Industry executives and experts share their predictions for 2026. Read them in this 18th annual VMblog.com series exclusive.
By Justin Endres, Head of Data Security, Seclore
For the last decade, many organizations treated security as a necessary constraint, important but disconnected from day-to-day operations. In 2026, that separation collapses.
Agentic AI is no longer just generating content; it is also creating meaningful experiences. It is taking action. These systems read data, update systems of record, trigger workflows, and coordinate decisions at machine speed.
As a result, the security challenge shifts from protecting the perimeter to governing execution, and that shift is already underway. Gartner predicts that by the end of 2026, 40 percent of enterprise applications will feature task-specific AI agents, up from less than 5 percent in 2025.
For security and IT teams, agentic AI brings something new: context and intent. Instead of reacting to alerts, teams can understand why actions occur, reduce false positives, and respond when it matters.
2026 predictions from a cybersecurity expert
Every AI agent gets an identity, and risk scoring becomes enforceable
In 2026, enterprises will stop treating AI agents as helpful features and start treating them as accountable actors. Every agent will have a distinct identity, a clear owner, a defined lifecycle, scoped permissions, step-up approvals for high-risk actions, and a mechanism for rapid revocation in the event of an issue.
Risk scoring alone is not a control. In 2026, it becomes a trigger for enforcement.
Agents authenticate, call APIs, and act across systems. Their blast radius is shaped by identity. Industry guidance around non-human identities and least-privilege access is converging quickly. Once agents act autonomously, identity becomes the only reliable anchor for governance and accountability.
Agent-to-agent communication becomes the next major attack surface
As enterprises move from single assistants to multi-agent systems that include planners, executors, verifiers, and monitors, risk shifts laterally. The issue is no longer traffic moving east to west across networks. It involves decisions, authority, and delegated actions being transferred between agents.
A common incident pattern will emerge. One agent delegates a task, another executes it, and a third modifies a system of record. However, no one can clearly explain who authorized the action, what policy allowed it, or what data left the organization.
This risk is already being formalized. OWASP has published a dedicated Top 10 for Large Language Model Applications, highlighting failure modes introduced by autonomous and agentic workflows.
Academic research has also demonstrated “agent-in-the-middle” attacks that manipulate inter-agent messaging. In response, organizations will enforce authenticated handoffs, constrained delegation, and mandatory audit trails across agent workflows.
Passwordless becomes the default, and identity verification becomes non-negotiable
AI-powered phishing, deepfakes, and automated fraud are eroding trust in traditional authentication. In 2026, passwordless authentication moves from a strategic initiative to the default destination, particularly for privileged access and high-risk workflows.
The real shift is not just passwordless login. It’s a verifiable identity behind every action.
Regulators and standards bodies are already pushing this direction. NIST’s digital identity guidance emphasizes phishing-resistant authentication and stronger identity proofing during enrollment and recovery.
Account recovery has become a primary attack vector rather than an edge case. Enterprises will demand identity systems that can prove who performed an action and demonstrate that proof later, not just at login, but throughout the lifecycle of access.
The most common agent breaches come from connectors and tokens, not model exploits
Most agent-related security incidents in 2026 will be operational rather than exotic.
They will involve over-permissioned SaaS integrations, long-lived API tokens, mis-scoped OAuth grants, and dormant connected applications that no one remembers approving.
Agents derive their power from tool access, and tools run on tokens. Once compromised, those tokens often bypass interactive controls entirely. Microsoft has documented widespread illicit consent grant attacks where attacker-controlled apps gain persistent API access without triggering MFA.
The headline will not be “the model was hacked.” It will be “the agent had access.”
Securing the repository becomes obsolete, governance shifts to retrieval and usage
With retrieval-augmented generation and action-oriented agents, the moment of risk is no longer file access. It is what gets retrieved, summarized, transformed, and reused.
Sensitive data can leak without the file ever moving. An agent can extract a paragraph, summarize it, and paste the substance into an email, chat, or another system. From a business perspective, the impact is the same as if a file were to leave the repository.
In 2026, governance programs mature to control what agents can fetch, how they can transform content, what must be redacted, and where outputs are allowed to go. AI safety becomes a data governance problem rather than a model problem.
