SandboxAQ: Are Enterprises Racing Into AI Without Security?

Share this article
Share this article
Prioritise Us on Google
Marc Manzano, General Manager of the Cybersecurity Group at SandboxAQ
SandboxAQ research shows 79% use AI in production but only 6% deploy comprehensive security strategies across IT systems

Enterprise organisations are implementing AI systems in production environments faster than they are securing them, according to SandboxAQ’s inaugural AI Security Benchmark Report. 

The AI startup’s research found that 79% of organisations currently operate AI in production settings, yet only 6% have established comprehensive, AI-native security strategies.

The study surveyed more than 100 senior security leaders across the United States and European Union in April 2025, examining organisations in financial services, healthcare, technology and telecommunications sectors.

Security leaders report concerns about AI-related threats, with 74% expressing high concern about AI-enhanced cyberattacks and 69% worried about AI systems discovering new vulnerabilities within their environments. However, only 28% of organisations have conducted full AI-specific security assessments, according to the survey data.

Youtube Placeholder

The report indicates that most organisations continue using rule-based security tools designed for traditional IT systems. These tools were not built to handle the dynamic, machine-speed operations that characterise AI implementations, the research notes.

SandboxAQ finds gaps in AI-native security

The survey found that 10% of companies maintain dedicated AI security teams. In the remaining 90% of organisations, responsibility for AI security falls to existing IT or security departments, according to the data.

The research identifies non-human identities as a particular security challenge. These autonomous AI agents, services and machine accounts operate independently, managing cryptographic credentials and accessing sensitive resources without human oversight. The survey indicates that most security teams lack visibility into these entities.

The report states that these non-human identities undermine Zero Trust principles and create gaps in identity governance and cryptographic hygiene. Traditional security frameworks struggle to monitor and control entities that operate at machine speed without human intervention.

Key facts
  • 79% of organisations use AI in production, but only 6% have comprehensive AI-native security
  • 74% of security leaders express high concern about AI-enhanced cyberattacks
  • Just 10% of companies maintain dedicated AI security teams

SandboxAQ reports observing similar patterns across large-scale cryptographic environments and AI deployments in its client base. The company states that enterprises struggle to apply core security practices such as automated inventory, visibility and policy enforcement to AI-dependent identities and assets.

Targeting cryptographic and identity governance issues

SandboxAQ offers AQtive Guard as a solution for organisations seeking to address cryptographic and identity governance in AI infrastructure. The company positions this product as enabling modernisation of security practices for AI environments.

Marc Manzano, General Manager of the Cybersecurity Group at SandboxAQ, explains the challenge: “This isn’t just a solution gap, it’s a conceptual one. AI is radically changing the cybersecurity paradigm at an unprecedented speed. This report highlights a growing recognition among security leaders that defending against evolving threats requires new assumptions and approaches, not just new layers or patches to current tooling.”

AI is radically changing the cybersecurity paradigm at an unprecedented speed

Marc Manzano, General Manager of the Cybersecurity Group, SandboxAQ

The research data indicates that current security architectures cannot accommodate the operational requirements of AI systems. Traditional security tools operate on rule-based logic, whilst AI systems function through machine learning models that adapt and change continuously.

The survey results show that organisations lack adequate protection for machine learning models, training data and inference pipelines. These components form the core of AI implementations but remain outside the scope of conventional security frameworks.

Investment in AI security increases across enterprise sectors

The survey data shows that 85% of organisations plan to increase AI security spending within the next 12 to 24 months. Of these, 25% indicate they will make significant budget increases for AI security initiatives.

Investment priorities identified in the research include protecting training data and inference pipelines, securing non-human identities and deploying automated incident response capabilities designed for AI-driven infrastructure. These areas correspond to the security gaps identified in the survey.

SandboxAQ operates as a B2B company delivering solutions combining AI and quantum techniques

The research focused on highly regulated sectors where security requirements often exceed baseline industry standards. These sectors face regulatory compliance requirements alongside the technical challenges of securing AI implementations.

GLG Insights conducted the survey data collection, gathering responses from security leaders across multiple geographic regions and industry sectors. The methodology targeted organisations actively running AI systems in production environments.

SandboxAQ operates as a B2B company delivering solutions combining AI and quantum techniques. The company emerged from Alphabet Inc. as an independent entity and maintains funding from investors including T. Rowe Price Associates, Inc., IQT, US Innovative Technology Fund, S32, Hillspire Capital, Breyer Capital, Marc Benioff, Thomas Tull and Paladin Capital Group.

The company’s Large Quantitative Models serve applications in life sciences, financial services, navigation and other sectors. SandboxAQ positions itself at the intersection of AI and quantum technology, using this positioning to address security challenges in AI implementations.

“This report highlights a growing recognition among security leaders that defending against evolving threats requires new assumptions and approaches, not just new layers or patches to current tooling,” Marc says.