HEXTYX  Research Phase 1 Edition · 2026
21 Chapters · 102 Pages Built on MITRE ATLAS · OWASP · NIST AI RMF

The AI Security Threat Landscape & Coverage Benchmark 2026

A full benchmark of enterprise AI security readiness — scored across six domains, eight industries, and the agents, RAG systems, and AI supply chains now running inside the modern enterprise.

8 industries scored 11 weighted scoring models 10 2027–2028 predictions
Lowest-Scoring Domain, 2026
39/100
Average enterprise coverage for AI Supply Chain Security — the weakest of all six domains in the Coverage Model, and the fastest-growing blind spot in production AI.
Prompt Security
62/100
Agent Security
41/100
RAG Security
46/100
Data Protection
57/100
Supply Chain
39/100
Governance
52/100
About This Report

Why this benchmark exists

Most organizations can describe their cybersecurity posture in detail — vulnerability counts, patch rates, endpoint coverage. Almost none can answer the equivalent question for AI: which AI attack techniques are covered, which threats remain exposed, and how that compares to peers.

The HexTyx AI Security Threat Landscape & Coverage Benchmark closes that gap. Across 21 chapters, it scores enterprise AI security readiness using the HexTyx AI Security Coverage Model™ — six weighted domains spanning prompt security, agent security, RAG security, data protection, supply chain security, and governance — then applies that model across eight industries, six threat categories, and the economics, maturity, and incident response practices behind the numbers.

This Phase 1 edition draws roughly 95% of its data from public frameworks (MITRE ATLAS, MITRE ATT&CK, the OWASP LLM Top 10, NIST AI RMF), governance standards, academic research, and public incident analysis, with the remaining 5% from HexTyx's own assessment data — a mix that will shift toward proprietary telemetry in future editions.

Key Findings

Five things every CISO should know

01

Agent security is the fastest-growing blind spot

Average coverage of 41/100 — the second-lowest of all six domains — even as autonomous agents gain access to email, CRM, ERP, and financial systems across every industry measured.

02

AI supply chain security is the weakest domain overall

At 39/100, most organizations cannot fully inventory the models, MCP servers, plugins, and vendors their AI systems actually depend on.

03

Governance failures amplify every other risk

The majority of major AI incidents analyzed trace back not to a technical flaw, but to a governance failure — no ownership, no inventory, or no approval process — further up the chain.

04

81% of organizations have never run a formal AI red team assessment

Most AI systems pass conventional penetration tests and compliance audits while remaining fully exposed to prompt injection, agent abuse, and memory poisoning.

05

Detection speed is the strongest predictor of incident cost

The same AI incident detected within an hour costs an estimated $50K; detected after 30 days, it costs $2M or more — runtime monitoring is now an economic decision, not just a technical one.

Coverage Model

The six domains, scored

Every score in this report rolls up to the HexTyx AI Security Coverage Model™ — six weighted domains that make up Tier 1 of the report's three-tier framework architecture.

Prompt Security
62
Data Protection
57
Governance & Compliance
52
RAG Security
46
Agent Security
41
AI Supply Chain Security
39
Industry Benchmark

Coverage by industry

Technology leads every sector measured; retail and ecommerce trail furthest behind, with insurance and legal services occupying a developing middle tier.

HexTyx Industry Coverage Benchmark™ — 2026
IndustryCoverage ScoreMaturity Level
Technology
72
Level 4
Financial Services
64
Level 3
Government
61
Level 3
Manufacturing
58
Level 3
Healthcare
54
Level 3
Legal Services
52
Level 2
Insurance
49
Level 2
Retail & Ecommerce
46
Level 2
Methodology

A three-tier framework

The report uses eleven distinct weighted scoring models. Rather than leave that complexity implicit, Chapter 4 introduces a three-tier architecture that organizes every model in the report:

Tier 1

Core Coverage Model

The six-domain, org-wide Coverage Model — Prompt, Agent, RAG, Data Protection, Supply Chain, and Governance — used as the report's primary executive score throughout.

Tier 2

Nine domain-specific sub-rubrics

Deeper weighted models for individual domains — agent risk, prompt injection exposure, data leakage, vendor risk, and more — each scoring one Tier 1 domain in detail.

Tier 3

Executive composite scores

Three board-level metrics — Coverage Score™, Threat Exposure Score™, and AI Maturity Index™ — that synthesize the full report into headline numbers for the boardroom.

Table of Contents

All 21 chapters

Part I — Foundations
01Executive Summary
02Research Methodology
032026 AI Threat Landscape
04The HexTyx AI Security Coverage Model™
Part II — Business Impact
05Industry Benchmark Analysis
06Coverage by Threat Category
07The Economics of AI Security
08The HexTyx AI Security Maturity Model (AISM™)
Part III — Emerging AI Risks
09The State of AI Supply Chain Risk
10The Rise of AI Agents
11The State of Prompt Injection
12The State of AI Data Leakage
13AI Governance Failures
14The State of AI Red Teaming
Part IV — Industry & Compliance
15AI Compliance Readiness
16AI Security by Industry
Part V — Operating AI Security at Scale
17AI Incident Response & Breach Management
18Third-Party AI Vendor Risk & Supply Chain Security
19AI Runtime Security & Continuous Monitoring
20The HexTyx AI Security Coverage Model — Executive Scoring
21State of AI Security 2026: Predictions & Conclusion
Go Deeper

Explore each topic on the site

Every major theme in this report has a dedicated deep-dive on HexTyx's research hub — read the chapter, then go deeper on the topic that matters most to your organization.

Get the full 102-page report

All 21 chapters, the complete Coverage Model methodology, and the full industry benchmark — free to download.

Download the Report (.docx)