Welcome to the KuppingerCole Analyst Chat. I'm your host, my name is Matthias and I'm an analyst and advisor with KuppingerCole Analysts. This is our first episode for 2026 and we are continuing a conversation, kind of, that we started late last year when we looked at predictions for IAM for 2026. And since we are doing more than IAM, we need another episode for that. And for this, I have invited Jonathan and Alexei from our great analyst team. So I would like to welcome them. So first of all, welcome Jonathan. Thank you. Happy New Year to you.
Happy New Year and Happy New Year to you as well, Alexei. Hi. Hello and yeah, thanks for having me again and glad to see you both in the new year. Looking forward to it. So alive and kicking and the podcast has left its hiatus. So this is really the first episode and the official title is the Analyst Predictions for Cybersecurity and AI 2026. And of course, we talked about that before this episode because it's always these episodes at the beginning of the year where analysts pull out their crystal ball and polish it and try to make great predictions for the next year.
And if I think back on what we had last year, especially when we had some last minute episodes when it comes to larger incidents, larger infrastructures going down, could we have predicted that? Or the question is, put it the other way around, looking at recent news, what's the point of making predictions at all? Maybe starting with you, Alexei.
Yeah, you're absolutely right, Matthias. I mean, at the moment of recording this, we are just one week into 2026 and already so much stuff happened, which basically makes absolutely no sense in making traditional style predictions.
But yeah, the world has changed and it's not just politics, it's economies, societies and psychology and the whole worldviews for entire nations are quickly changing and people aren't even liking AI anymore, speaking about that topic. So yes, I think we should focus probably more not on looking into crystal balls and doing our predictions, but basically telling people to prepare for the worst and how to do it the best possible way.
Jonathan, agree? I think Alexei's right. There've been some major geopolitical changes. And although we try and insulate ourselves and our views from these, but they do have a knock-on because they have an economic effect, which then bears down on investment decisions, purchase decisions and so on. And I think one of the difficulties, in fact, Alexei and I were talking about this just before the podcast recording, it's with the pace of change, it's very hard to make predictions because things are changing so rapidly. I think if we look back to last year, we can tease out some common factors.
The old joke about it's always DNS turned out to be true. In a very significant way, it really was all DNS, but certainly we're seeing upticks in threat actor activity. We're seeing, yes, as you say, lots of acts of cyber sabotage, so destructive cyber attacks. And I think we are, as you say, we are all trying to figure out what AI means. And I think there's considerable unrest.
Writers, artists, musicians, composers, anybody in the creative field has significant concerns about the impact of AI. Again, I see some of my composer friends saying, well, I thought the bright future was robots would do all the drudgery and leave us to, well, write and paint and compose music, whereas in fact, things have gone the other way around. So there's that concern. I think there's also governments are struggling to keep up. Governments are struggling, the UK government is struggling with digital identity, what that actually means.
They have recently passed what I believe is a tremendously hazardous piece of legislation, which allows government agencies to debit the bank in the UK who is in receipt of benefits in any way. That to me would seem to be a ripe attack landscape for an attacker, because it doesn't take, you don't have to take very much money, five pounds or 10 pounds from every UK citizen, and you're probably set up for the rest of your life. So I do see these surprising and sometimes challenging changes.
And as I say, the thing I note is that the rate of change today is probably the slowest the rate of change is ever going to be. Right. And nevertheless, I tried to structure this a bit. What we cannot anticipate is really the speed that you just mentioned. So it will accelerate. I assume you're right. The other part is really the structure. We cannot predict the unknowns, unknowns, but we cannot predict anything that we do not know is coming around the corner. So that would be difficult.
So now patterns that we expect in cybersecurity and AI and AI for cybersecurity that we expect we should prepare for, because we are also doing our preparation for our research, for our advisory. First of all, maybe that big question, will there be cybersecurity without AI in the future, Jonathan?
Yes, I think there will be. I think that AI will become a tool in the arsenal of the operations team and the incident response team. But I don't think that it will be, I don't think it will be the only tool in the toolbox. And I think one reality, again, sort of separating AI away from cybersecurity is that we've, for a long time, we've had this model of we're in a period of peace and quiet, and we detect an incident happening.
And so we gear up our incident response teams, they get out the incident response playbook, they respond to the incident, they contain, eradicate, isolate it, and restore. And then we can all have a cup of tea and relax. I don't think that's the reality that modern SOC teams are experiencing. I think it's incident, incident, incident, incident without respite. And I think that has a human cost in terms of the stress involved there. And I think that may be one of the things to bring AI back into the conversation that drives the adoption of AI.
