Vectra AI, the leader in AI-native security and observability, today released its 2026 State of Threat Exposure Management Report, offering new research into how AI is reshaping enterprise environments and driving the evolution of exposure management.
Based on anonymized telemetry aggregated across diverse enterprise environments, the report found that AI agents, unmanaged assets, cloud services and non-human identities are creating increasingly dynamic enterprise environments that traditional exposure management approaches cannot keep pace with. Notably, 98% of analyzed environments contained at least one attacker-relevant exposure condition, underscoring the need for continuous operational visibility into what is operating, how systems interact and where risk is emerging.
“AI is fundamentally changing enterprise environments, and exposure management must evolve alongside it,” said Mark Wojtasiak, SVP of Market Research and Strategy at Vectra AI. “The findings reinforce that exposure management is no longer just about identifying vulnerabilities. It requires continuously understanding how assets, identities, AI agents and systems interact so security teams can reduce attack exposure before it becomes an incident.”
Rapidly Changing Enterprise Environments Are Creating Visibility Gaps
The report found that modern enterprise environments are changing continuously as new assets, device types, and infrastructure roles are introduced. At the same time, many of those assets remain outside the reach of traditional endpoint solutions, creating blind spots that obscure exposure and provide opportunities for attackers to operate undetected.
Key findings include:
- 100% of analyzed environments observed newly discovered devices within 14 days
- 90% observed new device roles
- 83% observed new device types
- On average, more than 30% of enterprise devices were unmanaged because endpoint agents could not be deployed
AI Agents and Non-Human Identities Are Becoming a Material Part of the Attack Surface
As AI adoption accelerates, the report highlights how AI agents outnumber devices and how non-human identities are becoming active operational actors across enterprise environments. As these entities authenticate, move data, and trigger downstream actions, exposure management must increasingly account for AI agents, automation workflows, APIs, service accounts and other non-human identities.
Key findings include:
- The typical environment contained 1.17 AI agents per device
- The most extreme environment observed 96 AI agents to a single device
- 35% of environments contained more AI agents than devices
Attacker-Relevant Exposure Conditions Remain Widespread
Even as organizations modernize their environments and invest in new security technologies, attacker-relevant exposure conditions remain widespread. Rather than isolated vulnerabilities, organizations continue to face combinations of legacy protocols, credential risks and cryptographic weaknesses that can contribute to exploitable attack paths.
Key findings include:
- 98% of environments contained at least one attacker-relevant exposure condition
- 63% exhibited exposure across multiple risk themes, including weak cryptography, credential exposure, legacy protocols and exposed remote access
- Among the most observed conditions were deprecated TLS clients (96%), expired certificates (91%), NetBIOS (86%), plaintext passwords (85%) and deprecated TLS servers (82%)
The findings demonstrate that effective exposure management requires more than periodic assessments and static inventories. Organizations that understand how managed and unmanaged assets, identities, AI agents and systems interact will be better positioned to prioritize risk, reduce attack exposure and strengthen resilience as enterprise environments continue to evolve.
Read Also: Crowe Global Appoints Josh Cole as Growth Leader to Strengthen Cross-Network Collaboration











































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































