2026 Q2 Threat Report: Track the Threats Shaping Enterprise Risk

How Fidelis XDR Supports AI Risk Management Across Network, Endpoint, and Deception Layers

AI systems are infrastructure now, and adversaries treat them that way, probing inference APIs, poisoning training pipelines, riding generative AI tools into the credential theft and lateral movement behind most breaches today.

Fidelis Elevate® answers this with XDR delivered through three named products under one CommandPost: Fidelis Network watches the traffic, Fidelis Endpoint® watches the workstations where AI gets built, Fidelis Deception® catches whoever’s already inside. None of it touches a model’s weights or reasoning directly. What it secures is the infrastructure those models depend on, which is the right frame for AI risk management generally: a security operations problem, not an AI-native one.

Fidelis ComponentWhat It WatchesAI Lifecycle StageDetects
Fidelis Network®Network traffic, all ports and protocols, encrypted sessionsTraining, inference, deploymentData exfiltration, RAG abuse, anomalous API traffic
Fidelis Endpoint®Workstations, servers, processesDevelopment, trainingPipeline tampering, credential theft, model IP theft
Fidelis Deception®Decoys, breadcrumbs, AD objectsPost-compromise, lateral movementReconnaissance inside AI infrastructure

How Does Fidelis XDR Actually Work Across Network, Endpoint, and Deception?

Each of the three components covers ground the other two can’t, starting with the one that sees everything moving across the wire.

What Does Fidelis Network Do for AI Security?

AI workloads throw off distinct traffic. Inference calls, RAG queries, ingestion jobs, generative AI integrations, all forming patterns that, watched continuously, become a baseline. Deviation from that baseline is where attacker activity shows up.

Fidelis Network® inspects traffic bidirectionally, east-west and north-south, across all ports and protocols, using Deep Session Inspection. DSI pulls over 300 metadata attributes per session, well past what standard netflow captures. The 20 GB 1U sensor runs this at line speed, reaching into nested, compressed, obfuscated content, encrypted traffic, ephemeral containerized workloads too, exactly where most 2026 AI deployments live between scheduled scans.

A simple case. An attacker tries moving training data out through an HTTPS session to an external endpoint. Netflow sees encrypted bytes leaving and not much else. DSI sees the session content, the protocol behavior, the destination, and can tell ordinary browsing apart from machine-driven exfiltration on encrypted traffic. That gap is the difference between catching it and not.

DLP runs across network, email, and web traffic with pre-built compliance policies. Someone pastes confidential data into an unapproved generative AI tool, the platform flags the transfer and logs it. Continuous asset classification, covering unmanaged IoT, legacy systems, shadow IT, keeps the inventory accurate even when AI teams spin up cloud infrastructure outside procurement.

Network traffic tells you what’s moving. It doesn’t tell you what happened on the machine before that traffic ever left, which is where the next layer picks up.

What Does Fidelis Endpoint Do for AI Security?

A data scientist’s workstation holds model weights, pipeline credentials, training data access, all in one place. Compromise it, and an attacker injects corrupted data or steals model IP before anything ships, invisible to tools that only watch post-deployment.

Fidelis Endpoint® runs single-agent across Windows, Mac, Linux, watching every process and child process for behavior, registry changes, file activity, network connections, in real time. On detection, it isolates the endpoint, triggers one of over 100 built-in response scripts, investigative, forensic, or destructive. The Live Console gives analysts direct remote access into disks, files, registries, processes, as if sitting at the machine. It preserves a copy of every file and script executed even when an attacker tries wiping their tracks afterward.

This is the layer that catches phishing-to-pipeline intrusion before it reaches a model. Detections map automatically to MITRE ATT&CK. A single anomalous API call from a dev workstation looks like noise alone, but a sequence following a model extraction pattern, correlated with process behavior on that same machine, becomes a documented MITRE ATLAS technique. That correlation only happens because Endpoint talks to Network and Deception, not because any one piece works alone.

Network and endpoint coverage both assume the attacker is still moving, still generating signal somewhere. The third layer is built for the attacker who’s gone quiet.

What Does Fidelis Deception Do for AI Security?

Network and endpoint monitoring both handle known patterns well. Deception handles the harder case: someone already in, quietly mapping the environment before making a move.

Fidelis Deception® continuously maps cyber terrain, scores asset risk, deploys decoys and breadcrumbs from real assets, emulated services, cloud resources, enterprise IoT devices, using machine learning to keep placement current. Decoys span hardware, software, cloud, including fake Active Directory accounts. Breadcrumbs are files, credentials, registry keys, canary files, placed beside real ones. Touch one and there’s no legitimate explanation. The alert is true by design, no tuning required.

For AI infrastructure specifically, decoy model endpoints, fake training repositories, deceptive API credentials sit next to real assets. An attacker probing the environment hits these before reaching anything real, handing over presence, technique, intent, well before any actual compromise lands. Red Team and Blue Team simulations keep refining placement as the AI environment shifts underneath it.