Because, again, not only the pace of change, but the incident rate is also the slowest it's ever going to be. But if I remember back, I had some episodes with Alexei over the years, and we looked at augmenting traditional cybersecurity teams and systems with AI for other mechanisms, just filtering and boiling down XDR, whatever the three-letter acronym then was at that time. But the same question to you, Alexei. Can you explain what XDR is? But will there be cybersecurity without AI or with AI just being a tool in the mix?
Well, before we dive into technical details, let me just step back and reiterate one thing Jonathan said earlier. If there is one certainty, we can all agree on predicting that there will be more of the bad stuff happening. And unfortunately, we will have less resources to deal with all the bad stuff. This is a constant, it has been a constant in our industry for decades, but it probably will be even more noticeable this year. And this is the reality we have to deal with.
As one of the greatest British philosophers said in his book, and of course it was Lewis Carroll, you have to run as fast as you can just to stay in one place. And if you want to get somewhere, you have to run twice as fast. And this is what we are preparing to basically.
And yes, AI will be just one of the tools. Unfortunately, we have to admit that this is a very costly tool for us to implement, to operate, and it has huge negative impact on the environment. So I am afraid that impact and all those cost factors will be a much bigger consideration for a lot of companies.
So yes, we will be relying on AI to a degree. But if something can be solved without it, if you can basically address a specific risk with a simple script, or maybe with a bunch of low-cost labor hired somewhere, this will still happen. So one of the biggest challenges for security professionals would be how to combine all those different tools together in a security framework. And I think one of the difficulties, as you say, Alexei, is the cost of this.
And again, something that affects the macroeconomy, of course, is where do you put all these compute systems? Everyone's out going, hang on, this is going to make a sizable dent in our national power generation capability, and even possibly in our water table for cooling, unless everyone wants free hot water running into their house, of course. But the other side of it, and I think something which, again, to go back into the task of the security operations, they operate in a very deterministic, definite world. And I still maintain that I believe AI systems are non-deterministic.
They are probabilistic in nature. And so I think that, again, is something that was going to cause a little concern, especially if you're talking about a serious incident, perhaps even an insider incident, where people's careers, pensions, and livelihoods can be damaged. And certainly we've, again, going back to the poor old United Kingdom, we've seen some substantial risks happening there. Say the post office computing scandal is still rumbling on, people are still complaining that they've not received any compensation.
And of course, again, a failure of governance at the human layer, no matter how many AI systems you put in to support it, if you have that failure of governance at the human layer, then you are unfortunately fatally flawed. Yeah, I mean, absolutely. If you think of it, it's not just AI which is non-deterministic, humans are as well. And somehow we've learned to deal with those issues more or less to a degree.
And yes, you're absolutely right, governance is the key word here. I guess the biggest problem is that while we do understand that humans have to be governed and they have to bear responsibility for their actions, somehow a lot of people just don't think the same of AI systems.
AIs, no matter how great they are or will be, and who knows, maybe sooner or later we will develop a perfect quantum-based AI, which is always right, who knows, it still has to be governed and still someone has to be responsible for its activities. And this is all that matters. And this is all what we have to design our existing security and identity systems around, basically. And still people, and rightfully, come to us as analysts and advisors and ask us for advice.
So, the question is, if you look just at 2026, which has just started, from your expectation, what would be the single biggest mistake that enterprises can make in AI security this year? Or to put it the other way around, where should we as advisors, as analysts, prevent them from? What would be the most important thing that can go wrong when using AI as a defender, as an organization, as a user company?
Alexei, starting with you. Well, I would say the biggest mistake we can continue making is very simple. It's in the terminology. We all should forget the phrase AI security, because AI security as a term is extremely misleading and way too broad. Is it securing AI or securing with AI? What kind of AI? Securing what? Securing from what risks? And so on.
Again, who bears the responsibilities? So, let's just talk using buzzwords and start talking capabilities and risks. Because that's essentially what everybody needs in the real business scenarios. Understanding your risks and understanding how to deal with those risks with specific controls.
And yes, quote-unquote AI systems of different kinds are one of those tools. And yes, those tools have their own security controls. And that's exactly our job as analysts and advisors to explain to everybody that yes, it is complicated, but no, it's not something which is completely new. Huge parts of this architecture already exist. You just have to adapt, expand, automate all those to the new level of scale. And of course, you have to ensure that again, we have full visibility, full accountability and full responsibility for all those two.
Agree, Jonathan? I do. And I think we are in our industry, we are seeing that pushback.
You know, I've had CISOs on the phone saying, please, please, please, I really don't want to hear about any solution that says it's got AI in it. I'm absolutely fed up of hearing about, oh, AI pixie dust. And so yes, we are seeing that pushback. We are seeing people are fed up of, hey, it's AI, so it's magic and better. I think hopefully what we're getting to in 2026 is, as Alexa says, a balanced recognition that AI is just a piece of technology like any other. So AI is a hype, of course, the term AI is a hype, the way we are using it is currently most probably overhyped.
