Artificial intelligence has emerged as a top cloud security concern alongside longstanding problems involving identity and access management, third-party resources and APIs, according to the Cloud Security Alliance’s “Top Threats to Cloud Computing Survey Report 2026.”
Based on a survey of 507 security professionals, inadequate identity and access management (IAM) ranks as the top concern, while AI-enhanced attacks debuted at No. 2. Insecure third-party resources rank third, followed by insecure interfaces and APIs and misconfiguration and inadequate change control. A second new AI category, AI system compromise, ranks sixth.
The rankings reflect organizations’ growing reliance on AI, APIs, third-party services and automation as they seek to move faster and connect more business processes, explained Michael Roza, a CSA Research Fellow, co-chair of the Top Threats Working Group and a lead author of the report.
“Each choice changes the security problem,” Roza said. “More automation creates more non-human identities that have to be managed. More APIs create more connections and paths into systems. Greater use of third parties puts more data and business processes outside an organization’s direct control.”
Every service, API, workload, AI agent and automated process requires authentication and some level of permission, Roza said. As those identities multiply, organizations face greater difficulty determining what has access, whether that access remains necessary and how it is being used.
Andy Ruth, a research analyst with CSA, said organizations already understand many of the measures needed to improve IAM, including multifactor authentication and moving away from passwords. Executive sponsorship and balancing security with usability remain challenges.
AI compounds the IAM challenge because non-human identities can be created, used and deleted within short periods, requiring more advanced logging and management, Ruth said.