惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

Recent Announcements
Recent Announcements
奇客Solidot–传递最新科技情报
奇客Solidot–传递最新科技情报
MongoDB | Blog
MongoDB | Blog
H
Help Net Security
钛媒体:引领未来商业与生活新知
钛媒体:引领未来商业与生活新知
人人都是产品经理
人人都是产品经理
freeCodeCamp Programming Tutorials: Python, JavaScript, Git & More
The GitHub Blog
The GitHub Blog
V
V2EX
Microsoft Security Blog
Microsoft Security Blog
V
Visual Studio Blog
A
About on SuperTechFans
博客园_首页
L
LangChain Blog
量子位
雷峰网
雷峰网
Cyber Security Advisories - MS-ISAC
Cyber Security Advisories - MS-ISAC
Jina AI
Jina AI
月光博客
月光博客
阮一峰的网络日志
阮一峰的网络日志
博客园 - 聂微东
Microsoft Azure Blog
Microsoft Azure Blog
M
MIT News - Artificial intelligence
N
Netflix TechBlog - Medium

Hacker News - Newest: "AI"

AI can't read an investor deck AI as an attorney? Student uses ChatGPT, Gemini to sue UW over alleged racial discrimination Hacking MCP Servers in AI Systems – The Rug Pull: Tool Changes After Approval GitHub - MeepCastana/KubeezCut: Free Web based video editor Can AI judge journalism? A Thiel-backed startup says yes, even if it risks chilling whistleblowers Coming soon: 10 Things That Matter in AI Right Now DARPA built an AI to fact-check enemy weapons claims What explains heterogeneity in AI adoption? When AI Meets Muscle: Context-Aware Electrical Stimulation Promises a New Way to Guide Human Movements - Department of Computer Science AI Changed How We Build. It Did Not Change What Matters. Linux rules on using AI-generated code - Copilot is OK, but humans must take 'full responsibility for the… Meta spins up AI version of Mark Zuckerberg to engage with employees Code Mode: Let Your AI Write Programs, Not Just Call Tools | TanStack Blog GitHub - Delavalom/graft: Go framework for building AI agents. Type-safe tools, multi-provider (OpenAI, Anthropic, Gemini, Bedrock), zero vendor SDKs. India's TCS tops estimates, says new AI models did not dent services demand Gen Z's fading AI hype Strong feeling: we are in a folded AI reality GitHub - machinarii/total-recall-catalog: A reference catalog of latest knowledge retrieval, memory & RAG systems GitHub - mensfeld/code-on-incus: Give each AI agent its own isolated machine with root, Docker, and systemd. Active defense detects and stops threats automatically.. Quantization, LoRA, and the 8% Problem: Benchmarking Local LLMs for Production AI Iran war: We spoke to the man making Lego-style AI videos that experts say are powerful propaganda Powell, Bessent discussed Anthropic's Mythos AI cyber threat with major U.S. banks GitHub - immartian/bellamem: Persistent belief-graph memory for AI agents. Retrieves decisive context by importance — not recency, not RAG, not /compact. recursive-mode: The Repo-Native Operating System for AI Engineering After the attack on Sam Altman's home, will AI CEO's go on the offensive? The biggest advance in AI since the LLM Opus 4.6 vs GPT 5.4 One Prompt Unity World Generation Test “AI polls” are fake polls Client Challenge Can AI be a 'child of God'? Inside Anthropic's meeting with Christian leaders
The ‘counterintuitive crisis’ at the heart of AI security
Editor · 2026-06-16 · via Hacker News - Newest: "AI"

FusionAuth’s 2026 State of AI and Identity Report finds that nearly two-thirds of organizations have experienced a confirmed AI identity breach in the past year, and among those who feel most secure, the rate jumps to 84%.

This headline result details how AI is reshaping identity infrastructure, security posture, and enterprise trust. The findings reveal a profound and counterintuitive crisis: the organizations that feel most prepared are getting hit the hardest.

65% of respondents reported a confirmed AI identity-related cyber incident in the past 12 months, with another 23% reporting a near miss. Only 12% emerged from the past year without an incident or close call. But the headline finding is not the breach rate alone; it is who is getting breached.

Among organizations that rated themselves ‘extremely confident’ in their AI security posture, 84% had already experienced a confirmed incident. That figure drops to 64% among those ‘very confident’, and to just 17% among those who are ‘not so confident’. The gradient is near-perfect says FusionAuth: confidence and breach rates move together.

Key findings include:

  • 88% say AI deployment is outpacing their identity and security infrastructure
  • 65% experienced a confirmed AI identity-related cyber incident in the past 12 months
  • 84% of organizations that are ‘extremely confident’ in their AI security posture also reported a confirmed incident
  • 80% report shadow AI (employees connecting AI tools without security or IT review)
  • 83% vs 38% confirmed incident rate for multi-tenant SaaS vs self-hosted identity platforms
  • 85% have faced customer, partner, or regulatory demands to prove tenant isolation
  • 93% say AI is already a trigger for reevaluating identity infrastructure
  • 91% expect identity investment to increase in the next 12-18 months.

“Confidence appears to be tracking deployment velocity and governance activity, not actual protection,” said Brian Bell, CEO of FusionAuth. “The faster organizations move, the more confident they feel. The faster they move, the larger their attack surface. Written policies don’t answer the questions that matter: can you scope what each agent can access? Can you see what it’s doing? Can you prove what it accessed after the fact? Can you revoke access before a near miss becomes something worse? Architecture answers those questions. Policy alone does not.”

The report also notes that organizations with more mature security programmes are better at detecting incidents, meaning lower-confidence organizations may not be safer, but simply have less visibility into what is already happening.

Architecture is the new first-order security variable

The deployment model an organization uses for its identity platform correlates strongly with breach outcomes. Organizations using multi-tenant SaaS identity platforms report confirmed incidents at more than twice the rate of those using self-hosted or on-premises deployments: 83% vs 38%.

In a shared SaaS environment, a single compromised token or misconfigured policy does not stay contained. It cascades across every AI workflow connected to the identity layer, model access, data pipelines, automation actions, and downstream services, creating a fundamentally different blast radius than a self-hosted or isolated deployment.

The highest-risk profile in the study is not a low-maturity organization. It is the opposite: companies running AI in production, using AI broadly across the workforce, and operating on multi-tenant SaaS identity infrastructure. In this cohort, 90% reported a confirmed incident and 96% faced shadow AI challenges.

Identity is now a commercial trust problem

AI identity risk has moved beyond the security team. 85% of respondents have faced customer, partner, or regulatory demands to demonstrate tenant isolation at least occasionally, while 56% face it frequently. Tenant isolation has shifted from a backend implementation detail to a commercial requirement that now determines whether enterprise deals close.

Among organizations where AI is the primary driver of identity reevaluation and customers frequently demand proof of isolation, 99% reported a confirmed incident, and 95% are planning significant increases in investment, pointing to a buying motion driven by urgency rather than planning.