< back to blog

AI adoption is a security survival metric

Crystal Morin
AI adoption is a security survival metric
Published by:
Crystal Morin
AI adoption is a security survival metric
Sr. Cybersecurity Strategist
@
AI adoption is a security survival metric
Published:
September 25, 2026
falco feeds by sysdig

Falco Feeds extends the power of Falco by giving open source-focused companies access to expert-written rules that are continuously updated as new threats are discovered.

learn more
Green background with a circular icon on the left and three bullet points listing: Automatically detect threats, Eliminate rule maintenance, Stay compliant, with three black and white cursor arrows pointing at the text.

As AI adoption grows, usage trends are shifting. AI is moving from experiment to infrastructure. The data in the Sysdig 2026 Cloud-Native Security and Usage Report shows organizations increasingly building their own infrastructure rather than relying on external services. This change reduces the AI attack surface.

From consumable to infrastructure

This year, we analyzed over one million more AI and ML packages than we did last year. This is a signal of AI becoming a permanent part of infrastructure.

Translating this data point to McKinsey & Co.’s classification of AI adoption, organizations are increasingly operating as shapers and makers. That is, rather than consuming AI through hosted models like ChatGPT and Claude (takers), they are customizing those models, developing data pipelines, and integrating them into their products and workflows (shapers). Also, a few are training their own models from scratch using massive GPU capacity and vast amounts of data (makers).

Analyzing those packages by type, we’ve observed six times more ML packages in cloud environments. Meanwhile, for AI, OpenAI packages grew 14 times, and Anthropic’s grew 40 times.

Organizations are definitely using AI; that’s no question. The conversation is now about how deeply they are integrating it.

Consolidation is reducing the AI attack surface

As AI adoption shifts from external services to owned infrastructure, security benefits. Paradoxically, while AI adoption is growing, the attack surface for AI infrastructure is shrinking.

Organizations that create their own AI infrastructure are replacing an endless sprawl of AI-enabled point tools and APIs with fewer, yet more critical sets of model infrastructure. The resulting consolidated resources are easier to secure following best practices.

Our data corroborates this thesis. Even as the number of packages grew significantly, public exposure of AI and ML packages remained the same as last year at 1.5%, and just 0.05% of resources were publicly exposed.

You have to keep in mind that, although AI may look like some kind of black box, it’s still just software running on a computer. The following three resources bridge AI with traditional workloads:

Europe and B2C are leading AI adoption

We’ve observed how business-to-consumer (B2C) organizations like media & internet, transportation, and retail are leading AI adoption. For these companies, AI innovation drives revenue and is tied directly to customer experience, engagement, and differentiation.

In contrast, for business-to-business (B2B) organizations, AI does not serve as the primary product interface, but rather takes a subtler role improving operational efficiency. They primarily use AI to support internal productivity, analytics, automation workflows, or customer support.

Also, EMEA is vastly outpacing other regions in the adoption of AI and ML packages. Rather than stifling innovation, the EU’s clear AI regulatory guardrails appear to provide the necessary framework for cautious organizations to accelerate adoption confidently.

This difference could also be explained by data sovereignty requirements and compliance considerations, as they push organizations in EMEA towards using their own AI infrastructure. After all, our data does not account for organizations acting as takers, relying heavily on hosted AI services.

AI adoption for cybersecurity

There’s one area where AI usage has become a matter of survival, and that’s cybersecurity. AI is now an invaluable tool in the arsenal of both attackers and defenders.

Threat actors use it for more than just enhanced social engineering campaigns and reconnaissance. The Sysdig TRT has reported on JADEPUFFER, fully autonomous ransomware, an AI-assisted account takeover in less than 10 minutes, and newly disclosed vulnerabilities being exploited in less than four hours.

Luckily, defenders are hot on their heels. Organizations are leveraging AI in all its forms to accelerate the most time‑consuming parts of cloud security:

  • ML to detect abnormal behavior and flag security incidents.
  • LLMs to reduce the cognitive load and guide developers in fixing vulnerabilities in their code.
  • Agentic AI that correlates data from all your infrastructure to respond automatically to threats, and then helps security engineers investigate them. 

Learn more about AI’s role in cybersecurity by reading AI is the present of security.

Key takeaways

AI is no longer experimental or a novelty. It is operational infrastructure.

The growth in AI and ML packages signals a shift from AI consumption to production‑grade making and shaping.

Organizations that are consolidating AI into their infrastructure are following security best practices. Their AI resources are less publicly exposed, which reduces their attack surface.

The gap between attackers and defenders using AI in cybersecurity is closing quickly. Whoever automates faster will stay ahead for the next six to 12 months.

Check out our full analysis and more data points in the Sysdig 2026 Cloud-Native Security and Usage Report.

About the author

Threat Research
Security for AI
featured resources

Test drive the right way to defend the cloud
with a security expert