The recorded count of AI vulnerabilities in machine learning tools and large language models grew tenfold between late 2025 and mid-2026, according to data from cybersecurity firm Kaspersky. The quarterly exploits and vulnerabilities study showed that recorded flaws in artificial intelligence platforms reached 935 in the second quarter of 2026, up from the baseline in late 2025.

Surge in Recorded AI Vulnerabilities

Security researchers found that critical vulnerabilities alone reached 119 in the second quarter of 2026. This figure represents an increase of almost five times compared to records from the fourth quarter of 2025. Consequently, the rapid deployment of automated systems has exposed software weaknesses across diverse enterprise environments.

Data chart showing the increase in AI vulnerabilities across enterprise platforms

The research identified several key categories of weaknesses within AI systems. Specifically, the primary issues involve weak access-control mechanisms for critical system objects, improper implementation of authentication and authorization protocols, and injection vulnerabilities that target model logic.

“Tools, plugins, and AI technologies help to effectively automate tasks, but the rapid adoption of AI across organizations is creating new security challenges. Weaknesses in access-control, authentication, and injection handling are emerging as the most frequent vulnerability types. To stay protected, organizations need real-time visibility into their infrastructure and access controls, not just traditional patch-management, so they can detect and stop threats at the right moment.”

Alexander Kolesnikov, Malware Expert at Kaspersky

Targeted Threats Facing Small Businesses

In addition to flaws in core software, malicious actors increasingly target corporate users through spoofed applications. The Kaspersky report on small and medium-sized businesses noted that security tools detected more than 33,300 attacks during the first four months of 2026 where malicious or unwanted software was disguised as popular AI services. This represents a fivefold surge compared to the same period in 2025.

These developments impact organizations investing in artificial intelligence solutions to automate workflows. Meanwhile, enterprise teams operating in the business sector must address these risks directly to protect proprietary data assets.

Mitigation and Infrastructure Defense

To mitigate risks related to AI vulnerabilities, Kaspersky recommends organizations deploy specialized defenses. Modern corporate networks require continuous monitoring and proactive inspection across software stacks rather than relying solely on periodic patching.

Security solutions such as the Kaspersky Next product line provide continuous visibility and threat response capabilities to keep technical setups secure. More organizations are integrating cybersecurity defenses to safeguard operational systems and user data.

Outlook for Enterprise AI Security

As enterprises continue integrating digital assistants and language models into production systems, vulnerability discovery rates are expected to remain high. Organizations will need to adjust access control policies and monitor third-party plugins to maintain resilient defenses against emerging technical threats.