AI workloads in cloud riskier than traditional with 70% containing critical vulnerabilities compared to 50% in non-AI workloads – study
Bengaluru: As enterprises scale their AI initiatives in the cloud, a new report from Tenable reveals a worrying trend: AI workloads in cloud are emerging as significantly more vulnerable than traditional cloud environments — and demand immediate attention from IT and security leadership.
Tenable’s 2025 Cloud Security Risk report finds that 70% of AI workloads across AWS, Azure, and GCP contain at least one unremediated critical vulnerability, compared to 50% in non-AI cloud environments. For CIOs and CISOs accelerating AI adoption, the message is clear: AI infrastructure isn’t just powerful — it’s uniquely exposed.
“Organisations have made real strides in tackling toxic cloud risks, but the rise of AI workloads introduces a fresh wave of complexity,” said Ari Eitan, Director of Cloud Security Research – Tenable. “AI’s data-intensive nature, combined with persistent misconfigurations and vulnerabilities, demands a new level of diligence.”
A key finding: 77% of organisations using Google’s Vertex AI Workbench had notebook instances with overprivileged default service accounts, opening the door to privilege escalation and lateral movement. These risks are amplified as enterprises increasingly run sensitive data and proprietary models in public cloud environments.
Cloud Security Maturity Is Growing — But Gaps Remain
There is progress. The report shows a decline in “toxic cloud trilogies” — workloads that are publicly exposed, critically vulnerable, and overly privileged — which fell to 29% of surveyed organisations, down from 38% in 2024. Tenable attributes this improvement to better risk prioritisation and increased deployment of cloud-native security tools.
However, identity continues to be a major blind spot. While 83% of AWS environments now use at least one identity provider (IdP), credential abuse still accounts for 22% of breach incidents — suggesting that IAM implementation alone isn’t enough without proper enforcement of MFA and least-privilege principles.
Why It Matters for IT Leaders
The findings come as India moves closer to introducing AI and cloud regulations under the forthcoming Digital India Act. But Tenable warns that regulatory compliance alone won’t shield organisations from risk.
For CIOs and CISOs, the implication is strategic: cloud AI environments require a distinct security approach — one that integrates exposure management, proactive misconfiguration monitoring, and continuous identity risk assessment into the development and deployment lifecycle.
“Exposure management gives security teams the context they need to protect what matters most, including the crown jewels hidden inside AI environments,” added Eitan.
The Bottom Line
As organisations lean into AI to drive innovation, cloud security strategies must evolve in parallel. Ignoring the unique vulnerabilities of AI workloads could leave critical assets exposed — even as broader cloud security practices show improvement.
For enterprise IT leaders, the choice is stark: embed security early in AI lifecycles — or risk setbacks that could compromise both innovation and trust.
