Site navigation

Enterprise AI Just Sixteen Minutes From Breach, Warns Zscaler

Tom Quinn

,

AI enterprise risk
“In the age of agentic AI, an intrusion can move from discovery to lateral movement to data theft in minutes, rendering traditional defences obsolete,” said Deepen Desai, Zscaler.

As AI is woven tighter into business operations, enterprises are unprepared for the wave of cyber risk the tech will bring, Zscaler has warned, with AI now serving as a key vector for autonomous, high‑velocity attacks.

Analysing nearly one trillion AI and machine learning transactions, the latest ThreatLabz AI Security Report found a 90% year-on-year increase in enterprise AI activity, with 3,400 applications generating nearly four times more AI/ML traffic than previously recorded.

Zscaler found that although finance and insurance still lead in AI usage, making up a quarter of all AI/ML traffic, the tech sector saw explosive growth, with transactions spiking 202%.

Despite leaning ever more heavily on AI, however, many organisations are still not taking a basic inventory of their models or embedded features, a critical gap that leaves them unaware of exactly where sensitive data is exposed.

This problem is made worse by the 18,000 TB of company data poured into AI tools like Grammarly and ChatGPT over 2025, a 93% year-over-year increase that is roughly equivalent to 3.6 billion digital photos.

The massive influx of data has transformed these off-the-shelf products into the world’s most concentrated repositories of corporate intelligence, said Zscaler, a risk quantified by the 410 million Data Loss Prevention (DLP) policy violations tied to ChatGPT alone last year.

The study warns that this vast pool of data is now at serious risk of exposure, driven by the huge volume of activity flowing through unmanaged, “standalone” tools embedded into everyday enterprise SaaS applications and platforms.

For example, enterprise users logged 115 billion ChatGPT transactions last year through such tools, while the AI coding assistant Codeium logged 42 billion transactions.

Because these features are often active by default and escape detection by legacy security filters, Zscaler said they create a back door for sensitive corporate data to flow into AI models without oversight. 

Among all platforms analysed, Atlassian was a leading source of such embedded AI activity, reflecting widespread use of AI-powered features within its core platforms, such as Jira and Confluence.

As these repositories grow, they are becoming high-priority targets for cyber-attack, meaning AI governance needs to move from a policy discussion to an immediate operational necessity.

One Second From Disaster

Unfortunately, that’s where things get worse. By red teaming enterprise AI platforms, Zscaler discovered that these systems are brittle and vulnerable to breach at machine speed, breaking almost immediately when tested under real adversarial conditions.

The study found that, in controlled scans, the median time to first critical failure was just sixteen minutes, with 90% of systems being compromised in under 90 minutes. In the most extreme case, defences were bypassed in a single second.


Recommended reading


ThreatLabz warned that with autonomous AIs increasingly being used to automate cyber-attacks, through reconnaissance, exploitation, and lateral movement, defenders should now assume that live attacks can scale and adapt at machine, rather than human, speed.

“AI is no longer just a productivity tool but a primary vector for autonomous, machine-speed attacks by both crimeware and nation-state,” said Deepen Desai, EVP cybersecurity at Zscaler. 

“In the age of agentic AI, an intrusion can move from discovery to lateral movement to data theft in minutes, rendering traditional defences obsolete.”

Tom Quinn

Staff Writer, DIGIT

Latest News

AI

Nvidia Launches Open Secure AI Alliance for AI Safety and Security

AI Business Recruitment

Nearly a Quarter of Orgs Reducing Entry-level Hiring Due to AI Automation

Business

Scottish Businesses Turn to Self-funding as Growth Confidence Dips in H2

Data Finance

Payment Leaders are Struggling to Get Real-time Data