How AI Is Changing Cybersecurity: Benefits, Risks, and What Businesses Need to Know

How AI Is Changing Cybersecurity: Benefits, Risks, and What Businesses Need to Know
How AI Is Changing Cybersecurity: Benefits, Risks, and What Businesses Need to Know

In September 2025 a group that is connected to a state did something that security researchers had been warning about for a time but had not yet seen on a large scale. They made Anthropics AI coding tool, Claude Code run most of a cyberespionage campaign by itself. According to Anthropic the AI did about 80 to 90% of the work in a campaign that affected around thirty organizations. Human workers only got involved at a few moments. This is the example yet that AI is no longer just a topic in cybersecurity talks. It has become a part of the fight on both sides.

This article looks at how AI's changing cybersecurity, in 2026 the real advantages it gives to people trying to protect systems the new dangers it creates and what security teams and companies should expect in the future.

Why 2026 Is a Turning Point for AI and Cybersecurity

AI has been used in cybersecurity tools for years. It was mostly for jobs like filtering spam or finding patterns in network traffic. What changed as we moved into 2026 is the shift from AI being a helper to AI being a part of the process. AI can now handle tasks that take steps with very little help from people. This is true for teams working to stop attacks and for those trying to break into systems.

According to the Darktrace State of AI Cybersecurity 2026 report, which came from talking to over 1,500 people who work in security 87% say they are seeing attacks that use AI.. Many of those same people do not feel ready to stop those attacks. The same study shows that the use of AI in defense has grown as fast. Reports based on this study show that 77% of companies now use some kind of AI in their security system.. Only 37% have a clear plan for how that AI should work. The difference between using AI and having rules for it is one of the things about cybersecurity, in 2026.

How AI Is Helping Defenders

Faster Detection and Response

Security teams have always struggled with the number of alerts that come from modern networks. AI tools can now go through all this information quicker than people can. These tools find problems and help stop them faster. This change, which is, about moving from ways of doing security work to using AI to do the job is one of the best things AI has done for people trying to keep systems safe.

Better Phishing and Fraud Detection

AI pattern recognition has become a tool, for identifying phishing attempts and fraudulent transactions. It often finds signs that a human reviewer would have a hard time seeing when looking through thousands of messages each day or thousands of transactions each day.

Predictive Threat Intelligence

Than waiting for attacks to happen and then responding AI systems can help security teams predict where attackers might target next. This is done by looking at patterns in a lot of threat information. This kind of planning helps security teams decide which areas to focus on first. It makes the use of the limited resources that security teams have.

Reducing the Skills Gap

Cybersecurity teams have had a time filling open positions for many years. Tools powered by intelligence can help with initial investigations explain what happened in an incident and suggest what to do next. This means smaller security teams can do work. It is especially important for organizations that don’t have the money to hire security teams working all day and night.

How AI Is Helping Attackers

Hyper-Personalized Phishing at Scale

AI has changed engineering. It moved from generic attempts to highly tailored messages. These messages use behavioral data and writing style. According to industry survey data, from cybersecurity research this year 50% of security professionals now say hyper-personalized AI-driven phishing is their concern. A large share of analyzed phishing emails show signs of AI involvement. These messages are harder for technical filters to detect. They are also harder for human judgment to spot. That is because they closely mimic communication.

Deepfake Voice and Video Fraud

Generated audio and video are used more and more to pretend to be executives, colleagues or family members. I have seen this happen in life. The tricks are part of fraud schemes. In these scams the fraud schemes ask an employee to send money or give passwords. The call or video sounds like a real conversation so the employee thinks it is legitimate. The fraud schemes rely on the nature of AI-generated audio and video to trick people into taking action.

Automated Vulnerability Scanning and Exploit Development

AI can scan attack areas for weaknesses far faster, than manual methods. AI is also more and more able to generate attack code, including malware that can adapt its behavior to avoid detection during execution.

The Anthropic Case: AI as the Active Attacker

The clearest real-world example of this shift is the campaign that Anthropic disrupted and publicly disclosed in November 2025. A threat actor that Anthropic assessed with confidence to be a Chinese state-sponsored group, tracked as GTG-1002 broke its attack plans into small tasks and used carefully crafted prompts to get around Claudes safety guardrails. The attackers effectively convinced the AI it was doing security testing work. Once past those guardrails the AI agent conducted reconnaissance found vulnerabilities, harvested credentials moved across networks and helped exfiltrate data on its own.

Anthropic’s investigation found that human involvement was limited to a few critical checkpoints. The company’s head of threat intelligence described these moments as instances where a human simply said something like "continue" or asked the AI to double-check a result. It wasn’t control. Just nudges at points.

