AI-First Businesses are Paying an "AI Speed Tax" when Recovering from Cybersecurity Incidents, according to Fastly's Global Security Research Report
MWN-AI** Summary
Fastly's latest Global Security Research Report details the challenges that AI-first businesses face in cybersecurity, coining the term "AI Speed Tax." These organizations, which incorporate AI into their core processes from the outset, are experiencing notably longer recovery times from cybersecurity incidents—averaging about 80 days longer than their non-AI counterparts. As AI solutions proliferate, these businesses report recovery timelines of nearly seven months, which lead to an increase in financial losses exceeding 135% compared to non-AI-first organizations.
A significant contributor to this tax is the expanded attack surface introduced by AI systems, which complicate security. Notably, 44% of AI-first organizations reported that their AI was directly exploited during their latest security incident, compared to a mere 6% of non-AI businesses. The study highlights that AI implementations can lead to security blind spots, with over a third of AI-first organizations acknowledging that AI use had contributed to vulnerabilities in their last security incident.
The rise in operational costs attributed to AI activity is alarming, with approximately 64% of organizations reporting that AI scraping has become a significant financial burden, averaging an impact of $348,000 annually. Furthermore, as AI adoption accelerates, the need for robust security measures has never been greater; security investments are pivoting towards agentic discoverability, API security, and web application firewalls.
Fastly’s CISO, Marshall Erwin, emphasizes the urgent need for organizations to modernize their security infrastructure alongside their AI innovations, stressing that the evolving threat landscape requires comprehensive visibility and control over AI-related activities to secure valuable digital operations effectively.
MWN-AI** Analysis
The recent Global Security Research Report from Fastly reveals a pressing concern for companies that prioritize AI-first strategies: the so-called "AI Speed Tax." This term describes the disproportionately high recovery times and costs incurred by organizations that adopt AI technologies without modernizing their security measures concurrently. With AI-first businesses reporting an average recovery time from cybersecurity incidents of 80 days longer than their non-AI counterparts, the implications for market players are significant.
Investors should note that the increased financial impact—over 135% higher breach costs due to extended recovery timelines—reflects a critical vulnerability that could undermine profitability. Furthermore, a staggering 44% of AI-first organizations have admitted to AI-specific exploits in their security incidents. This figure underlines the expanding attack surface created by new technologies and the necessity for robust cybersecurity protocols.
As AI technologies become central to business operations, the challenge of enhancing security alongside innovation requires immediate attention. Organizations are compelled to prioritize investments in advanced security tools, including agentic discoverability, API security, and web application firewalls. Currently, 75% of surveyed organizations express concern about Distributed Denial-of-Service attacks targeting their AI frameworks, emphasizing the urgency of adopting specialized security measures.
In light of these findings, companies must proactively reevaluate their cybersecurity strategies. Failure to do so not only risks operational disruption but also escalates costs, particularly as AI scraping emerges as a material expense. By investing strategically in security infrastructure and expert knowledge, businesses can better position themselves to manage the risks associated with rapid AI adoption.
In conclusion, as the speed of AI integration accelerates, so must the pace of security modernization. Organizations must embrace the necessity of a robust cybersecurity posture to ensure sustainable growth and protect against escalating threats.
**MWN-AI Summary and Analysis is based on asking OpenAI to summarize and analyze this news release.
Fast moving AI adopters are paying the price with 80 day longer recovery times, higher breach costs and expanding attack surfaces
Fastly, Inc. (NASDAQ: FSLY), a leader in global edge cloud platforms, today published the findings from its fourth annual Global Security Research Report. It reveals that AI-first businesses – those integrating AI into key processes and offerings from the outset rather than as a secondary enhancement – are paying an AI tax by failing to modernize security in step with AI’s rapid expansion across IT infrastructure. These businesses report taking nearly seven months on average to fully recover from cybersecurity incidents, 80 days longer than businesses that do not identify as AI-first.
The implications of this AI Speed Tax are significant in today’s real-time economy. The financial toll of a cybersecurity incident for AI-first businesses exceeds that of non-AI-first businesses by more than 135%. This increased financial impact reflects both the longer recovery timelines and a higher rate of AI-specific compromise. In fact, almost half (44%) of AI-first organizations claim that AI was directly exploited in their most recent security incident, compared to just 6% for non-AI-first organizations. These findings highlight how AI-native systems expand the potential attack surface, introducing new layers like agentic workflows and decentralized data flows, all of which complicate defense.
