2025 Cloud AI Risk Report- Helping You Build More Secure AI Models in the Cloud | RSAC Virtual 2025
The 2025 Cloud AI risk report reveals trends in AI adoption and the associated challenges organizations face. It emphasizes the need to understand AI workloads, which can introduce vulnerabilities. Major risks include critical vulnerabilities, public access issues, and misconfigurations. Organizations are urged to adopt best practices like visibility into AI usage and least privilege access controls to enhance their security posture.
Transcript
Hi everyone. Thanks for joining us today. Today we're gonna be talking about insights from our 2025 Cloud AI risk report.
Uh, to begin with a quick introductions. My name is Franklin Wynn. I am a product marketer here at Tenable, supporting our Tenable cloud security solution.
Joining me today is Damien Lim. Uh, would you like to introduce yourself, yourself, Damien? Yeah, sure.
Hi, my name is Damien. I am the AI evangelist at Tenable. Um, so glad to be here.
Awesome, thanks, Damian. So what are we gonna be discussing today? I did mention it earlier, but to double click on that today we're gonna be, uh, talking about trends.
So AI adoption and some of the challenges that organizations face. Uh, we're also going to share AI risks insights from our report. And in addition to that, share some best practices to better secure yourself against threat actors.
So with that, why don't you go ahead and jump in. So to quickly level set, what are we gonna be talking about when it comes to ai? We're gonna be talking about how to secure, uh, organizations as they leverage AI services in the cloud or AI tools to integrate into their existing products or build their own LLMs.
Uh, we will also touch briefly on how organizations can also secure themselves when individuals in the organization may be using end user AI tools such as chat, GBT. So AI cloud services and related solutions use. So our insights today will focus on risks organizations face and safety measures organizations can take when they use AI and AI related services to build or incorporate AI into their own services.
So what does this look like? Well, at a high level, we're gonna be touching on three different areas. Uh, the first is AI workloads.
So organizations obviously are gonna be leveraging out of box AI services provided by cloud service providers such as a s Azure and Google. Uh, they're going to be training these models using data that they have stored in S3 buckets, for example. And they may also be using, uh, AI software that's deployed on their virtual machines or leveraging ai uh, libraries, right?
So these are three fundamental areas that we're going to be addressing and some risks that we found within all three of these areas. Okay, so with that, first, let's take a look at what are we seeing in the market. So according to McKinsey, organizations across the globe, across industries are beginning to use AI more significantly than in the past.
Um, in 2024, it's grown significantly more, and I believe, and I believe my peer over here believes as well that it's gonna continue to move up into the right. Additionally, according to our report, uh, we do see a growing trend, as I mentioned earlier, of organizations using cloud AI services. And as you can see, it's across the board from Google to Azure.
Organizations are beginning to incorporate these tools, uh, out of the box to help them build and deploy AI workloads and services. Uh, anything else you'd like to add, Damian? No, I, I think, um, you know, as we see the adoption of, um, ai, uh, in terms of development, uh, we're gonna see a lot of traction across these different services that, uh, Franklin just mentioned, uh, just because it gets, uh, gets most organizations, uh, quicker to the market.
So we definitely will see, um, those numbers increase, uh, as, as this journey continues on. Great, thanks Damian. So, yeah, a lot of organizations are beginning to use AI more significantly than in the past, but as you can imagine, uh, with great technology comes great responsibility.
Okay, so what do I mean by this? So first, let's take a look at this, uh, Jenga step. Now imagine this is your organization, and as you begin to introduce new technologies such as ai, uh, you are opening yourselves up to new types of risks.
Uh, so what are some of these types of risks? Uh, we see and find critical vulnerabilities, uh, public access, overprivileged access, and misconfigurations as types of risks that organizations face across the board, but become more prevalent with the indirect, with the introduction of new, uh, technologies such as ai. And as you are using AI and AI services and you introduce yourself to these types of risks, you may begin to potentially open yourselves up to the risk of attack by a threat actor.
And while taken separately, these risks may not pose a significant threat collectively. Uh, they may become what we call a toxic combination. For example, imagining yourself having a workload deployed with AI libraries, and that workload has a critical vulnerability.
