ExtraHop®, a leader in cloud-native network detection and response (NDR), has released findings from its 2026 Global Threat Landscape Report, revealing an overwhelming 83% of UK organisations have battled security incidents, data exposures, or "near-misses" rooted in AI systems over the past 12 months.As artificial intelligence rapidly integrates into corporate infrastructure, the report exposes how AI has transitioned from a theoretical risk to an active, chaotic battleground for UK enterprises.The new attack surfaceWhen asked to identify the single most significant cybersecurity risk to their organisation, more than half of UK IT and security leaders, 56%, pointed directly to AI agents, agentic infrastructure and Generative AI applications.The autonomy given to AI agents, designed to make decisions and execute tasks independently, coupled with the widespread use of Gen AI across the workforce, has created a complex, high-velocity attack surface that traditional security tools are struggling to defend.A mass of near-misses and a concerning blind spotThe scale of the issue is laid bare by how few organisations have managed to escape AI-driven fallout, as UK organisations experienced incidents, data exposures, or "near-misses" such as AI-enhanced external attacks (34%), compromised AI identity & session theft (32%), and shadow AI exposure (28%). Only 6% of UK organisations stated with absolute certainty they did not experience an AI-related security incident or data exposure in the last year. This raises critical questions about whether UK businesses lack the specialised visibility and context required to definitively determine if AI was the driver behind a breach."AI is moving faster than the defenses built to contain it," said Jamie Moles, Senior Technical Manager at ExtraHop. "When a majority of UK businesses are hitting tripwires with AI incidents and near-misses, it’s a clear signal that organisations are flying blind. Security teams are reacting to AI-driven threats and data leaks after the fact, rather than seeing them in real-time. If you don't have deep, network-level visibility into how AI traffic and autonomous agents are behaving, you aren't managing risk - you're just waiting for the next incident to happen."NoYesCybersecurity22 Jul, 2026