Blog Zscaler
Recevez les dernières mises à jour du blog de Zscaler dans votre boîte de réception
ThreatLabz 2026 Report: Frontier AI and Enterprise Readiness
The Breach
It was 9:14 AM when the CISO's VPN connection momentarily dropped, something that normally wouldn’t cause any concern. What he couldn't see was that attackers had already exploited a pre-authentication flaw in the VPN appliance itself, gaining access before any login ever occurred. From there, they extracted stored credentials, forged an identity as his Director of Security Operations, and authenticated through a trust chain that never questioned traffic originating from VPN infrastructure.
By 9:22, that stolen identity was requesting application access at machine speed, hundreds of grants per minute across a footprint of over 4,200 apps, until it reached an ungoverned internal AI endpoint sitting on top of three years of proprietary R&D data. Exfiltration began immediately, disguised as normal outbound traffic. By 9:33, the entire sequence had been autonomously replicated across nine additional VPN entry points.
While the scenario is hypothetical, it’s increasingly likely—pieced together from findings encountered during the course of conducting our Frontier AI Preparedness Assessments. Its implications are chilling. For enterprises globally, this scenario is rapidly becoming an impending reality. As the US National Security Agency warned recently, fully autonomous cyberattacks are mere months, not years, away.
Preparing for the Storm
Three months ago, we embarked on a journey to help organizations prepare by examining their readiness against these autonomous attacks.
Frontier AI refers to the most advanced, highly capable foundation models that push the boundaries of current artificial intelligence. Unlike traditional, narrow AI, these models possess sophisticated reasoning, planning, and autonomous execution capabilities. In the hands of adversaries, they don't necessarily uncover exotic, never-before-seen zero-days; instead, they find small gaps in the armor and chain them into complete attack paths at machine speed. Like a burglar testing every lock, window, and alarm on an entire street in seconds, an AI adversary compresses the kill chain from initial reconnaissance to full data exfiltration in minutes.
How We Assessed Readiness
To accurately understand and measure this threat, we worked closely with leading Frontier AI companies, gaining early access to their most advanced models. It is important to note that to maintain strict data privacy and security, we deliberately did not use these models directly on any live enterprise data other than our own. Instead, we leveraged them in isolated, controlled simulation environments to emulate the specific attack patterns and velocity of frontier AI.
Using these insights, we evaluated organizations on a 0-100 scale, assessing various axes including data protection, attack surface shielding, and decoy deployment to determine how well they could withstand an autonomous, machine-speed attack.
Current State of Enterprise Readiness for Frontier AI
Across hundreds of enterprises assessed in 2026, the average Frontier AI Readiness Score sat at 37 out of 100. Even more telling, the average AI governance pillar score was just 2.1 out of 20, proving that enterprise readiness for these advanced threats remains virtually at "year zero."
- 9 out of 10 organizations maintain exposed VPN appliances that serve as prime pre-authentication attack surfaces.
- More than 1/3 of enterprises leave CISA Known Exploited Vulnerabilities (KEVs) active on internet-facing assets.
- 100% of assessed organizations lack identity-based authentication for their AI systems.
- ~36% is the average proportion of encrypted traffic inspected by enterprises, falling far short of the 70% threshold required for inline security controls to function effectively.
- 64% of organizations use broad segmentation configurations. In one case, 195 wildcard domains exposed over 108,000 applications, creating a worst-case blast radius where a single compromised identity could reach up to 483,250 applications.
When your security stack is blind to nearly two-thirds of encrypted traffic and legacy VPNs expose massive blast radiuses, you aren't just leaving the door unlocked, you are building a high-speed freeway for AI-driven attack chains.
Architecture Beats AI: Closing Critical Gaps Today
You cannot out-algorithm an autonomous attack. When the adversary operates at machine speed, trying to detect and respond in real-time is a losing battle. The winning strategy isn't layering on more reactive AI; it's relying on a fundamentally superior architecture.
Architecture beats AI because a true Zero Trust platform denies exploitable paths by design. By eliminating the attack surface and making lateral movement mathematically impossible, you neutralize the AI's speed advantage entirely.
To build true resilience against machine-speed threats, security leaders should execute a focused 90-day sprint on four core actions:
- Flip the Switch on Enforcement: Transition dormant controls like IPS, malicious IP blocking, and domain fronting protection from monitor-only to full enforcement mode.
- Shield VPNs & Patch Known Exploits: Move exposed VPN appliances behind brokered Zero Trust access and patch CISA Known Exploited Vulnerabilities on public-facing assets immediately. If you can’t patch them, hide them.
- Gate AI Surfaces & Inspect Encrypted Traffic: Place every AI endpoint and copilot behind enterprise identity verification, and raise SSL/TLS inspection to at least 70% by default.
- Kill Wildcard Domains & Deploy Deception: Replace broad wildcard domain rules with named FQDNs, and deploy active decoys near critical applications to automatically detect and revoke compromised sessions.
Don't try to outrun the machine. Out-architect it.
To learn more about our findings and how to assess your own organization's readiness, read the full report.
Cet article a-t-il été utile ?
Clause de non-responsabilité : Cet article de blog a été créé par Zscaler à des fins d’information uniquement et est fourni « en l’état » sans aucune garantie d’exactitude, d’exhaustivité ou de fiabilité. Zscaler n’assume aucune responsabilité pour toute erreur ou omission ou pour toute action prise sur la base des informations fournies. Tous les sites Web ou ressources de tiers liés à cet article de blog sont fournis pour des raisons de commodité uniquement, et Zscaler n’est pas responsable de leur contenu ni de leurs pratiques. Tout le contenu peut être modifié sans préavis. En accédant à ce blog, vous acceptez ces conditions et reconnaissez qu’il est de votre responsabilité de vérifier et d’utiliser les informations en fonction de vos besoins.
Recevez les dernières mises à jour du blog de Zscaler dans votre boîte de réception
En envoyant le formulaire, vous acceptez notre politique de confidentialité.