"AI scales offense; deception turns that scale into exposure."

Three layers, three different jobs. The question is what happens when an attack doesn’t fit neatly into just one of them.

Why Do You Need Network, Endpoint, and Deception Together?

ScenarioFidelis NetworkFidelis EndpointFidelis Deception
Training data exfiltration attemptFlags anomalous upload via Deep Session InspectionDetects and isolates the compromised workstationAD deceptive objects catch lateral movement first
Unsanctioned generative AI data leakDLP flags the transfer, classifies sensitive contentSecondary layerSecondary layer
Evasion attack against an AI-based detectorIndependent monitoring sees the full session regardlessSecondary layerCatches the reconnaissance the model missed

No single layer tells the whole story of an attack on AI infrastructure. CommandPost correlates alerts, context, and evidence across all three through Active Threat Detection, and provides retrospective analysis for tracing a full attack timeline after the fact, the audit trail NIST’s Manage function and the EU AI Act’s Article 12 actually want to see.

Catch the Threats that Other Tools Miss

Why Are AI Systems a Different Kind of Cyberattack Target?

Regular attacks go after code, credentials, network access. Attacks touching AI go after something quieter: training data feeding a model, the API exposing it, the workstation where a data scientist builds it. Understanding these risks associated with AI is step one in any serious AI risk management effort, because the controls that catch a normal intrusion miss these slower, lower-signal paths most of the time, which is exactly why Network, Endpoint, and Deception need to work as one system rather than three separate tools.

MITRE ATLAS tracks this in numbers. Version 5.1.0, November 2025: 16 tactics, 84 techniques, 56 sub-techniques, 42 real-world case studies. Spring 2025 added 19 techniques for RAG poisoning, prompt crafting, AI supply chain compromise. By October, MITRE and Zenity Labs had added 14 more, aimed at AI agent vulnerabilities like context poisoning and tool-invocation exfiltration.

Not hypothetical. Cisco’s State of AI Security 2026 report found 83% of organizations plan to deploy agentic AI. Only 29% feel ready to secure complex AI models once they’re live. That gap is where managing AI risk stops being a slide in a deck and starts being an actual operational priority.

Four patterns matter most, and each maps to one of the layers above.

Adversarial evasion attacks alter input data at inference time so a model misclassifies malicious activity as benign. Poisoning as little as 0.001% of a training dataset can degrade an AI system’s performance in ways nobody notices until much later. A successful evasion attack against an AI-based anomaly detector suppresses alerts quietly while a real intrusion runs underneath, undetected by the tool meant to catch it. This is exactly the case Fidelis Network’s independent monitoring and Fidelis Deception®‘s reconnaissance detection are built to catch from outside the compromised system.

Generative AI data exposure happens when employees feed sensitive personal data or confidential data into unsanctioned tools, opening exfiltration paths most security teams aren’t watching. Attackers who reach retrieval-augmented generation systems pull enterprise knowledge stores straight through the model interface, no need to touch the underlying data stores at all. Fidelis Network®‘s DLP is the control built for exactly this.

Pipeline and supply chain exposure shows up when training pipelines sit accessible from corporate networks. Adversaries slip corrupted historical data into a retraining cycle. The model validates fine during testing and misbehaves only when a specific trigger appears, sometimes months later. Trend Micro’s State of AI Security Report 1H 2025 found more than 3,000 exposed Ollama servers and over 200 unprotected Chroma vector databases sitting open on the public internet, direct paths into AI development environments, unguarded. This is where Fidelis Endpoint’s process monitoring on development workstations does the heavy lifting.

Shadow AI is the quiet one. Gravitee’s State of AI Agent Security 2026 report found only 47.1% of deployed AI agents are actually monitored. The rest run unwatched, and any compromise or misuse involving them goes unnoticed until something downstream breaks.

None of this surfaces through endpoint agents or firewall logs alone. Conducting regular risk assessments against AI infrastructure means watching network, endpoint, and behavioral signals together, not any one in isolation.

What Do NIST AI RMF and the EU AI Act Require for AI Security?

Two frameworks now define what responsible AI practices look like operationally, and both carry real implications for the controls a security team has to run, which is the regulatory backdrop the three-layer approach above is built to satisfy.

What Does the NIST AI Risk Management Framework Require?

NIST’s Artificial Intelligence Risk Management Framework, published January 2023, gives a structured approach to identifying, assessing, and managing risks across the AI lifecycle. Four functions: Govern, Map, Measure, Manage. They run continuously, not once a year. NIST-AI-600-1, the Generative AI Profile, followed in July 2024, proposing specific actions for generative AI risk management tied to organizational goals. AI RMF 2.0, February 2024, tightened alignment with the EU AI Act.