In addition to that, imagine that it has public public access, so it's misconfigured. And finally, it's able to, to access other types of workloads and services within your organization, let's say to an SG bucket that has sensitive data. Now, collectively, this is a prime target for a threat actor.
So if they're able to, if compromise this workload, uh, they have now access to your organization. They have the ability to exfiltrate data, they have the ability to conduct a ransomware attack. And what does this mean?
This means that your organization can be compromised. Uh, and theoretically, obviously, uh, this can take place, but we'll put more substance behind that when I pass it along to a gaming who will provide specific, uh, accounts, uh, of vulnerabilities that we found. The next question is, why are we seeing more risks related to, uh, ai?
Well, again, with any new technology, uh, organizations are gonna begin to rush to use it, right? And because of the maturity level of the organization and the maturity level of the solutions themselves, uh, we find that, uh, new types of vulnerabilities may emerge that organizations may not be aware of that the, um, that, that they will need to resolve. Right?
And in addition to that, there's a, there's this ongoing pressure, uh, within organizations to, uh, win market share as it as it relates to ai. So with that pressure and with that rush to the market, uh, speed becomes critical and they may put to the side guardrails being built to secure, um, the AI services and tools that they're beginning to build. Uh, anything you'd like to add to that, Ian?
No, I, I think this is great and, um, you know, I'm gonna spend a little bit more time in discussing how some of these, uh, exposures, if you will, uh, can generate, you know, uh, bigger risk. Great. So with that, I'll go ahead and pass it off to Dan, who will, uh, double click on some of the insights that we found, uh, in our report.
Thank you so much Franklin. Um, and what we've found right from the AI risk report that, uh, we've, uh, looked into, uh, from a threat research perspective, uh, we've actually found that 70% of the AI workloads had at least one critical vulnerability versus 50% in non-AI workloads. And why is that?
Because if you look at the AI workloads, uh, they typically rely very heavily on open source components such as, uh, or TensorFlow. So that makes them inherently vulnerable to unpatched security flaws. Now, unlike the traditional workloads, AI models often incorporate multiple libraries frameworks and dependencies that if left on patch could expose organizations to significant security risks.
And the consequence, uh, could be and range from data corruption to the insertion of back doors into AI loads and AI models themselves. If we take a look at coal, uh, what we've found, uh, we, and analyzing this particular, um, vulnerability, CVE 20 23 38 5 4 5, uh, related to a heap buffer overflow, uh, remained on patch for over a year. So this leaves the critical AI infrastructure at risk.
And with that, attackers could exploit this vulnerability to gain unauthorized access, extract model data, and even temper with AI training pipelines. And if we take another example this time regarding the AI models themselves, and this example is the WAN who chat G-P-T-C-V-E 20 24, 32 34 is actually categorized as a critical vulnerability. Now, this allow attackers to steal sensitive files because the application used an outdated vulnerable iteration of the Grado open source Python package.
Now the key takeaway here is that AI workloads introduce unique vulnerabilities that organizations must monitor and patch just like any other critical infrastructure enterprise application, and its, uh, dependencies. When we talk about AI security, we often think of model integrity, but data exposure is an even bigger risk. AI workloads rely on massive data dataset, and if that data is not secured, uh, it can lead to inter intellectual property theft compliance violations and regulatory fines.
But before we dive in, uh, for those who are not familiar, uh, AWS bedrock is focused on generative AI using prebuilt foundation models. Example like Claude Llama and through an API, without having to manage any of the infrastructure or train your own models. Now, with that said, what we found is one of the most common risks that we found is storage misconfiguration.
3% of that training data has, uh, public access disabled. So this means that this confidential model training data, um, you know, within this particular storage, uh, could be accidentally exposed to the internet or create an opportunity to poison its data. And furthermore, overprivileged policies are another major concern.
