Cybersecurity enters an AI arms race as businesses confront new vulnerabilities

6 October 2026

Artificial intelligence is pushing corporate cybersecurity into a new phase as companies face the challenge of protecting AI systems while simultaneously adopting the technology to strengthen their own defences. Research published during 2026 points to rising security budgets and greater use of automation, but also significant weaknesses in data protection, governance and preparedness.

The scale of concern is evident in PwC’s latest Global Digital Trust Insights research, covering 3,934 business and technology leaders across 71 countries. Half of security leaders placed attacks directed at AI systems among the five cyber threats their organisations are least prepared to manage. Cloud-related risks were selected by 40%, third-party breaches by 34% and ransomware by 33%.

The findings are consistent with the World Economic Forum’s Global Cybersecurity Outlook 2026, which found that 94% of respondents expected AI to be the most important factor changing cybersecurity. The proportion of organisations assessing the security of AI tools had also risen from 37% to 64%, suggesting that businesses are beginning to apply more scrutiny to technology that has often been deployed faster than security frameworks surrounding it.

The nature of the threat is also changing. PwC found that 53% of security and risk leaders placed autonomous botnets among the AI-enabled attacks for which they felt least prepared. Attempts to manipulate AI models through their inputs and efforts to compromise them through corrupted training data were each selected by 52%. These results measure executives’ assessment of preparedness rather than the prevalence of such attacks, but they indicate where security teams expect some of their most difficult future challenges to emerge.

Microsoft’s 2026 threat research provides evidence that AI is already becoming more important to attackers. The technology is being applied across activities including reconnaissance, vulnerability discovery, social engineering and malware development, potentially allowing parts of an attack to be completed faster and at greater scale. However, complex cyber operations continue to require substantial human involvement, meaning fully autonomous sophisticated attacks should not yet be regarded as the dominant threat.

Businesses are increasing spending in response. PwC found that 84% of security and finance leaders expect cybersecurity budgets to rise during the coming year, compared with 78% in the previous survey. AI ranked among the main investment priorities for 58% of security leaders. Despite that increased spending, only 39% of security, risk and operations executives said their organisations had fully established and integrated continuity arrangements specifically addressing cyber disruption.

AI is meanwhile becoming an increasingly important defensive technology. Half of PwC’s security respondents included threat detection and alerting among their five main priorities for applying AI to cyber defence over the next 12 months. Fraud detection followed at 43%, phishing detection and response at 42%, while incident prioritisation and vulnerability scanning were each selected by 41%. IBM’s 2026 research provides a financial dimension to the trend, finding substantially lower average breach costs among organisations making extensive use of AI and automation in security.

Companies remain much less willing to hand complete control to machines. Only 22% of PwC respondents would allow AI agents to execute defensive actions without human approval. Another 38% would permit limited autonomy, while 36% preferred people to remain responsible for execution with AI providing assistance. Concerns about reliability, accountability and the ability to explain automated decisions are therefore limiting how far businesses are prepared to automate security operations.

The underlying quality of corporate data controls could become an equally important constraint. PwC found that organisations had fully implemented an average of only three of seven surveyed data-risk measures across their businesses. Enterprise-wide data classification was in place at 49% of respondents and comprehensive controls against information leaving through important channels at 48%. Only 5% reported full implementation of all seven measures.

Shortages of specialist expertise are also creating opportunities for managed-security providers. AI was among the five leading areas for external cyber services for 53% of relevant PwC respondents, followed by cloud security at 49%, data protection and trust at 42% and threat management at 39%. The figures suggest that businesses increasingly expect outside specialists to supplement internal teams in areas where technology and risks are changing particularly quickly.

Beyond AI, companies are beginning to prepare for another technological transition. PwC found that 21% were implementing quantum-resistant security measures and 31% were testing or piloting them. Another 34% were investigating the issue without having moved into implementation, indicating that preparations to replace vulnerable cryptographic systems remain at an early stage for much of the corporate sector.

The result is an emerging contest in which AI is accelerating both sides of cybersecurity. Greater investment and more sophisticated defensive systems can help companies identify threats sooner, but adding AI agents and models to corporate infrastructure also creates systems that themselves require protection and oversight. The decisive issue for businesses may therefore be less about how quickly they adopt AI than whether security, data governance and human controls can develop at the same pace.

front page info
LATEST NEWS