


2026 is the year AI stopped being a future cyber risk and became a present one. Agentic AI systems moved from advisor to operator this year, running multi-step intrusions with little to no human involvement. This report breaks down the five developments that defined the year: AI agents breaching real organisations, software flaws found and exploited faster than they can be patched, attacks reaching critical systems in seconds, deepfake fraud costing millions, and defenders gaining ground using the same technology.

A breakdown of 2026's defining AI security incidents, including the Taiwan government campaign, JADEPUFFER agentic ransomware and multiple cases where AI models from leading developers reached real organisations during testing.
