top of page
Search

Summer Cyber Recap: 3+1 Trends in AI and Cybersecurity in 2026 So Far

  • Writer: David
    David
  • 6 days ago
  • 5 min read

AI has become the defining technology trend of 2026, no doubt about that. Whilst in prior years many businesses were only experimenting, we have seen more widespread adoption of generative AI into everyday operations, as everyone is racing to stay on top.


This includes threat actors, who are also making things more efficient at their end, and introducing entirely new security challenges that are still difficult to defend against. At the same time, businesses are discovering that deploying AI securely is often more complicated than deploying AI itself.


As a quick summer refresher, we have compiled four of the top trends that emerged during the first half of 2026.



1. AI Has Changed Social Engineering Forever


For the past 2 decades, security awareness training focused heavily on teaching employees how to recognise phishing emails. They learned to spot poor grammar, suspicious links and elements of time pressure. Unfortunately, some of these characteristics are becoming less effective.


Generative AI allows attackers to produce very convincing emails, both in terms of looks and content, from just a few minutes of recorded speech; they create realistic voice clones, generate fake video messages and impersonate trusted colleagues at a scale that simply wasn't possible before. 


Deepfake technology has become so easily and widely accessible that even the banking sector is feeling the pain. 


This is not necessarily because the technique of the attack has changed, but the quality and believability of the deception has just gone through the roof.


So this year, instead of targeting hundreds of victims with obviously suspicious messages,  attackers have been creating highly personalised campaigns that reference company projects, organisational structures, social media activity and public information. And they do this in minutes. 


Ultimately, it is the people that remain the strongest security controls an organisation has, and they need to be armed with contextual warnings, realistic simulations (training) and continuous reinforcement to be able to confidently detect social engineering attempts. 


One of the key elements of our Cyber Awareness Training Package is to enable the workforce by teaching them how to protect themselves not just in the workplace but also at home, in their private lives. Helping them protect their family makes them more aware and in turn, improves cyber awareness in the business.       



2. Shadow AI Has Become the New Shadow IT


There are clear everyday use cases where AI absolutely excels, including note-taking, summarising meetings, analysing spreadsheets or large data sets, drafting reports, and so on. In fact, AI tools have become so notoriously good at simplifying certain tasks that employees reach for them directly all the time. 


It's just that, as we are humans, we all have preferences, and sometimes those preferences are not fully aligned with the AI assistants used by the business. On the surface, these LLMs are all just web interfaces; they all belong to well-known and trusted brands- what's the harm, right? 


We have seen a significant increase in the use of consumer AI platforms on corporate devices, often without security or IT teams being aware. Sensitive information, customer details, financial data and even contracts and intellectual property are being uploaded into public AI services to simplify day-to-day work.


There is usually no malicious intent whatsoever; employees simply want to be more productive. This phenomenon, often referred to as Shadow AI is becoming one of the largest governance challenges for security teams.


To recap some of the key concerns: 

  • sensitive information is leaving the organisation

  • data residency and regulatory obligations may be breached

  • AI-generated output may contain hallucinations and introduce inaccuracies if not validated

  • the possibility of submitted information being used as training data, and being regurgitated in the future 


We cover this topic extensively in our Cyber Awareness Training Package, but to summarise, the focus is on drawing attention to policies and procedures that already exist in the organisation (we can also provide templates if needed for additional coverage), and raising awareness by explaining the risks associated with the use of consumer AI tooling. 


If technical controls and capabilities exist in the business to filter consumer AI on company devices, these can be reviewed and improved, but in our experience the biggest contribution will always come from incentivising the correct behaviour in the workforce.  


3. AI Agents Need Identities Too


A more advanced use of AI is through deploying autonomous AI agents capable of executing certain technical actions. To do this, they usually need access to the target systems, read documents and execute workflows or interact with other applications.


While these capabilities clearly create a wealth of opportunity, they also introduce an old-school cybersecurity problem, which is to do with identity and access management.


In some environments, agents may inherit Identity and Access Management (IAM) permissions from existing user accounts, use shared service credentials or get granted broad permissions (ie admin) simply because it's the quickest way to make them work.


If an AI agent doesn't have its own identity definition, it is really difficult to determine what systems it should have access to, what actions it is authorised to perform or not, and who is ultimately accountable for its behaviour. Much like we have over the years successfully moved away from running everyday tasks as Local Admin, the AI agents should not have excessive permissions granted.


The principle of least privilege applies just as much to AI as it does to human users.


Every AI agent should have its own unique identity, clearly defined permissions, documented purpose and an accountable human owner. Security teams should also introduce approval workflows for high-risk actions to ensure that agents remain subject to appropriate human oversight (human-in-the-loop).


As AI adoption accelerates, Identity and Access Management is becoming one of the most important foundations of secure AI deployment. We see this as a good thing; it is a familiar problem, which has well-defined solutions and attributable good practice. 


Bonus Trend: Quantum Computing Is Moving into Planning Mode


Quantum computing has been discussed within cybersecurity circles for years, but in 2026 we started seeing some tangible advancements. Specifically, the industry now has access to published quantum-safe cryptography and protocols, which can be used to protect and future-proof sensitive information. 


We don't know when quantum is finally going to become a thing, but when it does, a lot of the methods used to secure data at rest today will become crackable. Think BitLocker, LUKS, encrypted key vaults and encrypted passwords in web application databases.  


Sensitive information encrypted today may still need to remain confidential well into the next decade. This has given rise to the "harvest now, decrypt later" threat, where attackers collect encrypted information and shelve it in storage, expecting that future quantum capabilities will eventually allow access to these data sets.


Luckily, we are seeing demand in this space, and businesses want to have a better understanding of where cryptography exists across their applications and infrastructure, and what its capabilities are. Once this is mapped, it becomes easy to match this to availability in terms of support for quantum-safe cryptography, and businesses can start to plan for and prioritise the updates to these algorithms. 


If you think you would benefit from support in this space, just reach out to us!


Final Thoughts


AI is no longer an emerging technology; in 2026 it has become part of day-to-day business operations. From our perspective, this means that AI should not be treated as a specialism in cybersecurity; we embed it across all of our training and testing services, and treat is an an integral part of the client organisation. 


Consultants on the 45 Cyber Labs team have helped many organisations, large and small, to strengthen their cyber security awareness and resilience. Reach out to learn how we can help secure your ecosystem.


 
 
 

Comments


bottom of page