Commissioned by Radware
Published July 2026
Executive summary
The weaponization of AI by threat actors is overshadowed this year by the threat of frontier AI models that can autonomously find previously undiscovered security vulnerabilities and chain exploits to bypass security protections and compromise organizations. With attacks increasing across AI, APIs, and applications (among others), and with low visibility into security threats in these domains, organizations must urgently seek integrated, cross-domain security capabilities as they adjust their posture to meet incoming AI-driven attacks.
This white paper reports data on a global survey of security leaders and professionals responsible for AI, API, and application security at their organizations. Where appropriate, research data is correlated and reported across three industry groupings — financial services, healthcare, and all other industries. One third of respondents worked in each of these three groupings.
Key findings (see the report for more):
- Organizations are deploying AI faster than they can protect it. 83% of organizations are making widespread use of GenAI or LLM functionality, and 96% expect to implement AI agents or autonomous workflows within 12 months. Yet only 17% have full visibility into AI agents or AI-driven processes.
- AI traffic is creating a new access-control challenge. Only 14% of organizations have full visibility into AI crawler traffic, while 76% have experienced a negative impact from AI crawler traffic or AI agents.
- Application development continues to outpace API security. Nearly half (48%) of organizations update APIs for production use daily or more frequently. Yet only 19% have a fully automated and continuously updated API inventory, and just 24% conduct comprehensive API security testing across the full lifecycle.
- The business impact of application attacks continues to grow. 71% of organizations experience application-layer or API-targeted DDoS attacks monthly or more often. The average cost of downtime from an application-layer DDoS attack increased 23% year over year to $7,530 per minute, or approximately $451,800 per hour.
- Security operations are not moving fast enough. Only 21% of organizations report the highest level of readiness to manage application security incidents, while the average resolution time for significant API, bot or DDoS-related incidents is 2.8 hours.