When we look at cybersecurity as a whole, and maybe AI and cybersecurity, and I'm using it the same way, I just find out, what do you consider to be underhyped? What are we, what is flying under the radar? And it shouldn't be, Jonathan?
Gosh, well, it's difficult to say, isn't it? Because solutions that are flying under the radar, I'm as blind as anybody else.
I don't, you know, I don't have omniscience, otherwise no one would play Trojan Pursuit with me. So I don't know what is flying under the radar. I do think that there are attacks that are flying under the radar that we're not looking at. So I think one of the attacks and indeed solutions that we're starting to see emerge is to the OAuth2 problem. And what I see there is that we have a proliferation of transient trust. So I decide I want to have a wonderful calendar manager or document manager.
So I connect this to my personal Google Drive or calendar, and I've got no idea what's behind that very useful document manager, calendar manager, whatever else it may be. And so I don't know what I'm letting in. I don't know what the vulnerabilities look like. And the only way I find out, of course, is when I'm breached, discover I was unwise.
Now, many organizations are being very careful about what they let access their Office 365 tenancy for this very reason. But we're also starting to see some companies emerging like Nudge, like Push Security are starting to offer solutions in this area, which I think is interesting. And I think it's even more interesting, of course, when we mix in the MCP servers, the A2A communications, which certainly we are seeing. And actually, I think we are seeing CISOs and architects are talking about how to manage and meet that challenge.
So I think, yeah, the permissions and control of transient trust, I think is something that has perhaps flown a little under the radar, but we're now seeing solutions coming to the and solve that particular problem. Right.
Well, let me look at this same question from a completely different angle, if I may. I mean, we've lived through several similar periods of technology hype before we had the multiverse and we had the Bitcoin and blockchain and whatnot. And then we had the cloud before and I think the cloud actually survived pretty well, way longer than its original hype cycle. And it survived exactly because there is no longer such thing as the cloud. There are multiple different kinds of cloud for different purposes we have.
Public clouds, private clouds, hybrid multi clouds, small, big ones, specialized ones for government services and so on. I think the same has to happen with AI, because right now everybody thinks of AI as basically the handful of those large language models from Google or OpenAI and a handful of other companies.
Well, this is definitely, it's not even the tip of the iceberg. Yes, it's tip of the hype cycle, but the actual useful AI has existed long before and it continues to be developed. We still use machine learning tools. We still use small language models, if you will. We still use specialized models for coding or producing music, if you will. I do understand you probably don't like those very much, you two guys, but they have their own valuable purposes and use cases. And this has to be communicated to the entire world that there is no such thing as the AI, but not a single tool.
There are different classes of different tools for different purposes. And the only way to actually reduce the hype and make useful and profitable outcomes from those tools is to use the right tool for the right purpose. And this is what is pretty fine under the radar at the moment because of the hype. Right. And I spent some time over the Christmas vacation period to read and listen to Jan Le not being finished already. These are just large language models. The development is going on.
There will be more, there will be different types of AI and we need them for different types of challenges, of problems to solve. We are not yet at the end of the development of AI because just LLMs are getting better. This is not the way that things are evolving right now. So this is really an aspect to consider. And if I'm allowed to contribute something that is flying under the radar for me, this is something that came up as a pattern last year already. This is really, on the one hand, supply chain availability and supply chain attacks.
Everything that we talked about when we had to be fast, we talked about platforms, about infrastructures, about security infrastructure not being available or compromised. I think this is something that people are talking about, but I think they are still not talking about it enough. Would you agree?
Well, absolutely. The whole AI thing is a huge supply chain risk, exactly because it's so costly and changing on a daily basis. And this is why we have to spread the word about this whole notion of AI agility, if you will. Just like we have crypto agility. If you want to stay on top of the quantum computing risks, you have to invest a lot of thought at least into AI agility because, again, the leaders change on a weekly basis and you cannot put all your AI eggs into a single basket. You have to hedge your risks.
You have to, again, combine different models, different kinds of tools from different vendors and somehow still make sure that they operate as a single AI fabric. Again, we're coming back to the same term. So somehow, you should be able to design an architecture where all different kinds of AI not just coexist peacefully, but actually work to produce useful results together and remain governed and observable and secure as well.
