The news
TrendAI, the enterprise unit of Trend Micro (4704.T), identified 2,457 niche AI tools in a report published in late September 2026, which Cybersecurity Dive covered on September 28, 2026. TrendAI said the 1,468 of those tools used by only one industry represent vendors that "may have never undergone a mainstream AI governance review."
The findings come from TrendAI's State of AI Security Report for the first half of 2026. According to the report, TrendAI swept 21.6 million URLs and 4.6 million unique hosts through its internal telemetry and identified 43,175 AI-related service instances across 25 industries and four global regions. TrendAI said technology accounted for 22,540 of those instances, or 52.2%, followed by retail, construction and manufacturing. The industry counts in the report's chart add up to far more than 43,175, so the categories overlap.
TrendAI defines a niche service as one adopted by two or fewer industry verticals, with no more than 10 instances worldwide. It counted 2,457 niche services and 1,468 exclusive services used by only one vertical, and said 59.7% of niche services are exclusive to a single industry. A summary passage in the same report gives a lower figure of 1,286 single-vertical tools.
The report names single-industry tools that it says standard AI inventories leave out: MinutaIA, a public-sector legal research platform with 284 instances; Featurespace ARIC, a fraud-detection engine for financial services with 109; and CodaMetrix, a medical documentation tool with 95. TrendAI said most AI risk frameworks, cloud access security brokers (CASBs) and AI-discovery tools are built to catch OpenAI, Microsoft Copilot and Google Gemini traffic instead.
Cybersecurity Dive framed the findings as a hazard for critical infrastructure organizations. The report itself groups niche services into verticals including the public sector, industrial energy and manufacturing, financial services and healthcare. It does not name individual organizations using the tools.
The report also points to exposure in the software that connects AI agents to business systems. It cites earlier Trend Micro research that found 1,467 exposed Model Context Protocol (MCP) servers, which link AI agents to tools and data, with 1,227 still using a long-deprecated transport. It adds that nearly half (48%) of more than 19,000 MCP server codebases analyzed recommended storing secrets in insecure .env files or plaintext configuration files.
The numbers
- AI-related service instances identified
- 43,175 across 25 industries
- Niche AI services (two or fewer verticals, up to 10 global instances)
- 2,457
- Exclusive AI services (one vertical only)
- 1,468
- Niche services exclusive to a single industry
- 59.7%
- Exposed MCP servers cited in the report
- 1,467
Why CEOs should care
For CISOs, the report challenges AI policies built around a short list of big vendors. A rule that blocks one chatbot and approves another does nothing about a fraud model or clinical documentation tool bought by a business unit. Security leaders should ask whether their shadow-AI discovery covers API traffic and third-party integrations, not just browser use; TrendAI says those channels deserve at least equal weight in monitoring and access control.
For procurement teams and CFOs, TrendAI recommends ranking vendor security reviews for single-industry AI tools by data sensitivity and regulatory exposure, not by vendor size or brand recognition. That means asking which AI services touch customer, patient or financial data, whether each vendor went through the same review as a major platform, and which business unit owns the contract. TrendAI suggests using the niche and exclusive catalog in its report as a starting point for that inventory.
Boards in regulated sectors such as healthcare, financial services and government should ask management for a complete AI inventory rather than a list of approved chatbots. TrendAI also says least agency is now as important as least privilege. Where least privilege governs what a user or service account can access, least agency governs the decisions and actions an agent can take without further review.
The bigger picture
TrendAI's broader conclusion is that AI has not created a new category of threat so much as sped up familiar ones: unauthenticated exposure, unpatched software, weak secret management and abused trust. In TrendAI's account, the most damaging incidents of the first half of 2026 were routine supply-chain and credential breakdowns, including the poisoning of the LiteLLM and Xinference packages, not attacks on AI models themselves.
In a TrendAI survey of the 2026 Pwn2Own Berlin hacking contest, run by Trend Micro's Zero Day Initiative, 29 of 34 contest entries (85%) reported using large language models (LLMs) in their workflow. Trend Micro sells AI security products, a commercial interest readers should weigh alongside the data.
What’s next
The report does not say how many customer organizations its telemetry covers, so the counts describe services observed, not adoption rates. The practical next step is internal: compare procurement records, expense reports and network logs against the approved AI list, then review any unlisted services that handle regulated data first. Any MCP servers reachable from the internet should be checked for authentication and for secrets stored in plain text.
What “Fact-checked” means
Fact-checking means testing a story’s facts against the evidence before it is published. This story went through at least two separate checks before this version was published.
- What we checked
- Its names, figures, dates, job titles, quotes and who said what were checked against the story’s sources, including its main source where it could be opened. The headline was checked for accuracy and overstatement.
- How
- A first check reviewed the whole story. If it passed, a second, skeptical check went back to the sources to look for mistakes in the most important facts. If a check flagged the story, it was edited to fix the problems found, and a separate re-check then reviewed the whole story again.
- Who
- The checks are made by our newsroom, as steps kept separate from the writing, under rules set by our editor, Hussein Mukhtar. A story the checks still flag is held for the editor, who decides whether it is fixed, published or dropped.
- If something is wrong
- “Fact-checked” does not mean error-free. If a material error is found after publication, we correct the story and add a note saying what changed. Report an error







