83% of organizations widely use GenAI or LLMs, while only 17% have full visibility into AI agents and AI-driven processes
Radware® (NASDAQ: RDWR), a global leader in AI and application security and delivery solutions for multi-cloud environments, today released its 2026 Cyber Survey: New Trends in AI, API and Application Security. Based on a global survey conducted by Osterman Research on behalf of Radware, the survey found that organizations are adopting AI faster than they are implementing the security controls needed to protect their environments.
Security professionals are accustomed to security models aligned with traditional layers of the technology environment, including the network, application and data layers. The emerging AI layer presents a new set of challenges. As enterprises expand their use of generative AI, large language models (LLMs), AI agents and autonomous workflows, the survey indicates that threat actors are using AI to discover vulnerabilities, evade defenses and accelerate attacks. The survey found many organizations lack the visibility and governance needed to effectively secure AI, applications and APIs.
Also Read: CIO Influence Interview with Hugo Dozois-Caouette, CTO and Co-founder at MaintainX
“The emerging AI layer presents a new set of security challenges that may not be addressed with isolated point solutions,” said Connie Stack, chief growth officer, Radware. “Organizations need visibility across AI, applications and APIs to identify and respond to emerging threats faster.”
Among the survey’s key findings:
- Organizations are deploying AI faster than they can protect it. 83% of organizations are making widespread use of GenAI or LLM functionality, and 96% expect to implement AI agents or autonomous workflows within 12 months. Yet only 17% have full visibility into AI agents or AI-driven processes.
- AI traffic is creating a new access-control challenge. Only 14% of organizations have full visibility into AI crawler traffic, while 76% have experienced a negative impact from AI crawler traffic or AI agents.
- Application development continues to outpace API security. Nearly half (48%) of organizations update APIs for production use daily or more frequently. Yet only 19% have a fully automated and continuously updated API inventory, and just 24% conduct comprehensive API security testing across the full lifecycle.
- The business impact of application attacks continues to grow. 71% of organizations experience application-layer or API-targeted DDoS attacks monthly or more often. The average cost of downtime from an application-layer DDoS attack increased 23% year over year to $7,530 per minute, or approximately $451,800 per hour.
- Security operations are not moving fast enough. Only 21% of organizations report the highest level of readiness to manage application security incidents, while the average resolution time for significant API, bot or DDoS-related incidents is 2.8 hours.
The survey’s findings underscore the growing need for organizations to strengthen visibility, governance and coordinated security across AI, applications and APIs as they prepare for increasingly sophisticated AI-driven threats.
Catch more CIO Insights: What Does “Job-Ready” Really Mean in IT and Cybersecurity?
[To share your insights with us, please write to psen@itechseries.com ]

