New research reveals AI is fueling an ‘unprecedented surge in cloud security risks’

  • Palo Alto warns rapid AI adoption expands cloud attack surfaces, raising unprecedented security risks
  • Excessive permissions and misconfigurations drive incidents; 80% tied to identity issues, not malware
  • Non‑human identities outnumber humans, poorly managed, creating exploitable entry points for adversaries

Rapid enterprise adoption of Artificial Intelligence (AI) tools, and cloud-native AI services, is significantly expanding cloud attack surfaces and putting businesses at more risk than ever before.

This is according to the ‘State of Cloud Security Report’, a new paper published by cybersecurity researchers Palo Alto Networks.

According to the paper, there are a few key problems with AI adoption; the speed at which AI is being deployed, the permissions it is being given, misconfigurations, and the rise in non-human identities.

Permissions, misconfigurations, and non-human identities

Palo Alto says organizations are deploying workloads faster than they can secure them – often without full visibility into how the tools access, process, or share, sensitive data.

In fact, the report states that more than 70% of organizations now use AI-powered cloud services in production, up sharply year-on-year. This speed at which these tools are deployed is now seen as a major contributor to an “unprecedented surge” in cloud security risk.

Then, there is the problem of excessive permissions. AI services frequently require broad access to cloud resources, APIs, and data stores – the report shows that many organizations grant overly permissive identities to AI-driven workloads. According to the research, 80% of cloud security incidents in the past year were linked to identity-related issues, not malware.

Palo Alto also pointed to misconfigurations as a growing problem, especially in environments supporting AI development. Storage buckets, databases, and AI training pipelines are often exposed, which is something threat actors are increasingly exploiting, instead of simply trying to deploy malware.

Finally, the research points to a rise in non-human identities, such as service accounts, API keys, and automation tokens that AI systems use. In many cloud environments, there are now more non-human identities than human ones, and many are poorly monitored, rarely rotated, and difficult to attribute.

“The rise of large language models (LLMs) and agentic AI pushes the attack surface beyond traditional infrastructure,” the report concluded.

“Adversaries target the tools and LLM systems, the underlying infrastructure supporting model development, the actions these systems take, and critically, their memory stores. Each represents a potential point of compromise.”

Follow TechRadar on Google News and add us as a preferred source to get our expert news, reviews, and opinion in your feeds. Make sure to click the Follow button!

And of course you can also follow TechRadar on TikTok for news, reviews, unboxings in video form, and get regular updates from us on WhatsApp too.

Read more @ TechRadar

Latest posts

Bungie’s Marathon shooter launches on March 5th

Bungie is putting an official date on Marathon today, its delayed extraction shooter. The slick-looking shooter from the makers of Halo and Destiny was...

A second US Sphere could come to Maryland

Sphere Entertainment, the company behind the eye-catching interactive venue in Las Vegas, has announced its "intent to develop" another Sphere in Maryland that will...

Musk claims Tesla will restart work on its Dojo supercomputer

Elon Musk posted on X that Tesla will be restarting work on Dojo3, the third generation of its in-house supercomputer project. The Dojo team...

Bungie’s Marathon arrives on March 5

Marathon, Bungie's long-awaited extraction shooter, will arrive on March 5, the studio announced today. Alongside a definitive release date, Bungie shared a new gameplay...

More malicious browser extensions uncovered – Chrome, Firefox, and Edge all affected

LayerX found 17 malicious browser extensions with 840,000+ downloads Extensions hijacked affiliate links, injected tracking, and enabled ad fraudAll extensions removed, but users must...

The world’s first Gemini-powered EV lands this week, but the Volvo EX60 needs to be better than Alexa+ on the BMW iX3

The Volvo EX60 will be the first to ship with Google Gemini built-inVolvo is promising "natural conversation" between man and machineLatest hardware from Nvidia...

MIO: Memories in Orbit is a pleasant stroll after the brutal ultramarathon of Hollow Knight: Silksong — and I’m here for it

When I booted up last year’s tough-as-nails and long-awaited Hollow Knight: Silksong, I knew I had to focus up and lock in – this...

Tour Down Under 2026 Free Streams: TV Channels, Schedule & Preview of UCI WorldTour Opener

Stream Tour Down Under 2026 completely *FREE* on 7Plus (AUS)Use NordVPN to watch from anywherePrologue: January 20 — Adelaide → Adelaide (3.6km)Start Time: 6pm...

How to watch The Secret of Me on Channel 4 — it’s *FREE*

Watch The Secret of Me for free on Channel 4 (UK restricted)Watch The Secret of Me for free on ABC iView (AUS restricted)Abroad? Watch...

ChatGPT now has ads, and before long Gemini might too – here’s what we can learn from Netflix, Prime Video, and other streaming services

The time has come, OpenAI has finally announced the thing we all knew was coming but didn't want to believe: ChatGPT is getting ads.The...