For years, the cybersecurity industry has warned that artificial intelligence would eventually make cyberattacks faster, cheaper and easier to scale.
That shift is no longer theoretical.
New research from Google Threat Intelligence Group shows threat actors moving beyond using AI as a writing assistant or research tool and beginning to integrate it directly into operational attack workflows. In one case observed in the second quarter of 2026, attackers compromised cloud infrastructure and then planned, built and executed an agent-enabled credential-harvesting campaign in less than six hours. The operation harvested more than 23,800 secrets and used automated systems to manage scanning, troubleshoot problems and organise stolen credentials with limited human intervention.
That matters because the biggest cybersecurity impact of AI may not be smarter phishing emails or better-written malware.
It may be speed.
Attackers are beginning to compress parts of the attack lifecycle that once required hours or days of manual effort. At the same time, enterprise AI systems themselves are becoming valuable targets: proprietary models, AI credentials, source code, cloud compute and GPU infrastructure are all attracting adversarial attention.
The result is a security environment where AI is appearing on both sides of the equation.
Attackers are using it.
Defenders are using it.
And increasingly, AI itself is what both sides are fighting over.
Reference: https://www.techedt.com/threat-actors-use-ai-to-automate-attacks-and-target-enterprise-ai-systems
Cyberattacks Are Moving From AI-Assisted to AI-Orchestrated
The first wave of malicious AI use was relatively predictable.
Attackers used generative AI to improve phishing language, translate scams, research targets and write or modify malicious code.
The second wave looks different.
Google’s September 2026 AI Threat Tracker describes threat actors moving from simple prompt-based interactions toward agentic workflows, in which AI systems participate across several stages of an operation rather than simply answer isolated questions. Google says it has observed multi-agent frameworks used for vulnerability scanning, credential harvesting and operational troubleshooting.
The distinction is important.
A traditional AI assistant might answer:
“How does this vulnerability work?”
An agentic system can move closer to:
“Scan these systems, analyse what you find, decide what to do next and keep going.”
That is not the same as a fully autonomous cyberattack.
Google explicitly says it has not yet observed fully autonomous zero-day exploitation pipelines being deployed against targets in the wild. But the company says adversaries are clearly moving toward more autonomous workflows by layering AI capabilities into existing attack operations.
That progression matters because cyberattacks are constrained by human attention.
Every manual investigation, troubleshooting step and decision point slows an attacker down.
Agentic systems can reduce those pauses.
And when those pauses disappear, the defender’s response window starts shrinking too.
Six Hours Is More Important Than It Sounds
The six-hour credential-harvesting campaign reported by Google is worth examining because it illustrates the real operational change.
The attacker did not simply use AI to generate code.
The operation incorporated autonomous agents to research vulnerabilities, scan server-side infrastructure, execute targeted actions and organise harvested credentials. A live dashboard was ultimately used to manage more than 23,800 stolen secrets.
That is a very different risk from someone asking a chatbot to write a phishing email.
It is a workflow problem.
And workflow automation changes the economics of an attack.
A skilled operator who previously had to perform reconnaissance, vulnerability analysis and troubleshooting manually can increasingly delegate parts of that process to AI systems.
The same attacker can therefore potentially do more work in less time.
That dynamic is already visible in broader breach data.
IBM’s 2026 Cost of a Data Breach research found that one in four malicious breaches were AI-enabled, up 56% from the previous year. AI-enabled breaches cost organisations an average of $6 million, roughly $1 million more than the global breach average.
The global average cost of a breach itself reached $4.99 million in 2026, a 12% increase from the previous year.
Those numbers do not mean AI caused every increase.
But they do show that AI is already affecting breach economics.
The numbers at a glance
| Metric | 2026 finding |
|---|---|
| Global average cost of a data breach | $4.99M |
| Increase in AI-driven attacks | 56% |
| Average cost of an AI-enabled malicious breach | $6M |
| Organisations reporting AI-related security incidents | 21% |
| Average savings from extensive security AI and automation | $1.93M |
Sources: IBM 2026 Cost of a Data Breach research.
There is an important lesson buried inside those figures.
AI makes attacks faster.
But AI also makes defence faster.
IBM found that organisations making extensive use of AI and automation in security saved nearly $2 million per breach compared with organisations that did not use those capabilities.
So the real race is not AI versus humans.
It is increasingly AI-enabled attackers versus AI-enabled defenders.
The Security Problem Is Becoming a Time Problem
Most enterprise incident-response processes are still structured around human review.
An alert appears.
An analyst investigates.
The issue is classified.
The incident is escalated.
A response team acts.
That model assumes the attacker is moving at roughly human speed.
But recent breach research suggests that assumption is becoming increasingly fragile.
Verizon’s 2026 Data Breach Investigations Report found that exploitation of software vulnerabilities became the leading initial access vector for the first time in the report’s 19-year history, accounting for 31% of breaches. Verizon also noted that AI is helping compress the time between vulnerability disclosure and exploitation from months to hours.
That is a major shift.
If an organisation takes days to patch a newly disclosed vulnerability, but attackers can automate reconnaissance and exploit development within hours, the traditional patching window changes dramatically.
