Organizations are accelerating the adoption of generative AI, AI agents, and large language models (LLMs), but security controls are struggling to keep pace, according to Radware's 2026 Cyber Survey: New Trends in AI, API and Application Security. Conducted by Osterman Research on behalf of Radware, the global survey highlights growing visibility gaps across AI, APIs, and applications, exposing businesses to increasingly sophisticated AI-driven cyber threats.
Radware released findings from its latest cybersecurity survey, revealing that enterprises are embracing AI technologies faster than they are implementing the security controls needed to protect them.
As organizations expand their use of generative AI, large language models, autonomous workflows, and AI agents, cybercriminals are increasingly leveraging AI to identify vulnerabilities, bypass defenses, and automate attacks. According to the survey, many organizations lack sufficient visibility into these emerging AI environments, making effective governance and threat detection more challenging.
"The emerging AI layer presents a new set of security challenges that may not be addressed with isolated point solutions," said Connie Stack, chief growth officer, Radware. "Organizations need visibility across AI, applications and APIs to identify and respond to emerging threats faster."
The research found that 83% of organizations have broadly adopted generative AI or LLM capabilities, while 96% expect to implement AI agents or autonomous workflows within the next year.
Despite rapid adoption, only 17% reported having complete visibility into AI agents and AI-driven business processes.
The survey also identified growing concerns around AI crawler traffic. While organizations increasingly encounter AI-powered crawlers and automated agents, only 14% have full visibility into this activity, and 76% reported experiencing negative impacts from AI crawlers or AI agents.
The report found that software development teams continue releasing APIs at a rapid pace, with 48% of organizations updating production APIs daily or more frequently.
However, API security practices have not advanced at the same rate. Only 19% maintain a fully automated and continuously updated API inventory, while just 24% perform comprehensive API security testing throughout the development lifecycle.
These gaps increase organizational exposure as APIs continue serving as critical entry points for enterprise applications and AI-powered services.
Application-layer attacks remain a significant operational concern, according to the survey.
Seventy-one percent of organizations experience application-layer or API-targeted distributed denial-of-service (DDoS) attacks at least once per month.
The average cost of downtime resulting from an application-layer DDoS attack has increased 23% year over year to $7,530 per minute, or approximately $451,800 per hour, highlighting the growing financial impact of application security incidents.
Meanwhile, only 21% of organizations consider themselves highly prepared to manage application security incidents, and the average time required to resolve major API, bot, or DDoS attacks remains 2.8 hours.
The findings underscore the need for organizations to improve security visibility, governance, and coordinated protection across AI systems, APIs, and enterprise applications as AI-driven cyber threats continue to evolve.
The 2026 Cyber Survey: New Trends in AI, API and Application Security is based on research conducted by Osterman Research among 377 organizations worldwide. Radware will also host a webinar on July 30 to discuss the survey findings, emerging cybersecurity trends, and recommendations for strengthening AI, API, and application security.
About Radware
Radware® is a global leader in application security and delivery solutions for multi-cloud environments. The company’s cloud application, infrastructure, API, and AI security solutions use AI-driven algorithms for precise, behavior-based, real-time protection against sophisticated web, application, and DDoS attacks, API abuse, business logic threats, and malicious bots. Radware delivers end-to-end API security, including discovery, posture management, testing, and runtime protection, along with advanced protection for AI agents and models. Enterprises and carriers worldwide rely on Radware to address evolving cyberthreats, protect their brands and business operations, and reduce costs. For more information, please visit the Radware website.