreport,nosinglemodelexceeds38%adoption.Thetop10most-deployedmodelsareallOpenAImodelsrunningonAzureOpenAI.

text-embedding-ada-002atrank3isafindingworthsinglingout.OpenAIreleased

text-embedding-3-smallandtext-embedding-3-largeinJanuary2024,withbetterperformanceandlowercost.ada-002stillsittingat29.1%adoptiontwoyearslaterreflectsthesamepatchinginertiathesupplychainfindingsearlierinthisreportdocumentedforAI

packages,nowappliedtomodelversions.Re-embeddingaproductioncorpusisoperationallyexpensive,andmanyRAGpipelinesdeferthemigrationindefinitely.

Threepatternsemergefromthetable.First,everymodelinthetop10isanOpenAImodelrunningonAzureOpenAI,whichmeansmodelconcentrationattheproviderlevelremainssubstantialevenasmodelconcentrationattheSKUlevelhasdeclined.Second,three

embeddingmodelsinthetop10reflecthowwidelyRAGpipelineshavebeendeployed,withthepersistenceofada-002indicatingthatlegacyembeddingversionsremaininproductionlongafterreplacementsareavailable.Third,theGPT-5familyando4-minirepresentthe

newestgenerationenteringproduction,withadoptioncurvesstillintheirearlyphase.

OnenotableabsencefromthetableisAnthropic'sClaudemodelfamily.OurtelemetryreflectsenterprisedeploymentpatternsthroughAzureOpenAI.Claude,increasinglyaccessedthroughAnthropic'sownAPIandAmazonBedrock,doesnotsurfacethroughthesamedeployment

signal.However,Anthropic'senterprisefootprinthasgrownsubstantially,andthecredential

exposurefindingsinChapter5reflectthatdirectly:AnthropicAPIkeyexposuresmorethan

tripledsince2024,reaching40%ofAnthropicSDKusers,thehighestrateofanyproviderin

ourtelemetry.AmorecompletepictureofthemodellandscapeincludesClaudeasasignificantandgrowingtier-oneprovider.

2026STATEOFAIREPORT|TOC|

13

AIADOPTION:FROMEXPERIMENTTOINFRASTRUCTURETheAIDeveloperStack

1.5TheAIDeveloperStack

TheOrcaResearchPodtrackswhichAIpackagesorganizations

actuallyinstallandrun.ThedatabelowispresentedagainstorganizationsweobservedrunningAIandmachinelearningpackagestrackedinourtelemetry,whichcapturesboth

AI-specificandincidentalenterpriseadoption.

Despitethemarket'sfocusongenerativeAI,thefoundational

classicalmachinelearninglibrary(scikit-learnat82.5%)remainsthesinglemostdeployedAIpackageacrossourtelemetry.ThatrepresentsasubstantialclassicalMLfootprintalongsideLLM

workloads.PyTorchat63.8%versusTensorFlowat48.5%

reflectsthebroaderindustryshifttowardPyTorchforproductionAI,apatternthathasacceleratedsince2023andisnowvisible

atclearmagnitudeinenterprisetelemetry.

TheLangChainecosystemdominatesthemiddleofthetable.

langchain-core(60%),langchain-text-splitters(53.7%),and

langchain-community(51.7%)togetherindicatethatLangChainhasbecomethedefaultabstractionlayerforAIapplication

development,spanningeverythingfrombasicLLMscaffoldingtofullagentorchestration.TheOpenAIPythonSDKatrank2

(80.7%)reinforceswhatthemodeldatashowedearlierinthischapter.TheOpenAIecosystemdominatesbothmodel

deploymentandSDKintegration,andmostorganizationsoperatewithinit.

RANK

PACKAGE

%OFAIADOPTERS

1

scikit-learn

82.5%

2

openai

80.7%

3

PyTorch(torch)

63.8%

4

transformers

60.8%

5

huggingface-hub

60.8%

6

langchain-core

60.0%

7

onnx

55.3%

8

langchain-text-splitters

53.7%

9

langchain-community

51.7%

10

tensorflow

48.5%

14

2026STATEOFAIREPORT|TOC|

01

AIADOPTION:FROMEXPERIMENTTOINFRASTRUCTURE

1.6AISprawl:TheGovernanceChallenge

AIisnowafootprintofoverlappingservicesratherthanasingleworkload.55.3%ofAIcloud

serviceusersoperatefourormoredistinctAIservicetypes,and19.6%usesevenormore.Eachserviceshipswithitsowndataflows,identities,andexposuredefaults,andtheaverage

organizationhasnosingleconsolewhereitseesthemall.

