Sunday, 14 September 2025
27.8 C
Singapore
27.4 C
Thailand
19.7 C
Indonesia
27.6 C
Philippines

Tenable warns AI growth is outpacing cloud security readiness

Tenable warns that rapid AI adoption using open-source tools and cloud services is outpacing security, leaving organisations exposed to growing risks.

Tenable has issued a stark warning about the growing cybersecurity risks associated with rapid adoption of artificial intelligence (AI) technologies. According to the company’s new Cloud AI Risk Report 2025, organisations in the Asia-Pacific and beyond are integrating open-source AI tools and managed cloud services at a pace that far exceeds their security preparedness, potentially exposing sensitive data and AI models to significant threats.

The report highlights that while businesses are eager to leverage AI for innovation and competitive advantage, they are often doing so without fully understanding the security implications. Tenable found that the widespread use of open-source packages and rapid cloud service deployment is creating systemic vulnerabilities in enterprise environments.

Widespread AI adoption lacks adequate safeguards

Tenable’s findings align with a 2024 McKinsey Global Survey which showed that 72 percent of organisations had embedded AI into at least one business function by early 2024, up from 50 percent two years earlier. However, this increased adoption has not been matched by improvements in security posture. Instead, Tenable warns that vulnerabilities, cloud misconfigurations, and exposed data are quietly accumulating.

From December 2022 to November 2024, Tenable Cloud Research analysed real-world workloads across major cloud providers including Amazon Web Services (AWS), Microsoft Azure and Google Cloud Platform (GCP). The research identified a growing dependency on open-source libraries such as Scikit-learn and Ollama, found in 28 percent and 23 percent of AI workloads respectively. While these tools accelerate machine learning development, they are also introducing hidden vulnerabilities through unverified code and complex dependency chains.

The risk is especially high in Unix-based environments, which are common in AI development. These systems often rely on open-source components that may go unpatched, creating opportunities for attackers to exploit them and gain access to sensitive data or alter AI model behaviour.

Cloud misconfigurations and excessive permissions

The report also shows that enterprises are heavily relying on managed cloud services to run AI workloads, introducing another layer of risk. In Microsoft Azure environments, 60 percent of organisations had configured Azure Cognitive Services, 40 percent used Azure Machine Learning, and 28 percent relied on Azure AI Bot Service. Similarly, on AWS, 25 percent had configured Amazon SageMaker, and 20 percent deployed Amazon Bedrock. GCP’s Vertex AI Workbench appeared in 20 percent of workloads.

While these tools support innovation at scale, their default configurations can lead to poor security practices. Many organisations unknowingly grant excessive permissions or fail to adjust permissive default settings, making it easier for attackers to access or manipulate critical AI systems and training data.

Nigel Ng, Senior Vice President at Tenable APJ, cautioned, “Organisations are rapidly adopting open-source AI frameworks and cloud services to accelerate innovation, but few are pausing to assess the security impact. The very openness and flexibility that make these tools powerful also create pathways for attackers. Without proper oversight, these hidden exposures could erode trust in AI-driven outcomes and compromise the competitive advantage businesses are chasing.”

Managing AI risk with strategic oversight

To address the risks, Tenable recommends a multi-layered approach. This includes managing AI exposure holistically by continuously monitoring infrastructure, workloads and identities; treating AI assets such as models and datasets as sensitive; enforcing least-privilege access controls; and staying updated on AI regulations and security frameworks like the NIST AI Risk Management Framework.

The company also advises organisations to prioritise remediation of critical vulnerabilities using tools that streamline alerts and improve remediation efficiency. Aligning cloud configurations with provider security recommendations is equally important, especially since many default settings are overly permissive.

Ng added, “AI will shape the future of business, but only if it is built on a secure foundation. Open-source tools and cloud services are essential, but they must be managed with care. Without visibility into what is being deployed and how it is configured, organisations risk losing control of their AI environments and the outcomes those systems produce.”

Hot this week

XPENG highlights AI-powered mobility at IAA Mobility 2025

XPENG unveils AI cars, flying vehicles, and robots at IAA Mobility 2025, with plans for Level 4 autonomous cars and a European R&D centre.

Apple unveils iPhone Air, its thinnest smartphone yet

Apple unveils the iPhone Air, its thinnest smartphone yet, featuring a 48MP Fusion camera, A19 Pro chip and all-day battery life.

Apple faces lawsuit over alleged use of pirated books for AI training

Apple faces a lawsuit from authors alleging it used pirated books to train AI models, sparking fresh debate on copyright and AI.

Apple introduces Watch SE 3 with major upgrades

Apple launches the Watch SE 3 with a faster chip, always-on display, new health tools, and 5G connectivity from 19 September.

ASUS routers dominate PCMag awards with record wins

ASUS routers win big at the 2025 PCMag Readers’ and Business Choice awards, sweeping all major home and office networking categories.

Asus unveils US$4,000 ProArt P16 with 4K tandem OLED and RTX 5090

Asus launches its ProArt P16 laptop with a 4K tandem OLED, RTX 5090 GPU, and creator-focused features, priced from US$1,999.

Lenovo unveils Legion Go 2 handheld with OLED display and higher price tag

Lenovo launches the Legion Go 2 handheld with an OLED display, upgraded specs and a higher starting price of €999 at IFA 2025.

Samsung could launch two Galaxy Z Fold8 models in 2026

Samsung may release two Galaxy Z Fold8 models in 2026, including one with a square-like screen, alongside the Galaxy Z Flip8.

Apple brings new health features to older Watch models

Apple adds hypertension notifications and Sleep Score to older Watch models with watchOS 26, expanding health tools beyond its newest devices.

Related Articles

Popular Categories