Dive Brief:
- Niche AI tools are creating serious cybersecurity hazards for the critical infrastructure organizations using them, the security firm TrendAI said in a recent report.
- These AI tools are often produced by vendors that haven’t received significant security scrutiny, making it difficult to know how well their products are protected, according to TrendAI.
- The firm’s report also delved into a host of other threat vectors in the AI industry, including vulnerable trust relationships and insecure core infrastructure.
Dive Insight:
Through a public internet scan of 21.6 million URLs and 4.6 million devices, TrendAI identified 43,175 AI-related services in use across 25 industries. Of those services, TrendAI classified 2,457 as “niche,” meaning they appeared in no more than 10 instances total across only one or two industries. The report also flagged 1,468 services that only one industry used.
The fact that so many services are so narrowly used is “a sign that generic AI platforms are possibly failing to meet vertical-specific requirements,” TrendAI said in its report.
While those bespoke AI products might fill important needs for critical infrastructure organizations, their obscurity could make them ticking cybersecurity time bombs. These tools’ developers “may have never undergone a mainstream AI governance review,” TrendAI said, because AI risk assessment tools and methodologies, including Cloud Access Security Broker products, are designed to scrutinize market-leading AI products from major frontier labs.
Those access controls and vetting processes, TrendAI said, weren’t designed for obscure AI tools such as the ones the company identified, which included a legal research platform, a fraud-detection service for the financial sector and a medical documentation tool.
The report recommended that infrastructure operators using niche AI tools take several steps to assure their security, including expanding their inventorying efforts beyond the mainstream vendors. Companies should also prioritize AI tool reviews based on the sensitivity of the data they can access and how much “regulatory exposure” a mistake could cause, rather than based on the vendor’s size or public profile. Also, TrendAI said, security monitoring tools should “weigh API traffic and third-party integrations at least as heavily as browser-based AI usage” to avoid overlooking niche tool activity.
Beyond niche tools, TrendAI’s report listed a host of other risk factors. One is the shoddiness of security measures protecting Model Context Protocol Servers, which act as hubs connecting AI agents to organizations’ other resources. TrendAI found that many MCP servers are “exposed, misconfigured, reused, and trusted as if they were ordinary developer utilities.”
“This exposure creates direct access pathways; plaintext secrets and cloud integrations can turn those paths into account-level risk,” researchers wrote. “Vulnerabilities in repositories create a supply-chain pool of exploitable flaws, and AI-assisted code may introduce quality debt when review does not keep pace. Furthermore, marketplace trust signals can spread adoption without offering real assurance.”
The report also described other key AI risk areas, including vulnerabilities in open AI infrastructure (such as publicly accessible AI inference engines running old, unpatched versions), a lack of attention to securing the LLM control plane (which would prevent malicious actors from using rogue commands to bypass guardrails), excessive ecosystem trust (which hackers can exploit by poisoning open-source packages) and the fact that old security models aren’t suited to agentic behavior, where the security emphasis should be on “least agency” in addition to “least privilege.”