Wiz Research shows in the report State of AI in the Cloud 2026 that AI usage in cloud environments is becoming increasingly fragmented. 68 percent of AI usage in the cloud occurs indirectly via third-party software and outside of organizations' visibility.
AI has rapidly evolved from an experimental technology to a fundamental part of the cloud, but many organizations are losing sight of the big picture. The new report State of AI in the Cloud 2026 from the cloud security company Wiz shows that more than eight in ten (81%) organizations now use managed AI services, while 90 percent run AI software hosted on-premises. However, because organizations also use AI models indirectly through third-party software, they can inadvertently inherit model risks and vulnerabilities in the supply chain, without this being consciously implemented or subject to any central governance.

AI is now part of the cloud infrastructure
The survey shows that AI is now present in virtually every layer of the cloud stack. AI is no longer a standalone tool, but a fundamental layer built into cloud environments, development flows, and automation tools.
The use of AI extends beyond direct implementation: three in five (63%) of organizations have self-hosted AI models. Of these, nearly seven in ten (68%) use such models (partially) via third-party software, while 18 percent rely entirely on these indirect AI components. While AI is becoming standard in cloud software and development tools, organizations are increasingly acquiring AI capabilities through vendors and integrations. The security focus is therefore shifting from what is explicitly implemented to what is active in the broader application ecosystem.
AI-assisted development has become standard
AI-assisted development is now an established part of software development. At least 80 percent of organizations use AI add-ons for integrated development environments (IDEs), and 71 percent have one or more AI-based code assistants active in their development environments.
The adoption of these tools is often fragmented and bottom-up, with developers adding tools outside of central governance processes. According to Wiz, this is increasingly leading to various forms of ”shadow AI” in development environments. This fragmentation increases the complexity for security teams, who must manage multiple AI systems that impact code generation, often without consistent policies, review processes, or telemetry data.
Additionally, AI-generated code can pose structural security risks. According to the survey, about one in five organizations using AI-powered code generation platforms have had to deal with applications affected by systematic security issues. According to Wiz, the risk lies not in the existence of code assistants, but in the fact that they can scale up insecure patterns as effectively as they increase productivity.

Fragmented adoption of AI agents
Organizations are increasingly implementing Model Context Protocol (MCP) agents and servers to orchestrate AI interactions with systems and data, marking a shift from AI assisting humans to autonomous AI systems that can act independently in diverse environments.
Wiz Research finds that well over half (57%) of organizations have implemented at least one self-hosted AI agent technology. This indicates strong early adoption of a category that was largely absent just a year ago. Agent frameworks are primarily used to automate development work, connect AI systems to external tools, and coordinate workflows across multiple services.
The adoption of AI agents is fragmented. Wiz Research sees a wide range of agent frameworks and implementations in different environments, with no single dominant framework having established itself. This diversity reflects a rapidly changing ecosystem where organizations are exploring different approaches to agent design, tools, and integrations rather than striving for a common standard.
MCP servers are also rapidly gaining traction, but with a slightly different adoption pattern. According to Wiz Research, MCP servers are now present in 80 percent of cloud environments. Within this group, five percent of environments have at least one MCP server accessible via the internet, indicating an early but significant risk when the orchestration infrastructure is put into production.
“AI is already embedded in development workflows, orchestration layers, and production infrastructure. The challenge for security leaders is to maintain visibility and control over how AI is being used and how the technology is reshaping cloud environments,” says Jesper Rellme, Manager Solutions Engineering at Wiz.
“Successful organizations are those that view AI security as an extension of cloud security, rather than a separate discipline. Understanding where AI is running, how it connects to data, identities and automation, and how these connections can be leveraged is now critical to managing cloud risk, as AI continues to transform the cloud operating model.”
The entire survey is available here.
Read more about Wiz here.
Methodology
This report is based on analysis conducted by Wiz Research across hundreds of thousands of real-world cloud environments in 2025, across leading cloud providers and across a broad range of industries. The findings are based on a combination of anonymized metadata from cloud configurations, mapping of AI-related assets, and hands-on security research. The analysis is also supplemented with publicly known incidents and threat intelligence from external sources.