The Playbook says it plainly. Effective AI risk management practices require ongoing measurement of an AI system’s performance under real conditions, adversarial ones included, using both quantitative and qualitative metrics to track behavior over time. Conducting regular risk assessments, documented incident response tied to actual identified risks, not a generic policy binder nobody reads.

Responsible AI under this framework isn’t a position paper. It needs infrastructure that generates continuous monitoring data, because a quarterly scan won’t catch the slow, low-signal attacks that work AI pipelines over weeks or months, which is precisely the gap CommandPost’s retrospective analysis is meant to close.

NIST’s framework is voluntary. The next one isn’t, and it comes with a number attached.

What Are the EU AI Act Cybersecurity Requirements?

In force since August 1, 2024. GPAI obligations since August 2, 2025. May 2026’s Digital Omnibus pushed the high-risk system deadline to December 2, 2027, but Article 5 prohibited practices have applied since February 2025, and the European Commission opened its first formal investigations in early 2026. This isn’t a future problem.

Article 15 is what security teams should read closest. High-risk AI systems must hold up against adversarial attacks, data poisoning, confidentiality breaches, throughout their operational life. Logs retained six months minimum. Risk management documented from day one, not bolted on after something goes wrong.

Three consequences follow.

  • Financial: up to EUR 15 million or 3% of global turnover for high-risk violations, EUR 35 million or 7% for the worst ones.
  • Operational: a manipulated AI system can run undetected for weeks, quietly skewing financial decisions or security classifications before anyone notices the output is off.
  • Trust: recovering from a model integrity failure means technical fixes plus reputational repair, and neither comes back fast.
Five Ways You Can Use Deception in the Mythos-like AI Era
use deception for ai-threats Cover

Why Does AI Governance Depend on Security Operations?

NIST AI RMF and the EU AI Act land on the same demand from different angles: security controls active across every stage an AI system touches, development through retirement. No single telemetry source covers that whole AI lifecycle. Training pipeline integrity needs network and endpoint working together. Inference-time attacks need traffic analysis and behavioral detection. Forensics need stored history with a clear event chain. Compliance needs tamper-evident logs held for months. That’s the practical case for one integrated platform over three disconnected tools managing AI risk separately, each blind to what the others see.

The MITRE ATT&CK mapping built into Network and Endpoint extends naturally to AI-specific threat modeling. Security teams translate MITRE ATLAS techniques into detectable patterns inside existing SOC workflows instead of building a parallel stack just for AI. Roughly 70% of ATLAS mitigations map onto controls organizations already run, so the investment compounds across traditional threats and AI-adjacent ones both.

AI brings new risk surfaces and considerably tighter regulatory stakes than most organizations have dealt with before. The discipline needed to manage AI risk isn’t new, though. Security operations, applied consistently, across wherever the AI systems actually sit, network, endpoint, and the terrain in between. Fidelis XDR, through Fidelis Elevate®, does that by securing the environment around AI rather than claiming to read what happens inside the model. The value isn’t in what the platform says about AI. It’s in what it catches around it, every day, without anyone having to ask.

Frequently Asked Questions

Does Fidelis Elevate analyze AI model outputs or training weights directly?

No. Network, Endpoint, and Deception watch the infrastructure around AI systems, traffic, endpoint behavior, attacker reconnaissance, not the math inside a model. Interpretability and AI-native security are different disciplines from what Fidelis provides.

Can Fidelis Elevate help meet EU AI Act Article 15 requirements without replacing existing SIEM or SOAR tools?

Yes. CommandPost feeds correlated telemetry, including the retention and audit trail Article 15 expects, into whatever SIEM or SOAR workflow a SOC already runs. It integrates rather than replaces.

How does deception help with AI supply chain risk specifically, versus network monitoring alone?

Network monitoring catches data as it leaves. Deception catches attackers before they reach anything real, by placing decoy training repositories and fake credentials in their path. For supply chain attacks, where the goal is quiet, sustained access rather than one fast exfiltration event, that early trip-wire counts for more than traffic analysis on its own.

Our customers detect post-breach attacks over 9x Faster

  • Detect Advanced Threats Before Damage Escalates Trusted
  • Cybersecurity Leader for 20+ Years
  • See why security teams choose us over other solutions
Request a DemoSee Fidelis in Action

Citations:

About Author

Sarika Sharma

Sarika, a cybersecurity enthusiast, contributes insightful articles to Fidelis Security, guiding readers through the complexities of digital security with clarity and passion. Beyond her writing, she actively engages in the cybersecurity community, staying informed about emerging trends and technologies to empower individuals and organizations in safeguarding their digital assets.

Related Readings

One Platform for All Adversaries

See Fidelis in action. Learn how our fast and scalable platforms provide full visibility, deep insights, and rapid response to help security teams across the World protect, detect, respond, and neutralize advanced cyber adversaries.