Yes, this is difficult, but unfortunately, this is the only sensible way. So we're getting close to the end. First of all, of course, although we do not do too much predictions today, Kopi Nakol, of course, will cover this topic and will look at cyber security, AI and cyber security for AI. I'm talking to the right people right here, but nobody leaves this podcast without at least one single prediction for 2026. It could be an easy one, but one should cover it. Jonathan? I think we will see an increase in fabrics and platforms. I think we will see things like cyber security.
I think we'll start to fade into the background. I would like to see that we get to a stage where authentication is something that is nigh on invisible to the user, so that we're no longer presenting people with challenges. For example, enrollment in any kind of financial service involves lots and lots of complicated, intrusive questions. And wouldn't it be great if we can actually get at least the feel of identity to the point where it's seamless and transparent? That's something I look forward to. I think the other thing that we will see is more of these complex attacks.
I think that we will see more determined and resourced attackers from a variety of sources with a more or less criminal intent. And I think that will be one of the biggest challenges to cyber security managers and leaders in 2026, is that we will have some determined and resourced attackers opposing us.
Well, at the risk of sounding perhaps a little bit too pessimistic, I would still say I believe 2026 will be the year when we will hear a lot of people proclaiming AI is dead, in a sense that the hype will be over finally. But on the other hand, I still think it will be a great opportunity both for vendors and users and of course us as neutral experts to finally make people realize that again, AI is not another reason to hype. It's a useful tool when implemented properly.
And we will finally start seeing people basically asking the right questions and coming to us looking for the right solutions. This is what our project will be this year. Identifying the best tools and explaining how to deploy them. So looking forward to a lot of interesting work. Exactly. And I think exactly building upon what you just said, not only the threat landscape will change, the product landscape will change, but also the vendor landscape will change dramatically over this year.
There will be acquisitions, there will be mergers, there will be new companies and vendors and products around and there will be some just being taken over, being obsolete or just going away. So I think the prediction for corporate users of AI and cybersecurity tools in general, be prepared for that change. Make sure that you are able and capable of adjusting your cybersecurity framework and landscape, your fabric, as you said, over time to changing supplier landscapes as well. So there will be changes there as well. Agility and resilience should be your mantras for the year. Right.
Final words, Jonathan? My final words. I wonder what we will look back on five years from now and say, I can't believe we did it that way. And it's easy to say, well, DNS, because it's always DNS. But the way that we've given AI agents long-lived credentials and broad missions, we are right now, I think, recreating the service account sprawl, which we spent a decade trying to fix, except now we have service accounts that can reason and take autonomous action. Perhaps future us will wonder why on earth we did this and trust in them to behave.
So we need to shift to a just-in-time, narrowly-scoped, human-approved mission structure. Because let's not forget, when these autonomous systems go wrong, it won't be them, it will be a human that gets hauled into court and is told you failed to exercise appropriate governance. Right. Final words, Alexei?
Well, kind of continuing look into the future, I believe 100 years from now, the historians will be looking back at 2025 and say, I can't believe this AI craze happened and people were throwing so much money at it. It will be basically compared probably to the tulip craze in the Netherlands, you probably remember from a few hundred years ago, when you could buy a house for a tulip bulb or something like that.
So yeah, this will sound completely crazy, especially for people who will probably be completely used to AI being an integral part of their future lives. But it will be so much less prominent, more transparent, just like, well, nobody's hyping about the internet nowadays, or phone lines, or telegraph, if you will, or newspapers. So AI will be exactly the same 100 years and, fingers crossed, it should happen earlier than that, we should be working towards. My final words are, look at what we do as a company, you do as analysts.
There's a great blog post by Alexei from early December that covers some of the topics and more that we just discussed. So there is a look at what the cybersecurity future will look like. We are constantly working on topics that are related to what we just discussed. Jonathan just published a leadership compass on AI-related security components, to put it very, very general. This is a great read and really interesting to follow up on. Have a look at our blog post. 2026 has just started.
And if you want to join the conversation, maybe you want to be a subscriber to our professional services or just to our membership services. That was the commercial break at the end. Really getting in touch with us is really important. If you don't want to subscribe, if you don't want to have a look at our blog post, but you still want to reach out to us, leave a comment. We are really interested in your feedback, in your questions, in topics to cover in upcoming episodes. There will be some changes to this podcast, but it will stay every Monday around, starting right now.
And if you have any suggestions for that, please let us know, leave it behind the YouTube video, send us a mail, send a mail to JC, to AB, to MR at Copenhagen Call, and we are happy to be in touch with you. Thank you very much, Alexei. Thank you very much, Jonathan, for leading this discussion, for doing not too much predictions, but for shedding a light on what's just happening out there right now.
Thank you, Jonathan. And thank you, Alexei.
Thank you, Matthias. And thanks to all of our viewers, listeners, and to readers as well. Thank you. Thank you. Bye-bye. Bye-bye.