SME horizon

AI has crossed from assistant to operator in cyberattacks

Photo by cottonbro studio

Check Point Software Technologies Ltd. has published its Annual AI Security Report 2026 from Check Point Research, documenting a decisive shift over the past twelve months: artificial intelligence has moved from assisting attackers to operating attacks.

Where AI once helped criminals prepare, it now runs live intrusions with minimal human direction, compressing the time defenders have to respond and opening new attack surfaces across the enterprise, as enterprise adoption of AI outpaces AI governance controls.

The report is grounded in real incidents, telemetry, and original case studies from the past year, and sets out what has changed for defenders as AI participates directly at every stage of the attack chain.


Key findings from the Annual AI Security Report 2026:

Lotem Finkelstein, Vice President, Check Point Research, said: “A year ago we described AI as a force multiplier for attackers. What we documented this year is more significant: AI has crossed into the live attack chain and is now running operations as a sole operation, that once required a skilled team.

“The expertise barrier that separated capable attackers from the rest is disappearing, and defenders can no longer assume a human is setting the pace on the other side.

“The organizations that stay ahead will be the ones that govern how AI is used, secure the AI systems they now depend on, and defend at machine speed rather than human speed.”

What defenders can do

The report frames the response around three imperatives, mirroring Check Point’s approach to securing the age of AI:

Exit mobile version