Readiness for AI-Powered Attacks
Analytics2026-08-14, 09:48
Readiness for AI-Powered Attacks
Zscaler ThreatLabz assessed how prepared enterprises are to withstand autonomous AI attacks that frontier AI models are capable of carrying out. The study covered hundreds of companies across 12 industries, with Fortune 500 companies accounting for 32% of participants.
For each company, researchers calculated a Frontier-AI-Readiness Score ranging from 0 to 100 based on assessments across five areas: reducing the available attack surface — 25 points, limiting the scope of compromise — 25, governing AI use — 20, data protection — 20, and using deception to detect attackers — 10. The score reflects the likelihood that an AI adversary could penetrate the LAN, move laterally within it, and steal data without encountering effective resistance.
The average readiness of companies for attacks using frontier AI models was just 37 out of 100 points: the worst result was 17, and the best was 60. The researchers highlighted the following:
• For 100% of companies, access to AI infrastructure was not tied to corporate identity-based authentication, making it difficult to control who had access to which AI services. The average score for the "Govern AI Use" defensive pillar was just 2.1 out of 20.
• On average, deep inspection was performed on 36% of encrypted traffic, well below the 70% threshold established by the researchers for the purposes of the study. No company reached this threshold, while in the worst case, 99.6% of traffic passed without inspection.
• The problem is often not a lack of technology. At 64% of companies, deception platforms used to create decoys for attackers did not cover critical segments, meaning an attacker's lateral movement could go undetected. At 15% of companies, IPS solutions could have been switched from monitoring into full enforcement mode, while at 18% — existing authentication could have been extended to additional resources.
• For 64% of organizations using zero-trust network access (ZTNA), policies contained overly broad wildcard rules. In one case, just 195 wildcard domains granted access to more than 108,000 applications for a single account.
• 53% of companies received recommendations to remediate vulnerabilities listed in the CISA KEV catalog on internet-facing resources.
These findings, along with three real-world cases involving companies with identified issues and remediation efforts underway, are examined in greater detail in the full report.
The key distinction of frontier AI models is that they can do more than create individual exploits: they can independently identify and construct attack chains from multiple weaknesses in an infrastructure. Readiness for such attacks depends less on deploying new AI-powered security tools (on the assumption that only AI can compete with AI) than on how consistently a company addresses existing architectural and configuration gaps. According to Zscaler, optimizing existing security controls could raise the readiness score from its current level of 37 to 73–98 points.
Vendors