I am usually skeptical of predictions, and early 2026 has done little to change that view - if anything, it has reinforced it. Within the first days of the year, we have already seen enough disruptive events to make any forecast feel obsolete before it is finished. The problem is not a lack of imagination, but that reality is moving faster than that.
In fact, spending time on forecasts can easily distract from the more urgent task of understanding what is already changing beneath our feet. Cybersecurity and AI are shaped by constant pressure, accelerating feedback loops, and a growing gap between expectations and operational reality – annual planning just won’t cut it anymore.
Rather than attempting to guess specific outcomes, let us reflect on why current narratives around AI are misleading and which structural issues organizations continue to underestimate. The goal is not to predict 2026, but to understand how to approach it armed for the worst possible scenario.
It Takes All the Running You Can Do to Keep in the Same Place
The current rate of change is probably the slowest it will ever be again. Every year, security teams are asked to absorb more complexity, more dependencies, and more external volatility, often with fewer people and tighter budgets. The problem with predictions is not that they are inaccurate, but that they are rarely tested. Each year produces a new set of confident forecasts, while last year’s assumptions quietly fade from memory. In today’s conditions, it only creates a false sense of control.
Cybersecurity and AI sit at the intersection of technology, economics, politics, and human behavior. Political decisions, such as recent moves by the US administration signaling a more confrontational stance toward both regulation and international cooperation, or the European Union’s continued push to operationalize the AI Act, directly influence investment priorities and risk tolerance. These developments shape what organizations can deploy, how fast they can adapt, and where they may suddenly find themselves exposed.
At the same time, public sentiment toward AI is shifting. There is growing fatigue with what is often described as AI slop: low-quality, automated output that adds noise rather than value. Writers, artists, and engineers are increasingly vocal about their frustration, and this skepticism inevitably spills over into enterprise environments.
Against this backdrop, security teams operate in what feels less like incident response and more like permanent incident management. The relevant question for 2026 is not what exactly will happen, but whether security programs are designed to function under sustained pressure. First, the volume and impact of adverse events will continue to grow. Second, organizations will not receive proportionally more resources to deal with them. This imbalance has existed for a long time, but it is rapidly approaching a breaking point.
AI in Cybersecurity: Tool, Not Magic
This tension explains much of the current interest in AI for security operations. It is becoming an important component in security operations, incident response, and analytics, largely because it can help teams cope with volume and speed. Modern security operations rarely experience a clear beginning and end to incidents, and automation and AI-assisted analysis can reduce some of that burden.
However, AI systems remain non-deterministic by design. They produce likelihoods and recommendations, not certainties. This matters in environments where decisions can have legal, financial, or personal consequences. Accountability does not disappear simply because an AI model is involved. Governance, oversight, and clear responsibility become even more critical and they remain with humans.
Cost and sustainability add another layer of friction. Large-scale AI systems are expensive to operate and increasingly visible in discussions about energy consumption and infrastructure limits. In many scenarios, a simpler technical control or a well-designed process will still be a more rational choice. Using AI because it is fashionable rather than because it is necessary is unlikely to reduce risk or to generate any added value at all.
Trust, Supply Chains, and AI Agility
Organizations increasingly rely on transient trust relationships between applications, services, and external components, often mediated by delegated permissions and tokens. These relationships are convenient, but they are also opaque. Many environments have only a limited understanding of what has been trusted, for how long, and with which privileges.
Recent cybersecurity incidents have already shown how AI agents can amplify the blast radius of misconfigurations or compromised credentials, especially when combined with overprivileged access. These cases are rarely about malicious AI but familiar identity and access failures playing out at larger scale.
Supply chain risk compounds the problem. AI ecosystems are complex and change rapidly. Models, platforms, and vendors evolve, merge, or disappear at a pace that makes long-term dependency risky. Modern attacks that specifically target developers putting too much trust in AI (like slopsquatting) help hackers turn LLM hallucinations directly into attack vectors. Another risk comes directly from poisoned models and training data entering the supply chain, where compromised AI components can introduce subtle, hard-to-detect behavioral flaws that only surface under specific conditions, long after they have been embedded into production systems.
Betting everything on a single provider or architecture increases the risks, both technically and commercially. This is where the idea of AI agility becomes essential. Similar to cryptographic agility, it describes the ability to adapt to change without rebuilding core architectures. It also requires abandoning the notion that there is a single thing called AI. There are many classes of models and techniques, each suited to different purposes. Treating them as interchangeable only reinforces confusion.
Practical Considerations for This Year and Beyond
Rather than relying on forecasts, organizations would benefit from focusing on a small set of concrete priorities:
- Avoid vague terminology. Replace broad labels such as “AI security” with precise descriptions of assets, risks, and controls.
- Treat AI as a governed capability, not an abstract enhancement. Define accountability, oversight, and escalation paths before integrating it into critical processes.
- Design security operations for continuity. Assume overlapping incidents and sustained pressure rather than isolated events with recovery time in between.
- Reevaluate identity and trust models, particularly for agents and third-party integrations. Short-lived, narrowly scoped, and explicitly approved access should be the default. Zero Trust for AI!
- Vendor landscapes, platforms, and models will continue to shift. Architectural resilience and adaptability matter more than selecting any single technology. Stay agile and plan for constant change.
2026 is unlikely to reward confident predictions. It will favor organizations that acknowledge uncertainty, focus on fundamentals, and build security programs that can adapt without constant reinvention. If you have 30 minutes, I would encourage you to listen to our recent Analyst Chat podcast, where we discuss these challenges in more detail. However, if you are interested in meeting real industry experts and learn directly from their experience and best practices, there is no better opportunity than attending our EIC conference, which will be taking place this May in Berlin, Germany.