In bedrock, 5% of organizations have at least one over permissive bucket. So if an attacker gains access to an AI storage bucket with weak permissions, they could still training data and use it to replicate, uh, proprietary models inject poison data to manipulate AI decision making processes, delete or modify AI training data sets leading to a skewed model output. And lastly, in AWS SageMaker, we found that 90% of organizations left SageMaker notebook instances with root access enabled, and with root access, users can manipulate Exfiltrate AI model and ip, and even the data in the S3 buckets.
Now, anticipating this question ahead of time, Amazon SageMaker is a fully managed machine learning platform that helps developers and data scientists built train and deploy ML models at scale. Now, keep in mind that AI models are built on sensitive proprietary data. So whether it's a customer data set, a financial model, or otherwise exposing this data could be devastating.
The key takeaway here is organizations must treat AI training data as a critical asset, enforcing strict access controls and ensuring that no data sets are left vulnerable to exposure. Uh, so now that we have identified some of the key risk in AI workloads mentioned earlier, let's walk through five essential best practices to secure them. Number one, gain unified visibility across AI workloads.
Now, that's the saying, right? You can't secure what you can't see so many organizations like visibility into their AI usage and AI development across the environments. The solution here is to simply deploy a AI security posture management solution, as well as any related security tools to monitor AI specific resources.
Number two, apply lease privilege access controls. We've just learned that overprivileged service accounts are one of the biggest security gaps in AI workloads. Now the solution is pretty straightforward as well Limit the access to AI models and training infrastructure following the familiar zero trust approach.
Third, circuit the AI training data and storage because we've learned as well misconfigured storage is an easy target for attackers. Remember the deep sick data leak it exposed sensitive information including chat history, security keys, and backend details. So always enforce strict access policies and disable public sharing of AI related data.
Next, prioritize AI specific vulnerability remediation. Now we know that traditional vulnerability management does not cover AI specific threats. So make sure that you implement AI risk detection to identify unpatched CVEs in machine learning frameworks such as PyTorch.
I TensorFlow further use a system that can enable teams to be strategic by prioritizing the mitigation of these vulnerabilities. And then number five, enforce and secure cloud configurations. Cloud security misconfigurations or default configuration in AI services can cascade into major security incidents, as Franklin mentioned earlier, with the Jenga concept.
So continuously monitor and remediate noncompliant AI infrastructure discovered in AWS Azure and GCP. Lastly, additional guidelines can be found in the cloud AI risk report. And feel free to peruse this resource, which will provide a link at the end of this presentation.
And I just would like to kind of leave you the key takeaway here is to understand that AI security must be proactive addressing misconfigurations and vulnerabilities and accessing risks before they're exploited. And this is where we believe that tenable solution can help. Tenable one is an AI powered exposure management platform.
One important key aspect is that it provides full visibility into the exposures across the entire attack surface, including emerging ai, very seamless integrated, uh, vulnerability management and cloud security technologies found in this platform. Now, this unique combination of AI SPM and AI aware capabilities gives you 360 degree visibility to effectively manage risk from both shadow AI as well as a in-house AI LLM model development locally and into the cloud. Now, as we, uh, wrap up, uh, today's session, I would like to leave you with this, uh, takeaway.
Uh, AI is already transforming how we operate in a modern world bus, uh, world and in our lives, but it also introduces a new attack surface in a fast moving risk landscape. So securing these workloads isn't just a technical requirement, it's actually a business imperative. And at Tenable, we believe that visibility and accountability must evolve alongside innovation.
And with the right tools and approach, you can empower your teams to safely innovate and innovate securely. So thank you for spending, uh, time with us today, and we hope this gave you new perspectives and practical next steps for your AI journey. Now, with that, I would like to also add some of these next steps, uh, for us to consider.
Uh, and if you're interested in digging a little bit more into our solutions, please visit our cloud security, um, page. Uh, the QR code is available there as well as accessing the full cloud AI risk report, uh, with the QR code, uh, provided. With that in mind, I would like to kind of leave us, uh, with some next steps, uh, for you to consider.
For example, you can go to our Tenable Cloud security, uh, page to dig a little bit more about our solutions as well as accessing the full cloud AI risk report by scanning the QR codes, uh, that we have provided. And, and with that, I'd like to again thank you all for your time and participation.