For years, the cybersecurity industry viewed AI as a force multiplier: something that made existing attack techniques faster, cheaper, and more accessible. This representation was correct. But Check Point Research’s 2026 Annual AI Security Report documents a transition that goes even further. AI has moved from being an assistant to being an operator. Where it once helped the attackers prepare, it now carries out the operation.
Table of Contents
Key observed results
- AI has evolved from development aid to live attack operators. It now does practical work in live operations, from China nexus espionage campaigns to criminal breaches of multiple Mexican government agencies, and has expanded from nation-states to common cybercriminals.
- AI now creates ready-to-use malware and attack suites. His involvement is often invisible in the finished artifact: One developer used an AI environment to create VoidLink, an 88,000-line command-and-control offensive framework, in less than a week.
- Attackers prefer commercial models and are now abusing them by exploiting the agent architecture and not just individual prompts. Most actors prefer mainstream jailbroken models over self-hosted models, and the permanent bypass is now an implanted configuration file that an agent loads across sessions and trusts.
- The market for AI-powered criminal tools is mature. Phishing-as-a-Service kits now integrate a voice model with built-in jailbreak, and voice-powered AI voice agent services perform vishing and one-time passcode theft at scale.
- Virtual Identity is no longer a reliable anchor of trust. Speech, face, documents and live video can now be faked cheaply and convincingly and are often used in attacks that take multi-channel social engineering to a new level of integration.
- AI itself is a growing attack surface. Models cannot always separate data from instructions, and the content they process could influence the model’s behavior; The surrounding stack adds common software vulnerabilities and supply chain risks, all in a rapidly evolving ecosystem where security practices are not always mature.
- Indirect immediate injection is on the rise. Detection of longer-form malicious payloads increased sharply, increasing approximately fivefold between March and May 2026 and reaching nearly 1% of observed prompts in May. Longer payloads are more typical of content-based and agent-based attack paths. This pattern suggests that indirect prompt injection is becoming more operationally relevant.
- Loss of corporate data through GenAI is an ongoing and growing risk. The number of high-risk prompts doubled from 2% to 4% in the last year, while companies used an average of 10 AI applications per month, many without official approval.
- The risks of data exposure are not evenly distributed across industries. A sector-level analysis shows that AI-related data exposure risks are not evenly distributed across industries and correlate with both AI usage patterns and security maturity. Business services saw the highest rate of high-risk GenAI prompts at 5.91%, meaning nearly 1 in 17 AI interactions pose a significant risk of sensitive data exposure.
To read the full findings, access Check Point Research’s 2026 AI Security Report here.
https://research.checkpoint.com/2026/ai-security-report-2026/
