Artificial intelligence and machine learning (AI/ML) is no longer a new feature within enterprise environments. In 2025, they have become a persistent operating layer for running work. Developers ship faster, marketers generate more content, analysts automate research, and IT teams leverage AI to streamline troubleshooting and operations. The productivity gains are real, but so are the tradeoffs.
As AI adoption accelerates, sensitive data is flowing through an increasing number of AI-enabled applications. These systems often operate with less visibility and fewer guardrails than traditional enterprise software. At the same time, threat actors are tracking your data. The same forces that make AI more accessible with faster automation and more realistic outputs are also compressing attack timelines and making attacks harder to detect.
The newly released Zscaler ThreatLabz 2026 AI Security Report examines how enterprises are navigating this change. This report is based on an analysis of nearly 1 trillion AI and ML transactions observed across the Zscaler Zero Trust Exchange™ throughout 2025. This activity translates into hundreds of thousands of AI transactions per day per organization, providing an evidence-based view of how AI is actually used across global enterprises.
This finding confirms what many security teams already feel. AI is now embedded throughout daily workflows, governance remains uneven, and enterprise attack surfaces are growing in real time.
This blog highlights some of the most important findings and implications for security teams. The full report provides deeper analysis of risk patterns and practical guidance for enterprise leaders tasked with safely operating AI at scale.
Five key takeaways for security teams in 2025
1 – Enterprise AI adoption is rapidly accelerating and the attack surface is expanding
Enterprise AI/ML transactions grew 83% year over year in 2025. ThreatLabz’s analysis includes more than 3,400 applications that generate AI/ML traffic, nearly four times more than last year. This growth reflects how quickly AI capabilities are being incorporated into daily workflows.
Even if an individual application generates a modest amount of traffic, the impact on the entire ecosystem is significant. Risk increases with sprawl. As AI capabilities emerge across vendors and platforms, security teams inherit governance responsibilities across thousands of applications rather than a small set of standalone tools. What was once a bounded category has become a distributed system.
2 – The most commonly used AI tools are built directly into work and data flows.
While the landscape of enterprise AI adoption continues to evolve, with models like Google Gemini and Anthropic gaining traction recently, enterprise usage in 2025 remains focused on a small number of productivity layer tools. When we analyzed AI/ML activity throughout the year, the most widely used applications were Grammarly, ChatGPT, and Microsoft Copilot, reflecting how deeply AI is integrated into daily work. Codeium also ranks among the top applications by transaction volume, highlighting the growing role of AI in development workflows where proprietary code is always running.
ThreatLabz also looked at the amount of data transferred between enterprises and AI applications. In 2025, the amount of data transferred to AI tools increased by 93% year over year, totaling tens of thousands of terabytes. The same applications that drive productivity gains, from writing/editing to translation/coding, are often the ones that handle the highest volumes of sensitive corporate data, underscoring how closely connected AI adoption and data risk are.
3 – Many corporate organizations still block AI completely
Not all organizations are ready to enable pervasive AI access across their business. While overall blocks are down year-over-year, suggesting progress toward more policy-driven AI governance, enterprises still blocked 39% of all AI/ML access attempts in 2025.
This pattern reflects unresolved risks rather than resistance to AI itself. Blocking is often used when organizations lack visibility, internal guardrails, or confidence in the behavior of their AI systems once deployed at scale. ThreatLabz Red Team testing supports this warning. Every enterprise AI system tested failed at least once under realistic adversarial pressure, and the failure surfaced quickly.
Blocking may reduce exposure, but it doesn’t stop AI-driven work. Users often move to unapproved alternatives, personal accounts, or built-in AI capabilities within approved SaaS platforms, often with less visibility and control. The long-term goal is a secure enablement that enables organizations to support the use of AI while consistently managing risk.
4 – AI adoption varies widely by industry, with uneven concentration of risks
In 2025, the use of AI/ML increased across all industries, but adoption was uneven. Each sector moves at a different pace and with different levels of oversight. Finance and insurance once again generated the largest share of enterprise AI/ML activity (23.3%). Manufacturing continued to be very active at 19.5%, driven by automation, analytics, and operational workflows.
Industry context is important. In sectors where AI intersects with regulated data, operational technology, or supply chain systems, the risks to data protection and access controls are higher. The block patterns are diverse, highlighting that AI governance is not one-size-fits-all. Controls must align with industry risk profiles, compliance requirements, and operational dependencies.
5 – Threat actors are already using AI throughout the attack chain
The ThreatLabz story shows that generative AI is being actively used by adversaries to accelerate existing tactics, rather than replace them. Attackers are using AI to support initial access, social engineering, evasion, and malware development, making it difficult to distinguish malicious activity from legitimate use.
The campaigns analyzed in the report include indicators of AI-powered social engineering, fake personas, and AI-powered code generation. For defenders, this means that AI security must consider not only how employees use AI, but also how attackers use it to move quickly and blend in once they gain access.
The “hidden” growth story: Embedded AI is amplifying risk in unexpected places
Not all enterprise AI will manifest itself as a standalone generative AI usage. AI increasingly operates through built-in functionality built into everyday SaaS applications. These features are often enabled by default, run continuously in the background, and interact with corporate data without being classified or managed as AI.
Embedded AI may seem like a simple enhancement, but it often introduces new data pathways. As a result, AI can interact with a company’s sensitive content even in places that security teams don’t actively monitor or classify as an AI use. This is a growing blind spot that requires continued monitoring and significant attention from security teams and the industry at large.
How Zscaler ensures AI adoption and accelerates your AI journey
As AI becomes more embedded throughout the enterprise, from public GenAI tools to private models, pipelines, agents, and supporting infrastructure, security teams need control beyond traditional app security. You need visibility into how AI works across your systems.
Zscaler helps organizations use AI securely with protections across the AI security lifecycle.
AI asset management
Gain complete visibility into AI usage, exposure, and dependencies across applications, models, pipelines, and supporting infrastructure (such as MCP pipelines), including the AI Bill of Materials (AI-BOM). Discover your complete footprint and identify risks.
Secure access to AI
Apply fine-grained access controls for AI applications and users. Inspect prompts and responses inline To help you use AI apps safely and responsibly Prevent sensitive data from being sent to external models or returned in insecure output.
Secure AI applications and infrastructure
Protect not only the tools your employees use, but also the AI systems your business is building and deploying. This includes system hardening and runtime protection with vulnerability detection across models and pipelines, protection against common and evolving threats such as adversarial red team testing, prompt injection, data poisoning, and insecure use of sensitive information.
Get the report to stay ahead of enterprise AI risks
The ThreatLabz 2026 AI Security Report provides a data-driven view of how AI is being used across enterprise environments, where security teams are drawing the lines, and where risks are occurring. In addition to the findings highlighted here, the full report also examines leading AI applications and vendors, regional usage patterns, reveals ThreatLabz experts’ predictions for AI security in 2026, and provides additional insights and guidance.
Download the full report to explore the data, insights, and recommendations that will shape the next stage of enterprise AI security.
