99.9% of Fixable AI Vulnerabilities Remain Unpatched, Exposing Cloud AI Deployments to Exploitation
What Happened — Orca Security’s 2026 State of AI Security Report found that 81.2 % of organizations running AI workloads have at least one known vulnerability and that 99.9 % of fixable AI‑related alerts remain unpatched. The study also highlighted low adoption of customer‑managed encryption keys and the proliferation of non‑human agent identities that broaden the attack surface.
Why It Matters for Compliance & Audit Readiness
- Unpatched vulnerabilities directly violate SOC 2 CC6.1 (System Operations) and CC7.1 (Change Management) requirements for timely remediation of known security flaws.
- The lack of continuous evidence that patches have been applied makes it difficult to demonstrate a defensible audit trail to examiners.
- Mapping AI‑specific assets to control frameworks and automating patch verification provides the continuous‑compliance evidence that SOC 2 auditors expect.
Who Is Affected – Cloud‑native technology firms, SaaS providers, and any organization that embeds AI models, agent frameworks, or vector databases into production workloads.
Recommended Actions
- Create an inventory of all AI packages, agent frameworks, and model‑hosting services.
- Map each AI component to SOC 2 control requirements (CC6.1, CC7.1, CC5.1).
- Deploy automated patch‑management tooling that captures immutable evidence of remediation for audit purposes.
- Enable customer‑managed encryption keys for AI services where available.
- Incorporate AI‑specific risk items into your continuous‑monitoring dashboard. Source: Help Net Security
Technical Notes
- Attack surface expands across five AI‑stack layers: package registries, model hubs, developer tools, agent frameworks, and brand‑trust services.
- 74.1 % of surveyed firms host at least one critical CVE in their AI packages, many of which are older than five years.
- Lack of encryption‑key management (87‑98 % of firms) adds data‑confidentiality risk. Source: same article