“The speed of AI adoption is reshaping security infrastructure almost overnight. For AI-first businesses, the priority isn’t to slow down innovation — it’s to modernize security at the same rate that AI is transforming their infrastructure,” said Marshall Erwin, CISO at Fastly. “That means securing AI and inference infrastructure, monitoring and throttling unwanted AI crawler activity, anticipating the rise of shadow AI and shoring up your outer perimeter.”
Meanwhile, more than a third (34%) of AI-first organizations say that AI use led to a security oversight or blind spot that contributed to their last security incident, compared to 20% for non-AI-first organizations. This points to a growing challenge in visibility, control, and enforcing AI use policies. As AI becomes more embedded across operations, it’s getting harder for security teams to map where and how AI is being used, or to isolate its role in incident recovery.
At the same time, practices such as AI scraping are adding cost and complexity to already stretched infrastructure, driving operational disruption and pushing spend into six-figure territory.
“There is a major shift happening in terms of what organizations are responsible for defending,” continued Erwin. “The challenge is no longer confined to malicious actors and isolated security incidents. Instead, it's about managing an infrastructure footprint that is growing rapidly and, often, invisibly.”
For many businesses, these risks are no longer theoretical; they’ve become a reality. AI scraping alone has become a material cost center for nearly two-thirds (64%) of organizations, with average annual infrastructure impacts exceeding $348,000.
These costs are just the beginning. Almost half of organizations (43%) have seen infrastructure expenses increase as a direct result of AI activity, while 40% have faced operational disruption, and 29% reported issues impacting online visitors – from sluggish load times to broken functionality. For many, the reality is creeping costs and architectural complexity.
To respond, organizations are investing heavily in security tools built for this new era. Agentic discoverability (56%), API security (55%), and web application firewalls (54%) have emerged as the leading areas of investment. However, the response is far from complete; three in four (75%) respondents are concerned about Distributed Denial-of-Service (DDoS) attacks targeting AI agents, and more than half (53%) acknowledge they have an increased need for AI-specific security expertise to effectively defend their systems.
“From unmonitored agentic activity to escalating scraping costs, the risks are real, operationally and commercially. As a result, Web Application and API Protection (WAAP) tools are becoming business-critical solutions because they provide essential visibility and control organizations need to secure innovation at the edge,” noted Erwin.
To find out how to modernize your organization’s security infrastructure and implement steps to recover more quickly from cybersecurity incidents, download the report today .
About the research
This research surveyed 2,000 key IT decision-makers with an influence in cybersecurity, in large organizations spanning multiple industries across North, Central and South America, Europe, and Asia-Pacific. The interviews were conducted online by Sapio Research in Q4 2025 using an email invitation and an online survey.
About Fastly, Inc.
Fastly’s powerful and programmable edge cloud platform helps the world’s top brands deliver online experiences that are fast, safe, and engaging through edge compute, delivery, security, and observability offerings that improve site performance, enhance security, and empower innovation at global scale. Compared to other providers, Fastly’s powerful, high-performance, and modern platform architecture empowers developers to deliver secure websites and apps with rapid time-to-market and demonstrated, industry-leading cost savings. Organizations around the world trust Fastly to help them upgrade the internet experience, including Reddit, Universal Music Group, and SeatGeek. Learn more about Fastly at https://www.fastly.com , and follow us @fastly .
View source version on businesswire.com: https://www.businesswire.com/news/home/20260225463676/en/
Media Contact
Stacey Hurwitz
press@fastly.com
Investor Contact
Vernon Essi, Jr.
ir@fastly.com
FAQ**
How does Fastly Inc. Class A FSLY plan to address the emerging cybersecurity challenges faced by AI-first businesses, particularly regarding the AI tax and longer recovery times from incidents?
With the report indicating that AI-first organizations face a 135% higher financial toll from breaches, what strategic measures is Fastly Inc. Class A FSLY implementing to mitigate such risks for its clients?
Given the increasing complexity and costs associated with AI scraping, how is Fastly Inc. Class A FSLY planning to innovate its edge cloud platform to provide better security and efficiency for AI-first organizations?
What specific AI security tools and investments is Fastly Inc. Class A FSLY focusing on to enhance visibility and control for organizations struggling with the rapid expansion of AI in their infrastructure?
**MWN-AI FAQ is based on asking OpenAI questions about Fastly Inc. Class A (NYSE: FSLY).
NASDAQ: FSLY
FSLY Trading
24.62% G/L:
$10.655 Last:
4,032,069 Volume:
$10.56 Open:



