CSA Official Press Release
Published 08/13/2026
Artificial Intelligence (AI) Emerges as an Attack Enabler and Target in Cloud Security Alliance’s 2026 Top Threats Report
Identity, AI, software supply chains, and interconnected cloud ecosystems displace traditional infrastructure as top security concerns
SEATTLE – Aug. 13, 2026 – Security practitioners are increasingly concerned about the impact of AI on cloud security, according to the findings of the Top Threats to Cloud Computing Survey Report 2026. The latest installation in the Top Threats to Cloud Computing series from the Cloud Security Alliance (CSA), the world's leading not-for-profit organization committed to AI, cloud, and Zero Trust cybersecurity education, found that traditional concerns about cloud infrastructure and cloud service providers are being displaced by those surrounding the growing influence of AI on both attack methods and defensive strategies.
The addition of two new AI-related issues — AI-Enhanced Attacks (#2), which examines the use of AI to improve or automate attacks, and AI System Compromise (#6), which addresses AI systems as assets that can be compromised, manipulated, or abused — underscores this concern. Together, they illustrate AI’s evolving role in the threat intelligence landscape as both a weapon for attackers and a target for adversaries.
“AI is not an emerging cloud security concern. It is already changing both how attacks are carried out and what organizations have to protect,” said Vic Hargrave, a lead author and chair of the Top Threats Working Group.
The 2026 Top Threats ranked the following concerns in order of significance (with applicable previous rankings from 2024). Of note, concerns related to the underlying cloud infrastructure and cloud service providers, which were featured in 2024, rated low enough to be dropped from the list.
- Inadequate Identity and Access Management (Identity & Access Management in 2024 survey) (up from #2)
- AI (Artificial Intelligence)-Enhanced Attacks (new)
- Insecure Third-Party Resources (up from #5)
- Insecure Interfaces and APIs (down from #3)
- Misconfiguration & Inadequate Change Control (down from #1)
- AI System Compromise (new)
- Advanced Persistent Threats (up from #11)
- Lacking Cloud Security Strategy & Governance (Inadequate Selection/Implementation of Cloud Security Strategy in 2024 survey/down from #4)
- Insecure Software Development (down from #6)
- Accidental Cloud Data Disclosure (down from #7)
- System Vulnerabilities (down from #8)
“The organizations most exposed to the next generation of cloud threats are not necessarily those with weak perimeter controls,” added Michael Roza, a lead author and chair of the Top Threats Working Group. “They are the ones whose governance, visibility, and change management have not kept pace with the complexity of their environments.”
The report highlights how complexity is outpacing governance. The rapid growth of non-human identities, machine-to-machine interactions, and autonomous decision-making has now surpassed what traditional management and oversight processes were designed to handle. Unsurprisingly, as organizations speed their adoption of AI, cloud services, and increasingly interconnected technologies, many of the risks outlined this year stem from the fact that organizations aren’t able to govern these new capabilities at the same pace.
In creating the Top Threats to Cloud Computing 2026 report, the Working Group conducted research in two stages, both of which used surveys to gather the thoughts and opinions of cybersecurity professionals concerning the most relevant threats, vulnerabilities, and risks of security issues to cloud computing. During the first stage the group created a short list of cloud security issues through in-person surveys of group members; the second stage polled more than 500 industry experts on a short-list of 23 security issues to compile the final report.
Each analysis describes the threat and its business impacts and provides key takeaways, anecdotes, and real-world examples, in addition to referencing the relevant section of CSA’s Security Guidance for Critical Areas of Focus in Cloud Computing v5 domain guides and mitigating controls in CSA’s Artificial Intelligence Cloud Controls Matrix v1.1 (AICM).
The CSA Top Threats Working Group aims to provide organizations with an up-to-date, expert-informed understanding of cloud security risks, threats, and vulnerabilities in order to make educated risk-management decisions regarding cloud adoption strategies. Individuals interested in becoming involved in the future research and initiatives of this group are invited to join.
About Cloud Security Alliance
The Cloud Security Alliance (CSA) is the world’s leading not-for-profit organization committed to awareness, practical implementation, and credentialing of forward-looking cybersecurity topics, including AI, cloud, and Zero Trust. In an era where digital transformation drives business success, CSA stands as the global authority ensuring organizations can operate securely while harnessing cutting-edge technology. Through the 501(c)3 CSAI Foundation, volunteer-driven research, globally-accepted standards, and award-winning vendor-neutral education programs that unite varied associations, governments, chapters, and corporate members, CSA bridges the gap between innovaion and pragmatic security execution. Visit CSA’s website to learn more.
Media Contacts
Kristina Rundquist
ZAG Communications for the CSA
[email protected]
About Cloud Security Alliance
The Cloud Security Alliance is a not-for-profit organization with a mission to promote the use of best practices for providing security assurance within Cloud Computing, and to provide education on the uses of Cloud Computing to help secure all other forms of computing. The Cloud Security Alliance is led by a broad coalition of industry practitioners, corporations, associations and other key stakeholders. For further information, follow us on Twitter @cloudsa.
For press inquiries, email Zenobia Godschalk of ZAG Communications or reach her by phone at 650.269.8315.