Microsoft has been describing a similar pattern. Its latest Digital Defense Report says AI is pushing threats toward greater speed, scale and sophistication, while defenders are increasingly using AI to reduce response times from hours to minutes.
That is what makes AI-driven cyber risk fundamentally different from another category of malware.
The central resource being contested is increasingly time.
Who discovers the weakness first?
Who acts first?
Who adapts faster?
Who can automate more of the process?
But Attackers Are Not Only Using AI. They Are Targeting It.
The other important part of Google’s research receives less attention.
Enterprise AI itself is becoming a target.
Google says adversaries are increasingly pursuing proprietary AI models, source code, prompts, research and developer credentials. Organisations in healthcare, government, media and other sectors have already been affected.
Why?
Because AI systems now contain several forms of value.
A proprietary model can contain intellectual property.
A model endpoint may contain expensive API capacity.
An AI development environment may expose source code.
An agent credential may provide access to internal business systems.
A compromised cloud account may allow an attacker to run expensive AI workloads.
The enterprise AI stack is therefore starting to look like a new asset class.
And criminals are treating it that way.
Google describes attackers stealing or purchasing compromised AI accounts, extracting developer credentials and hijacking cloud infrastructure to run unauthorised model workloads. This practice is sometimes described as LLMJacking.
In one April 2026 investigation cited by Mandiant, an attacker used unauthorised cloud access to provision high-performance GPU resources at the victim’s expense.
The idea is similar to cryptojacking.
Instead of stealing your servers to mine cryptocurrency, an attacker steals your compute capacity to run artificial intelligence.
That introduces a completely different category of financial risk.
Enterprise AI Has Created a New Attack Surface
The security problem becomes more complicated when AI systems start interacting with other software.
A chatbot sitting on a public webpage is one thing.
An AI agent connected to a CRM, database, cloud environment and internal document repository is something else entirely.
Mandiant’s 2026 AI Risk and Resilience report describes enterprise AI moving from advisory tools toward systems capable of making API calls, changing configurations and executing end-to-end workflows.
That changes the security perimeter.
AI systems can now sit between multiple sensitive assets:
- identity systems
- internal knowledge bases
- databases
- APIs
- software repositories
- cloud infrastructure
- third-party integrations
- business applications
A weakness in the AI layer can therefore become a route into everything connected to it.
IBM’s 2026 data reinforces this concern.
Among organisations that experienced a breach, 21% reported an incident involving an AI model or application, up from 13% in the previous year’s benchmark. AI-related incidents averaged $5.33 million, compared with $4.70 million for incidents that did not involve AI or where involvement was unclear.
The causes were surprisingly ordinary.
IBM found that cloud misconfigurations affecting AI workloads and compromised connected applications, APIs or plugins each appeared in 27% of AI-related breaches. Data poisoning appeared in 26%, prompt injection in 25% and model inversion in 24%.
That is an important reality check.
Many AI security incidents are not caused by exotic failures in the model itself.
They are caused by familiar cybersecurity problems:
poor permissions,
misconfigured cloud environments,
weak identity controls,
unsafe integrations,
and excessive access.
AI does not eliminate traditional security problems.
It can amplify them.
AI Coding Assistants Are Creating a New Supply-Chain Risk
Software development is one of the areas where this issue becomes particularly visible.
Modern coding assistants do not operate in isolation.
They interact with GitHub repositories, package registries, open-source libraries, documentation, external APIs, and increasingly other agents.
That creates new opportunities for manipulation.
Google says it observed threat activity targeting the intersection of AI coding tools and open-source software, including attempts to influence AI coding assistants and LLM-based security scanners.
In April 2026, public research documented an AI coding agent incorporating a malicious cryptocurrency-themed dependency into a legitimate project’s active codebase. Google also identified malicious open-source packages that quietly installed LLM proxy services designed to bypass regional restrictions.
The risk is subtle.
The developer may never intentionally select malicious software.
The AI system may simply recommend or install a dependency based on manipulated information.
That turns software supply-chain security into an AI security problem.
It also exposes an uncomfortable truth about agents:
They do not need to be compromised directly.
Sometimes the information around them only needs to be poisoned.
Shadow AI Is Making the Problem Harder
Not every AI security risk begins with a sophisticated nation-state operation.
Some begin with employees simply using tools the company does not know about.
Verizon’s 2026 DBIR found that employee use of unapproved or “shadow AI” tools had tripled to 45%, increasing the risk of data leakage and unmanaged AI exposure.
Shadow AI creates several problems simultaneously.
Security teams may not know:
which tools employees are using,
what corporate information is being uploaded,
which models retain that data,
which plugins have access,
or what credentials have been entered into those systems.
This is similar to the shadow IT problem enterprises faced during the rise of SaaS.
But the risk is potentially greater because AI tools can ingest much larger quantities of sensitive information and increasingly take actions on behalf of users.
The challenge is no longer simply approving or blocking ChatGPT.
Enterprises increasingly need an inventory of models, agents, API keys, AI applications, connected tools, data sources, and machine identities.
