Kong Inc., a developer of cloud API technologies, recently released findings from their API Security Perspectives 2025: AI-Enhanced Threats and API Security Report which highlights today’s API security landscape and how new developments in AI will impact it.
Most notably, 25% of respondents have encountered AI-enhanced security threats related to APIs or LLMs, with 75% of respondents expressing serious concern about AI-enhanced attacks in the future. And while 85% say they’re confident in their organisation’s security capabilities, 55% of respondents cited they’ve experienced an API security incident in the past year, highlighting a notable disconnect.
The findings also put into perspective the importance of having a strong security strategy noting that 1 in 5 respondents cited their organisation has experienced an API security incident costing more than $500,000 in the past 12 months.
While 92% of respondents say they are taking measures to counter AI-enhanced attacks and 88% of respondents citing API security as a top priority, it is clear that many organisations lack the comprehensive security measures needed to protect their API infrastructure in the AI era.
As might be expected 84% of respondents feel AI and LLMs will make securing APIs more difficult, but surprisingly, the research finds many basic API security tactics being left out of overall strategy.
Only 35% of organisations are adopting zero-trust architecture in order to mitigate API security risks and only 3% of respondents cite shadow APIs as a significant security threat to their organisation. With the convergence of APIs and AI, it is more important than ever to have a strong API security posture.
The report draws on insights from a survey conducted in October and November 2024 with 700 IT professionals and business leaders from the United States and the United Kingdom.
According to the study, to safeguard APIs against AI-enhanced threats, organisations are prioritising measures such as increased monitoring and traffic analysis (66%), staff education on AI-related risks (60%), and deploying AI-driven threat detection systems (51%).
Key steps to mitigate API security risks include leveraging API monitoring and anomaly detection tools (63%), implementing API gateway solutions (61%), and adopting encryption and tokenisation practices (58%).
Recommended reading
- AI Skills Gap Leaves Older Workers Behind
- Over Half of UK Businesses Don’t See AI Adoption as a Priority
- AI Skills Gap Puts Public Sector Projects in Jeopardy
Despite these efforts, 41% of respondents remain unsure or doubtful that their organisation’s investments are sufficient to address API security risks, with 45% dedicating at least 20% of their cybersecurity budgets to API security. Furthermore, 66% of organisations are establishing API governance frameworks to ensure compliance with internal policies and external regulations such as GDPR and HIPAA.
“Organisations cannot afford to underestimate their own security risks — especially in the age of AI,” said Marco Palladino, CTO and Co-Founder of Kong, Inc.
“The report showcases that API security is being taken seriously as part of overall cybersecurity strategy, but there are still some blind spots that can open an organisation up to threats. As AI continues to advance, not only will companies create more vulnerabilities within their own organisations, but attacks will become more sophisticated. Understanding the full threat landscape is crucial to maintaining a strong API security posture.”