Enterprises adopt an unstructured data control plane for AI
Unstructured data contracts, source code, designs, financials, and strategic documents fuel AI and represent the highest-value risk. Repository-centric security cannot keep pace with how this data is actually used and shared.
By 2026, leading organizations will adopt data-centric security models, where protection, policy, monitoring, and revocation are integrated with the data itself. This approach becomes essential when AI agents consume and act on sensitive information at machine speed. It is no longer optional architecture. It is the practical way to scale AI safely.
Security gates move into core business workflows
Security stops being an after-the-fact review and becomes embedded directly into procurement, contracting, collaboration, and vendor onboarding.
Risk-based approvals and evidence-backed decisions move upstream. Rather than slowing the business, embedded controls reduce friction by making decisions predictable and automatable. Security becomes the system that enables controlled execution, not the function that reacts after the fact.
Auditability becomes a KPI for the COO and CFO
In an agentic world, executives still own outcomes even when machines execute the work. Auditability moves from compliance theater to operational necessity.
Boards and operating leaders will expect fast, defensible answers about what agents accessed, what changes were made, what left the organization, and who approved it. This capability directly affects revenue, customer trust, and regulatory exposure. When auditability enables deals and prevents churn, it becomes an executive-level metric.
Regulators shift from policy compliance to evidence-based control
By 2026, regulators will expect proof, not promises. AI governance moves from written policy to demonstrable enforcement.
The EU AI Act emphasizes the importance of traceability, accountability, and risk-based controls for high-impact AI systems.
NIST’s AI Risk Management Framework will similarly center on measurable governance practices that require records and evidence.
Organizations that cannot rapidly produce evidence packs covering identity, authorization, retrieved data, actions taken, approvals, and data movement will struggle to scale AI in regulated environments without slowing the business.
Ways leaders can prepare for 2026
As agentic AI transitions from experimentation to execution, preparation shifts from focusing on tools to emphasizing foundational elements. Organizations that scale safely in 2026 will focus on a small set of structural priorities that keep control durable as automation accelerates.
1. Define agent identities and ownership
Treat every AI agent as a first-class actor, not background automation. Each agent should have a unique identity, a clear business owner, and a documented purpose. Leaders should require defined lifecycles for provisioning, permission changes, and decommissioning. If no one can quickly explain who owns an agent, what it can do, and how it can be shut off, the organization is not ready to scale.
2. Move toward passwordless authentication with defensible identity verification
Passwordless authentication must be paired with robust identity verification, particularly for onboarding, account recovery, and high-risk transactions. Focus on phishing-resistant methods and step-up verification when risk changes, not just at login. The objective is to prove that a verified person or authorized agent performed an approved action and to be able to demonstrate that proof later.
3. Lock down connectors and tokens using least privilege and time-bounded access
Agent risk often comes from integrations rather than models. Inventory connected apps, OAuth grants, and API tokens, then reduce permissions to the minimum required. Tokens should be time-bounded, monitored, and easily revocable. This work is unglamorous, but it significantly reduces blast radius.
4. Govern data retrieval and usage, not just storage
In an AI-driven environment, risk shifts from who can open a file to what information can be retrieved, summarized, transformed, and reused. Governance controls must be applied at the moment data is accessed and used, whether by humans or agents, including where outputs are permitted to go.
5. Adopt persistent, data-centric controls for unstructured data
Unstructured data fuels AI and carries the highest-value risk. Prioritize controls that are integrated with the data itself, enforce usage policies, monitor access, and enable rapid revocation when risk levels change. Persistent protection provides the auditability needed to scale AI without relying on trust or manual oversight.
Together, these priorities move security from a reactive function to an enabling system, allowing enterprises to move faster with AI while maintaining accountability and control.
Conclusion
2026 is the year security becomes the operating system for AI-driven business. This is not because security is expanding its mandate, but because automation is increasing the blast radius.
The organizations that succeed will be those that can move quickly and demonstrate they have maintained control of their sensitive data.
##
ABOUT THE AUTHOR
As CRO, Justin drives revenue growth, expanding the company�s global market presence, and deepens channel relationships. Prior to joining Seclore, Justin held various executive roles at prominent cybersecurity companies, including SolarWinds, AlienVault (acquired by AT&T), and Webroot (acquired by Carbonite).