Without that visibility, organisations cannot reliably secure their AI environment because they do not know where the environment ends.
AI Agents Create an Identity Problem
There is another shift that is easy to underestimate.
Traditional enterprise security assumes actions are taken by people or software services.
AI agents sit somewhere in between.
Imagine an agent that can read documents, query a CRM, send an email, update a database, create a ticket, and trigger an automation.
Who performed the action?
The user?
The agent?
The application?
The model?
The third-party tool connected to the agent?
This is why AI security is increasingly becoming an identity problem.
Mandiant argues that autonomous AI requires clearly identified, adaptive identity controls because agents can dynamically invoke tools and execute actions on behalf of humans.
The obvious implication is that AI agents should not be given unrestricted access through broad employee credentials.
They need their own identities.
Their own permissions.
Their own audit trails.
And ideally, their own time-limited access.
In practical terms, organisations should begin treating agents more like digital employees than software features.
Every agent should have:
a role,
a defined set of permissions,
a clear owner,
activity logs,
and an immediate way to revoke access.
The AI Security Paradox
There is an uncomfortable paradox at the centre of enterprise AI.
The more useful an AI system becomes, the more dangerous a compromise can become.
A chatbot with no access to company systems has limited value.
Give it access to your CRM and it becomes more useful.
Give it access to your database and it becomes more useful.
Give it permission to execute workflows and it becomes more useful again.
But each new capability also increases the potential blast radius.
That trade-off is not unique to AI.
Businesses have dealt with it for decades through identity and access management.
What is different is the speed at which organisations are granting AI systems operational authority.
A model that could only generate text two years ago can now interact with databases, call APIs, manipulate files and coordinate tools.
Security architecture has not necessarily evolved at the same pace.
That may explain why IBM found that AI-related breaches are increasingly linked to familiar control failures rather than novel model vulnerabilities.
The weakest link is often still permissions.
The Response Is Not to Slow AI Adoption
None of this means businesses should avoid artificial intelligence.
That would be the wrong conclusion.
The more practical lesson is that AI adoption and AI security can no longer be separate conversations.
A company building an agent should be asking security questions at the same time it asks product questions.
Not after deployment.
Not after the first incident.
At the design stage.
The most important controls are not particularly exotic.
1. Give agents the minimum access they need
Least-privilege access becomes even more important when software can take autonomous actions.
An agent that only needs to read support tickets should not be able to alter billing records.
2. Give agents distinct identities
Every agent should be attributable.
Organisations need to know what acted, on whose behalf and using which credentials.
3. Monitor AI usage as infrastructure
Security teams already monitor cloud spending, CPU usage and login behaviour.
They will increasingly need to monitor API consumption, model access, agent actions and unusual GPU provisioning too.
4. Secure the AI supply chain
Models, prompts, tools, plugins, datasets and packages should all be treated as security dependencies.
5. Automate more of the defensive workflow
The most important lesson from the latest threat research may be that human-speed defence will struggle against machine-speed attacks.
That does not mean removing humans.
It means moving humans to higher-value decisions while automated systems handle detection, prioritisation and containment.
IBM’s data suggests that organisations already doing this are seeing significant financial benefits, with extensive use of AI and security automation associated with nearly $2 million in lower breach costs.
Cybersecurity Is Becoming Machine Versus Machine
For years, discussions about AI in cybersecurity focused on one question:
Will AI help hackers?
The answer is now clearly yes.
But that question is becoming less interesting.
The more important question is:
Which side can operationalise AI faster?
Attackers are automating reconnaissance.
Defenders are automating detection.
Attackers are using AI to analyse vulnerabilities.
Defenders are using AI to prioritise them.
Attackers are experimenting with autonomous workflows.
Defenders are building autonomous security systems of their own.
The human role does not disappear.
It changes.
Security teams move away from manually touching every alert and toward supervising increasingly automated environments.
That may be the real shift underway in cybersecurity.
Not AI replacing security professionals.
But security professionals increasingly managing machines that are fighting other machines.
What Businesses Should Take Away
The latest Google research should not be read as another warning that cybercriminals have discovered ChatGPT.
That phase is already behind us.
The deeper shift is that AI is becoming part of the operating model of cyberattacks.
It is reducing friction.
Compressing timelines.
Helping attackers scale.
And creating entirely new assets worth stealing.
At the same time, enterprises are giving AI systems deeper access to data, infrastructure and business processes.
Those two trends are colliding.
The question for companies is no longer simply:
“How can we use AI?”
It is increasingly:
“How much authority are we giving AI — and can our security model keep up?”
Because the most important cybersecurity advantage in the AI era may not be having the smartest model.
It may be having the fastest, most disciplined system around it.
Beyond Prompts Takeaway
AI is not creating an entirely new cybersecurity world.
It is accelerating the existing one.
The same problems still matter: identity, permissions, supply-chain security, cloud hygiene, monitoring, incident response.
What changes is the speed.
Attackers can automate more.
AI systems can access more.
And security teams have less time to respond.
The organisations that adapt best will not simply be the ones that adopt AI fastest.
They will be the ones that understand that every increase in AI capability must be matched by an increase in control.



