Futurum Research Finds API and AI Risks Top Application Security Concerns
Austin, Texas, USA
Fernando Montenegro, VP at Futurum, shares new research revealing that API security and AI-driven risks are the top challenges for application security teams as they navigate complex cloud-native environments.
Futurum's Fernando Montenegro,
Cite this
Fernando Montenegro, The Futurum Group, "Futurum Research Finds API and AI Risks Top Application Security Concerns," April 23, 2026. https://preview.erikbethke.com/press-release/futurum-research-finds-api-and-ai-risks-top-application-security-concerns/

Austin, Texas, USA, April 23, 2026
Organizations Grapple with a Broad Spectrum of Application Threats as Innovation Outpaces Traditional Security Frameworks
New research from Futurum Intelligence reveals that while artificial intelligence (AI) is a critical priority for modern enterprises, the challenges facing application security teams are increasingly diverse. Findings from the 2H 2025 Cybersecurity Decision Maker Survey indicate that security leaders are balancing the need to secure emerging AI workloads with long-standing requirements for API governance and the complexities of cloud-native environments.
The study highlights that API security and governance remain the most significant hurdles, followed closely by the management of risks associated with Generative AI and agentic flows. This suggests that as organizations decentralize their application architectures, the interfaces connecting them have become primary points of vulnerability.
Figure 1: Top 5 Key Challenges in Application Security

Beyond the AI Hype: The Breadth of Modern AppSec
The data underscores a strategic tension for security organizations. While the rapid adoption of AI and machine learning (ML) has introduced numerous complex threat vectors, such as data poisoning, manipulation of generative outputs, and significant concerns about agentic workloads, foundational issues, such as vulnerability prioritization at scale, continue to strain limited staff resources. Organizations are finding that traditional security tools often lack the visibility needed to effectively secure containerized applications and automated CI/CD pipelines.
Balancing Innovation with Operational Oversight
The focus on API governance reflects the growing complexity of the modern digital ecosystem. As the “feel” of security becomes an operational priority, leaders are moving toward architectures that offer better integration and transparency. The research indicates that for application security to be effective, it cannot exist in a silo; it must be seamlessly integrated into the development lifecycle without creating friction for engineering teams.
“These responses indicate the immense breadth of the challenge facing organizations today, extending well above and beyond the immediate concerns of AI,” stated Fernando Montenegro, Vice President and Practice Lead at Futurum. “While we may legitimately look to AI to help automate defenses and prioritize vulnerabilities, security leaders shouldn’t lose sight of the big picture. Effective application security requires a holistic approach that addresses the entire lifecycle, from the APIs that connect our services to the automated pipelines that deploy them.”
About Futurum Intelligence for Market Leaders
Futurum Intelligence’s Cybersecurity and Resilience IQ service provides actionable insight from analysts, reports, and interactive visualization datasets, helping leaders drive their organizations through transformation and business growth. Subscribers can log into the platform at https://app.futurumgroup.com/, and non-subscribers can find additional information at Futurum Intelligence.
Follow news and updates from Futurum on X and LinkedIn using #Futurum. Visit the Futurum Newsroom for more information and insights.
Other Insights from Futurum:
Anthropic Glasswing: AI Vulnerability Detection Has Crossed a Threshold
RSAC 2026: The AI ‘Tragedy of the Commons’ and the Future of Agentic Security
Futurum Research Finds Threats and Skills Shortages Dominate SOC Challenges
Published by Futurum.
More from Fernando Montenegro
Why AI Learned to Attack Before It Learned to Defend
Fernando Montenegro, VP & Practice Lead at Futurum, shares his insights on how offensive AI succeeds because it’s easier to verify than defensive security, shifting the need for vendors to sell proof of exploitability over volume.
Can Frontier Virtual Patching Close the AI Exposure Gap?
Fernando Montenegro, VP at The Futurum Group, shares insights on how Palo Alto Networks connects AI vulnerability discovery with pre-disclosure network protection.
Brinqa Buys PlexTrac to Put Proof Behind Exposure Management
Fernando Montenegro, VP at Futurum, analyzes Brinqa’s acquisition of PlexTrac and what adding offensive security validation to an exposure management platform does, and does not, prove about remediation.