ThebrowserhasbecometheprimaryAIconsumptionchannelandtheleast-governedsurface.

AIbrowserextensionsare60%morelikelytohaveknownvulnerabilitiesthannon-AIextensions,3xmorelikelytoaccesssessioncookies,and6xmorelikelytochangetheirpermissionsafter

installation.Chapter4mapsthefullgovernancegapacrossservices,codegeneration,andregulatoryexposure.

2026STATEOFAIREPORT|TOC|

55.3%ofAIcloudserviceusersoperatefourormoredistinctAIservicetypes

19.6%ofAIcloudserviceusersoperatesevenormoredistinctAIservicetypes

55.3%

19.6%

2026STATEOFAIREPORT|TOC|

02

TheAISupply

ChainUnderAttack

2.TheAISupply

ChainUnderAttack

Softwaresupplychainattackshavebecomethemostcost-efficientwayforattackerstoreachmanytargetsatonce.Across2025and2026,thatpatternmovedaggressivelyintotheAI

ecosystem.ReversingLabsresearchfoundthat23%ofthetop1,000most-downloaded

HuggingFacemodelshadbeen

compromisedatsomepoint

,andcampaignslike

NullifAI

and

ModelNamespaceReuse

demonstratedthatattackersareactivelytargetingAI-specific

packages,modelhubs,andagentictooling.

OrcaResearchPodtelemetryshowedintheprevioussectionhowconcentratedtheexposurehasbecome.Atthatlevelofconcentration,asinglesuccessfulcompromiseofoneofthesepackagesreachesthemajorityofAI-adoptingorganizationsbeforedefenderscanrespond.Thisisthe

adoption-securitygapinaction:AIdependenciesarespreadingfasterthantheenforcementofpracticesneededtoinventory,patch,andgovernthem.

Thesectionsthatfollowtracetheshapeofthatexposureacrossfiveangles:thenamedincidentsthatdefinedthethreatin2025and2026,theCVEfootprintacrossthemostcommonlyusedAIpackages,thesharpriseinexploitability,thepackagescarryingthehighestseverityscores,andtheemergingvulnerabilitiesappearinginnewerAItooling.

2026STATEOFAIREPORT|TOC|

17

THEAISUPPLYCHAIN

UNDERATTACK

2.1Major

AISupply

ChainAttacks

Theincidentsbelowdefined

theAIsupplychainthreat

landscape.Readtogether,

theyshowattackersmovingdeliberatelyacrossfivelayersoftheAIstack:package

registries,modelhubs,

developertooling,agent

frameworks,andbrandtrust.Everyoneoftheselayersis

deployedinthemajorityof

productionenvironmentsOrcaobserved,whichmeanseachincidenthasaplausiblepathintomostAI-adopting

organizations.Casesare

drawnfrompublicvendor

disclosuresandCVEreporting.

ATTACK/CAMPAIGNTYPEIMPACT

温馨提示

  • 1. 本站所有资源如无特殊说明,都需要本地电脑安装OFFICE2007和PDF阅读器。图纸软件为CAD,CAXA,PROE,UG,SolidWorks等.压缩文件请下载最新的WinRAR软件解压。
  • 2. 本站的文档不包含任何第三方提供的附件图纸等,如果需要附件,请联系上传者。文件的所有权益归上传用户所有。
  • 3. 本站RAR压缩包中若带图纸,网页内容里面会有图纸预览,若没有图纸预览就没有图纸。
  • 4. 未经权益所有人同意不得将文件中的内容挪作商业或盈利用途。
  • 5. 人人文库网仅提供信息存储空间,仅对用户上传内容的表现方式做保护处理,对用户上传分享的文档内容本身不做任何修改或编辑,并不能对任何下载内容负责。
  • 6. 下载文件中如有侵权或不适当内容,请与我们联系,我们立即纠正。
  • 7. 本站不保证下载资源的准确性、安全性和完整性, 同时也不承担用户因使用这些下载资源对自己和他人造成任何形式的伤害或损失。

评论

0/150

提交评论