Tenable Research Reveals Growing AI Exposure Gap Fueled by Supply Chain Risks and Lack of Identity Controls
Summary
Tenable released its Cloud and AI Security Risk Report 2026, finding that organizations inherit cyber risks faster than they can remediate as AI adoption, third-party code, and cloud scale accelerate. The report highlights that 86% of organizations host third-party code packages with critical vulnerabilities, 70% have integrated at least one AI/MCP package, nonhuman identities now represent higher risk (52%) than human users, and 65% hold unused or unrotated cloud credentials. Tenable describes an emerging 'AI exposure gap' across applications, infrastructure, identities, agents and data and flags supply chain attack vectors and excessive privileges as urgent issues. The firm recommends identity-centric controls, enforcing least privilege for AI roles, neutralizing ghost identities, and unifying visibility across code, VMs, identities and cloud environments to reduce exposure.