New research from Absolute Security shows that endpoint security software fails to protect enterprise devices nearly 21% of the time, leaving cyber-criminals with the equivalent of 76 days of open access to company PCs every year.
According to the cyber firm’s 2026 Resilience Risk Index, that gap is contributing to $400 billion in annual downtime losses and average revenue losses of $49 million, a problem set to worsen as firms fall behind in applying critical patches to ageing software.
By analysing telemetry across millions of endpoint devices, Absolute found that 10% of enterprise PCs are still running on Windows 10, despite Microsoft having ended support for the OS last October.
Critical OS patching across PCs running Windows 10 and 11 is behind an average of 127 days, a sharp increase from 2025, when overall patching lagged just 56 days.
Further, around one in five enterprise devices operate outside a fully protected and enforceable state. Overall device integrity has slipped, too, falling from 64% in 2025 to just 55%, meaning nearly half of all devices are now operating without complete security controls in place.
This has left these devices highly vulnerable to evolving threats and attacks, especially zero-day attacks, ransomware, and AI-driven assaults, a particularly pressing concern given that a small number of PC users continue to engage with high-risk genAI sites like DeepSeek.
However, most are sticking to the relatively safer ChatGPT, which still dominates enterprise AI traffic, accounting for 78% of all genAI use, though traffic to Google’s Gemini web app has shot up from 0% last year to over 16%, evidence that workers are exploring alternatives.
Absolute found that more than 99% of enterprise devices are accessing genAI platforms through the web, with the number of browser sessions observed spiking from 150 million to 350 million year-over-year.
While that lowers the risk of unmanaged software installations, it also limits visibility and allows AI use to expand outside of control policies – putting corporate data, IP, and sensitive documents at risk if users are not security aware.
The report warns that with security software failing 20% of the time, more AI use will accelerate failure where fragility already exists, increasing the speed of disruption.
This could prove to be a costly long-term issue, given that endpoint devices are rapidly becoming the new AI platform. In 2025, Absolute found that 68% of PCs had enough RAM to fully take advantage of AI (16-32 GB), but this year, enterprises are ramping up investment in AI-ready devices, with 96% now equipped with 16-32 GB.
In practical terms, that makes most enterprise PCs capable of running AI workloads locally, a trend set to continue as chip makers launch dedicated AI accelerators baked into hardware, which, as well as faster performance and lower latency, means that, theoretically, sensitive data never leaves the machine.
Recommended reading
- PwC Interview | How Agentic AI is Reshaping Business
- Report: 1.5 Million Enterprise AI Agents At Risk of ‘Going Rogue’
- Will AI Agents Be the Enterprise Disruptor of 2026?
But with AI now running directly on company laptops, desktops, and devices, the security risks have shifted. Across all industries, 20% of connected devices store sensitive data, with 30% lacking encryption, and 25% unaccounted for, all having risen since last year.
“The cybersecurity industry has rushed to provide innovations that detect and prevent threats; unfortunately, it’s lagging when it comes to ensuring that tools can remain operational when they are needed most,” said Christy Wyatt, president and CEO of Absolute Security.
“Enterprise security, risk, and business leaders that are working together to ensure their critical defences remain resilient under any conditions will avoid falling victim to the downtime era.”





