Companies that bake AI into their core operations from “D1” are actually heading toward a cybersecurity crunch, according to Fastly’s ‘The AI Speed Tax’ Global Security Research Report.

Fastly KV

Data from the report leads to one general phenomenon – AI-first organisations take nearly 7 months to fully recover from a cyber incident. That’s about 80 days longer than businesses that don’t consider themselves AI-first. In today’s real-time economy,3 extra months of disruption is a big deal.

And it’s not just about time. The financial hit is heavier too. AI-first companies report costs that are more than 135% higher compared to their non-AI-first counterparts, with 44% of them saying that AI was directly exploited in their most recent security incident, while only 6% of non-AI-first businesses said the same. Specifically for the SEA region, the numbers are even more striking, with 69% of organisations saying AI tools or models contributed to their latest cybersecurity incident.

On the other hand, budgets are constantly being drained in a rather stealthy way, all because of AI scraping, as 7 in 10 organizations in Southeast Asia expressed that AI scraping has become a real cost centre, with average annual infrastructure impacts exceeding US$372,330. Beyond that, companies are also reporting operational disruption (53%), higher infrastructure expenses (51%), security incidents or data leakage (50%), and even user-facing issues like slow load times or broken functionality (35%) directly tied to AI activity.

To fight back, organisations are pouring money into tools like web application firewalls, API discoverability and security solutions, and agentic discoverability. But there’s still a sense that they’re playing catch-up. About 83% of Southeast Asian respondents are worried about DDoS attacks targeting AI agents, 61% say they need more AI-specific security expertise, and 59% feel mounting pressure on existing teams to manage AI risks.

In terms of the patterns shown by the report, CISO of Fastly, Marshall Erwin, defended that AI innovation itself isn’t the main source of the problem – it’s the gap between rapid AI adoption and outdated security. He points out that businesses need to secure AI and inference infrastructure properly, monitor and throttle unwanted AI crawler activity, anticipate the rise of shadow AI, and reinforce their outer perimeter before things spiral.

Meanwhile, Rachel Ler, AVP of Asia at Fastly, adds that AI is no longer just another tool but rather a core feature that has been embedded across business operations rapidly. As such, it is harder for security teams to track deployment and assess impact during recovery. And if governance isn’t put in place now, companies risk falling behind later.

Facebook
Twitter
LinkedIn
Pinterest

Related Posts

Subscribe via Email

Enter your email address to subscribe to Tech-Critter and receive notifications of new posts by email.