Opens in a new tab
vmblog logo 2024 wht (updated)

Cybersecurity Predictions: What AI will (and won't) do for us in 2026

Share: 

David Marshall | Published: November 25, 2025

   

Industry executives and experts share their predictions for 2026.  Read them in this 18th annual VMblog.com series exclusive. 

By Pieter Danhieux, CEO & Co-Founder and Matias Madou, Ph.D., CTO & Co-Founder, Secure Code Warrior 

It is a fun industry tradition to ponder what the future holds for us on the cybersecurity frontlines, and the past three years of AI dominance have certainly kept us on our toes. Incredible advancements are sure to continue, and so too will our need to stay one step ahead, mitigate risk, and continue to approach the space with critical thinking, creativity, and curiosity. 

AI technology represents one of the most rapid, transformative disruptors to how we live and work, and as cybersecurity professionals, it is our responsibility to stay grounded and sort the wheat (genuine efficiencies and breakthroughs) from the chaff (failure points and risk). 

My co-founder and CTO, Matias Madou, Ph.D., and I consulted our crystal ball (or should that be our NVIDIA GPUs?), and this is what we believe 2026 has in store for us from an AI security perspective:

  • AI will make progress toward eliminating a class of vulnerabilities, such as SQL injection, but it won’t do so seamlessly without a human in the loop: We’ve had a few years to play around with AI coding assistants, AI cybersecurity tools, and most recently, agentic AI models working autonomously on various processes in the SDLC.

Our own experiments with a range of LLMs solving comprehensive code-level security challenges revealed that, in general, most models had a reasonably high success rate in addressing more linear vulnerabilities, such as SQL injection… a problem that has plagued us since Coldplay’s debut on the charts. It would not surprise us if, in 2026, a tool were released that could reliably and consistently detect and remediate SQL injection bugs, essentially eradicating it as a prominent vulnerability class for the first time since its discovery. 

However, there is a catch: With hallucinations and security degradation remaining inherent problems in LLMs, false positives will remain a significant hurdle to overcome. Security-proficient developers will still be key to the safe use of a tool like this and will need the necessary skill set to review and test code before it is deployed.

  • AI will cause a prominent breach, but we won’t achieve global consensus on AI regulation: Research from Aikido Security has revealed that a staggering one in five security breaches is now thought to be caused by AI-generated code. The same report also found that when AI tooling and the code it produces malfunction, security teams and developers still tend to get the blame. In 2026, it’s highly likely that we will live through a high-impact security incident that can be pinned solely on the use of AI-generated code.

It is clear that unchecked use of AI across multiple disciplines, with no guardrails or safety nets, presents an unacceptable risk profile for most, and coding is no different. Websites tracking global AI regulation and policy are helpful, but they give the impression that security leaders will not be subject to GDPR-like legislation that will result in a unified, global push for AI safety as it relates to coding assistants and agentic agents.

In the absence of regulation, these same leaders must still ensure prominent internal guardrails around AI use and developer upskilling in security.

  • Agentic AI, coupled with MCP technology, will provide exciting new software development possibilities, but it won’t be safe to deploy in enterprise environments without security-proficient developers: Comprehensive data from the likes of BaxBench has proved, at least to date, that LLMs and agentic agents cannot yet generate enterprise-ready code, with 62% of the solutions offered by even the best-performing model containing an error or security vulnerability.

Agentic AI and Model Context Protocol (MCP) technology adds a new dimension to frontier AI applications, allowing autonomous, and often seamless, integration into existing workflows to complete set tasks. 2026 is sure to provide further advancement in this area, with fascinating developments in MCP-powered scanning tools, access control tools and other security weapons to add to the arsenal, but it will inevitably be quite a while before true, safe, trusted autonomy can be realized. These will all need careful monitoring by skilled security personnel and developers, the latter of which should be assessed and verified as security-proficient before using such potent tools.

  • AI will continue to struggle with subjective, context-dependent risk profiles, such as Authentication and Access Control, and, as a result, it won’t eliminate good developers: Our research uncovered one of the main pitfalls of LLMs dealing with common security issues, and we found that they seriously struggle with more subjective, contextual vulnerabilities like Authentication, Access Control, and Security Misconfiguration.

These categories represent common, serious threat vectors that will only be exacerbated by the use of AI coding tools, especially given the speed at which they can produce functional code. These areas should be treated as high-priority learning pathways for all developers, especially those in enterprise environments who are now using AI coding assistants as standard in their day-to-day workflows.

  • We will spend another year building AI technical debt, and it won’t be something we can fix quickly or easily: Decisions made now will have a significant impact later, especially concerning technical debt. Experimental commits with AI coding are being performed by developers today at great frequency and speed, and it’s more likely than not that at least some of this work will need to be corrected in the coming years when we all realize that AI solutions were not the catch-all solution to all of our development issues. Whether it’s being fixed by a skilled human, or by a skilled human wrangling better AI, the debt impact remains the same.
  • Agentic AI worms will spread by injecting prompts into other MCPs and forming “sleeper cells” in GitHub repositories, and we won’t get ahead of this issue anytime soon: As we have seen with Anthropic’s latest security discovery, agentic AI can be leveraged for near-autonomous, highly damaging hacking campaigns. With Model Context Protocol security remaining a complex new challenge for security professionals, attacks like this are likely to get worse before they get better… and CISOs with low visibility into which AI tools are in use, what they’re connected to, and how they’re interacting with sensitive repositories will find themselves at a distinct and risky disadvantage.

2026 is sure to bring more mind-boggling, rapid advancement in the AI security landscape, and the industry needs to stay ready, safety-conscious and diligent as we navigate these challenges and explore efficiencies together.

## 

ABOUT THE AUTHORS

Pieter Danhieux 

Pieter Danhieux is the Chief Executive Officer, Chairman, and Co-Founder of Secure Code Warrior. In 2020, Pieter was recognised as a finalist in the Diversity Champion category for the SC Awards Europe 2020, and was awarded Editor’s Choice for Chief Executive Officer of the Year by Cyber Defense Magazine (CDM), the industrys leading electronic information security magazine. In 2016, he was No. 80 on the list of Coolest Tech people in Australia (Business Insider), awarded Cyber Security Professional of the Year (AISA – Australian Information Security Association) and is member of the Forbes Technology Council. 
?
Pieter is also a Principal instructor for the SANS Institute teaching military, government and private organisations offensive techniques on how to target and assess organisations, systems and individuals for security weaknesses. He also serves as an advisory board member of NVISO, a cyber security consulting company in Europe. Before starting his own company, Pieter worked at Ernst & Young and BAE Systems. He is also one of the Co-Founders of BruCON, one of the most awesome hacking conferences on this planet. 
?
He started his information security career early in life and obtained the Certified Information Systems Security Professional (CISSP) certification as one of the youngest persons ever in Belgium. On his way, he collected a whole range of cyber security certificates (CISA, GCFA, GCIH, GPEN, GWAP) and is currently one of the select few people worldwide to hold the top certification GIAC Security Expert (GSE).

 

Matias Madou 

Matias Madou is a researcher and developer with more than 15 years of hands-on software security experience. He has developed solutions for companies such as Fortify Software and his own company Sensei Security. Over his career, Matias has led multiple application security research projects which have led to commercial products and boasts over 10 patents under his belt. When he is away from his desk, Matias has served as an instructor for advanced application security training courses and regularly speaks at global conferences including RSA Conference, Black Hat, DefCon, BSIMM, OWASP AppSec and BruCon.
 
Matias holds a Ph.D. in Computer Engineering from Ghent University, where he studied application security through program obfuscation to hide the inner workings of an application.