Companies are racing into model-driven services, software agents, and automated development tools while leaving 99.9% of fixable vulnerabilities untouched, according to fresh industry estimates.
More than half of organizations already use software agents in production, and about the same share use them to build custom apps. The rollout is moving faster than patching, access controls, or secure defaults. Model-driven platforms surface roughly 25 confirmed flaws a day. Teams fix about 1.5 of them, and deployment still takes 3 to 5 months.
That leaves companies open to the basics going wrong: missing encryption, exposed interfaces, and permissions that reach too far. The risk gets worse when cloud-hosted models and software agents tie into internal data, third-party tools, and production workflows. Attackers are using the same automation for phishing, adaptive malware, and real-time exploitation. One forecast puts tech-driven cyber incidents in 2025 at 28 million, up 72% from the year before.
If you run model-driven services, software agents, or automated development tools, pay attention to this. Anthropic, Amazon Web Services, IBM, and Microsoft are backing the Akrites coalition, and the U.S. Treasury Department and the Cybersecurity and Infrastructure Security Agency (CISA) have both issued guidance. But gaps across Africa, Latin America, and Southeast Asia, hiring shortages, and too much reliance on machine output mean the security groundwork is still falling behind.
You can find guidance online from CISA, the U.S. Treasury Department, and the Akrites members.