There are 66,241 exposed AI systems sitting on the open internet right now with zero authentication. Not test environments. Production deployments of Ollama, Open WebUI, n8n, and other agent infrastructure — reachable by anyone with a browser and a port scanner.
We know because we just scanned for them again on Sep 16, 2026 — first full pass since April. The mix shifted; the open-by-default pattern did not.
The organizations shipping the fastest are also the ones skipping the authentication step. They treat their AI infrastructure the way early web developers treated their databases — open by default, secured later. Except later never comes. And unlike a misconfigured MySQL instance, an exposed Ollama endpoint can execute arbitrary inference, exfiltrate training context, and be weaponized for prompt injection at scale.
The attack surface grows at exactly the same rate as the market. And the market is growing at 171% per year.
Run a Free Security Scan →