The impact of AI on the speed and scale of cybercrime seems certain to be one of the dominant security themes of 2026. As the World Economic Forum (WEF) pointed out in its recent analysis, “generative AI is boosting the speed at which hackers work, from identifying new security weaknesses to writing the matching malware.” If that wasn’t enough, recent headlines about agentic frontier AI models from Anthropic and OpenAI autonomously instigating breaches have added another item to the list of emerging security priorities. And we already know that threat actors are using agents to automate research and produce convincing personalized phishing or social-engineering messages for likely targets. Then there’s the massive adoption of AI tools and agents on an operational level. These systems are typically connected to business applications and sensitive data. When they are granted excessive permissions, attackers may be able to manipulate or misuse them to act on their behalf. The point is, security teams are in uncharted territory, and as the WEF also explains, “the window for [them] to detect and respond is becoming ever smaller, and they are struggling to keep pace.” Familiar weaknesses Behind the growing sense of alarm, however, the stages of an attack have not fundamentally changed. Take end-user devices, for example, which remain a key target because compromising just one can give an attacker a foothold inside the organization. If we follow the logical chain of events, the damage an attacker can cause will depend in part on the permissions available to the compromised device or account. AI can also accelerate the activities that follow the initial breach by helping attackers gather information and identify likely targets more quickly. The same level of concern applies when an AI agent with broad access to internal systems and data is manipulated to act