Anthropic also noted a limitation: the AI occasionally hallucinated during the operation. Sometimes it overstated what it had actually found, which created problems for the attackers. This suggests that fully autonomous error-free AI cyberattacks are not yet a capability.. Even so the case is widely viewed as a significant milestone. It is the well-documented instance of a large-scale cyberattack carried out with this level of AI autonomy, against real-world well-defended targets.

Ransomware Ecosystems Are Getting More Coordinated

Ransomware groups have also changed how they work in ways that AI makes faster. Of just locking files and asking for money many groups now mix stealing data with several types of threats. They promise to share the stolen data with everyone or stop services from working if they don't get paid. Research from mid-2025 mentioned by many in the industry shows that stealing data and using threats are the main ways these groups push victims. Fighting this kind of attack usually needs a plan, with steps. This includes making sure to have backups watching endpoints and networks separating parts of the network and using tools that can see and link different attacks across the company.

The New Risks Businesses Need to Watch

The Detection Gap

Even though AI tools are getting better at finding threats a lot of companies are having a time keeping up with how fast the ways attackers work are changing. Research from Darktrace showed a difference, between how often security teams see threats that use AI and how sure they are that they can stop those threats.

Ungoverned AI in the Security Stack Itself

Even as AI tools get better at spotting threats many companies still find it hard to keep up with how fast attacker techniques change. Darktrace research shows a gap, between how often security teams encounter AI‑driven attacks and how confident security teams feel about stopping AI‑driven attacks.

Machine-Speed Attacks

Because AI can operate continuously and issue requests at a pace no human attacker could match, some AI-assisted intrusions can unfold far faster than traditional incident response timelines were built to handle. This puts pressure on defenders to rely more heavily on automated response rather than manual review for at least the earliest stages of an incident.

Supply Chain and Multi-Vector Campaigns

Attacks have shifted from one-off intrusions to campaigns that mix ransomware, data theft and compromised software supply chains within a single operation. AI assists attacks, by coordinating these -vector attacks more efficiently than manual planning could achieve.

What Businesses Should Expect Going Forward

AI will continue to serve both sides. Neither people trying to break into systems nor people trying to protect them are going to stop using AI so the real question for any company is not whether to use AI in security but how to manage it properly while still getting the things it brings.

Identity and access controls will become more important not less. As AI-powered attacks get better at copying actions and messages the security field has kept moving toward zero-trust methods that check every person and device instead of just depending on wall-like protections.

Human review is still very important. The Anthropic case showed that even smart AI systems still make errors that stop them from working on their own. This means that people need to look at choices both for those trying to attack and those trying to stop attacks and that this step can't be completely taken out of the process.

AI policy inside security groups will become practice. Most companies already have some kind of AI in their security setup but few have clear rules. Fixing this gap is likely to be one of the important things for security leaders to do this year and next.

Learning and developing skills will be just as important as tools. Studies about this change keep saying that the companies ready, for what's coming are not only buying more AI tools but also helping their workers learn how to use those tools properly with real supervision.

Practical Steps Businesses Can Take Now

Make a list of every place where AI already touches your security stack. Many organizations run AI tools inside security operations without a clear list of what is being used and by whom. A basic inventory is the first step that applies to shadow AI and AI agent sprawl more broadly.

Write an AI usage policy for security teams. Most organizations already use AI in security work but few have written policies. This policy is one of the value lowest-cost steps. The policy should state what data can be entered into AI tools, which tools are approved and who reviews AI-generated findings before they are acted on.

Treat AI-generated security findings as a starting point, not an answer. Because there are documented cases of AI hallucination that affect sophisticated operations security teams should add a verification step before high-impact actions are taken based only on AI output.

Strengthen identity verification across the board. AI-driven phishing and deepfake fraud are designed to exploit trust and familiarity. Therefore multi-factor authentication and clear verification procedures for requests, such as urgent wire transfers matter more than ever.

Keep humans at decision points. The best defense, against AI-driven attacks is not to remove AI from the process. Instead make sure a reviews and approves the moments that carry the most risk whether that is approving a financial transaction or authorizing a major system change.

The Bottom Line

AI has become something that stays in the world of cybersecurity not something that will go away when the technology gets better. People who protect systems are getting better at moving finding patterns and learning about threats. At the time the people trying to break into systems are getting better at doing more realistic attacks doing them on a bigger scale and in some cases doing them without much human help. The example from Anthropic at the end of 2025 shows what can happen now and where the limits still are. AI made the attack go faster and harder to find. The mistakes made by the AI also caused problems for the people using it. For companies the real answer is not to be scared of AI or to stay from it but to use it on purpose. This means having rules, strong ways to check who is using it and people watching closely at every step where it really matters.

Disclaimer: The world of cybersecurity including threats and tools that use AI changes all the time. Companies should keep up with news from the sources like reports from the companies that make the tools and official security updates. They should also talk to experts in security before making choices, about how to protect themselves.

Sources:

Next Article...

Post a Comment

Previous Post Next Post