Key Takeaways
A new report on AI-native application security reveals that the rapid integration of artificial intelligence in enterprise environments is creating critical security blind spots. The report, which surveyed 500 security practitioners, indicates that 63% believe AI-native applications are more susceptible to threats than traditional applications.
This rush to adopt LLMs and generative AI has outpaced the capabilities of security teams, leaving organizations exposed to a new class of vulnerabilities.Â
According to the "State of AI-Native Application Security 2025" report from Harness, on average, 61% of new applications are designed with AI components.
The proliferation of unauthorized AI use, termed "shadow AI," is a primary concern. The research found that 75% of security leaders believe the security issues caused by shadow AI risks will soon eclipse those of shadow IT.Â
This is compounded by a lack of visibility, as 62% of security teams have no way to track where LLMs are deployed within their infrastructure. This creates a significant blind spot, making it difficult to monitor API traffic, data flows, and access controls for AI components.Â
The report highlights a significant breakdown in collaboration between development and security teams, which exacerbates security risks. A majority of respondents (74%) stated that developers often view security as a blocker to innovation, leading them to bypass established governance processes, which contributes to the rise of shadow AI..
The report notes that most organizations have already suffered security incidents related to LLM vulnerabilities, including prompt injection (76%), vulnerable code (66%), and jailbreaking (65%).
Furthermore, only 43% of organizations report that their developers consistently build AI-native applications with security integrated from the start. This points to a critical need for implementing DevSecOps for AI:
These findings align with other reports that recently highlighted that security gaps force firms to rethink AI adoption, cloud adoption outpaces security readiness, and API security lags as AI adoption accelerates.
The most recent report warned that 65% of the top AI 50 companies leaked sensitive data on GitHub, including API keys and tokens.