Artificial Intelligence (AI) Emerges as an Attack Enabler and Target in Cloud Security Alliance’s 2026 Top Threats Report
Security practitioners are increasingly concerned about the impact of AI on cloud security, according to the findings of the Top Threats to Cloud Computing Survey Report 2026. The latest installation in the Top Threats to Cloud Computing series from the Cloud Security Alliance (CSA), the world’s leading not-for-profit organization committed to AI, cloud, and Zero Trust cybersecurity education, found that traditional concerns about cloud infrastructure and cloud service providers are being displaced by those surrounding the growing influence of AI on both attack methods and defensive strategies.
The addition of two new AI-related issues — AI-Enhanced Attacks (#2), which examines the use of AI to improve or automate attacks, and AI System Compromise (#6), which addresses AI systems as assets that can be compromised, manipulated, or abused — underscores this concern. Together, they illustrate AI’s evolving role in the threat intelligence landscape as both a weapon for attackers and a target for adversaries.
“AI is not an emerging cloud security concern. It is already changing both how attacks are carried out and what organizations have to protect,” said Vic Hargrave, a lead author and chair of the Top Threats Working Group.
The 2026 Top Threats ranked the following concerns in order of significance (with applicable previous rankings from 2024). Of note, concerns related to the underlying cloud infrastructure and cloud service providers, which were featured in 2024, rated low enough to be dropped from the list.
- Inadequate Identity and Access Management (Identity & Access Management in 2024 survey) (up from #2)
- AI (Artificial Intelligence)-Enhanced Attacks (new)
- Insecure Third-Party Resources (up from #5)
- Insecure Interfaces and APIs (down from #3)
- Misconfiguration & Inadequate Change Control (down from #1)
- AI System Compromise (new)
- Advanced Persistent Threats (up from #11)
- Lacking Cloud Security Strategy & Governance (Inadequate Selection/Implementation of Cloud Security Strategy in 2024 survey/down from #4)
- Insecure Software Development (down from #6)
- Accidental Cloud Data Disclosure (down from #7)
- System Vulnerabilities (down from #8)
“The organizations most exposed to the next generation of cloud threats are not necessarily those with weak perimeter controls,” added Michael Roza, a lead author and chair of the Top Threats Working Group. “They are the ones whose governance, visibility, and change management have not kept pace with the complexity of their environments.”





