Industry executives and experts share their predictions for 2026. Read them in this 18th annual VMblog.com series exclusive.
By Erez Tadmor, Field CTO, Tufin
2025 will be remembered as the year artificial intelligence (AI) stopped being experimental and started behaving like infrastructure. The defining shift was not simply smarter models or larger training runs, but the growing realization that intelligence at scale has physical, economic, and organizational constraints.
Energy consumption, compute scarcity, data quality, and operational risk are no longer secondary considerations; in fact, they are limiting factors that will directly shape what is viable. AI is now subject to the same forces that govern other forms of critical infrastructure: reliability, resilience, cost control, and trust.
As we move into 2026, enterprises will be forced to reconcile AI ambition with architectural discipline, cybersecurity realism, and a renewed focus on accountability in how intelligence is built and applied.
The Need for Sustainable AI
Most conversations around AI next year will move decisively away from “what is possible” to “what is sustainable.” Training and running advanced models has turned power availability, efficiency, and cost predictability into competitive differentiators. Organizations are discovering that the real challenge is not deploying AI, but operating it continuously under real-world constraints.
Those that treat AI as a bolt-on feature – layered onto legacy systems and unmanaged data – will struggle with escalating costs, brittle integrations, and governance gaps. By contrast, organizations that redesign workflows around AI-native decision loops will unlock more durable value. In these environments, intelligence is embedded directly into business processes, enabling faster feedback, tighter iteration cycles, and more consistent outcomes.
The biggest gains will not come from replacing humans, but from compressing time. AI will accelerate analysis, shorten development cycles, and reduce the lag between insight and action. Decisions that once took days or weeks will happen in near real time, changing how organizations plan, respond, and compete. This shift will reshape the workforce, but in an evolutionary way. Roles will increasingly focus on AI orchestration, oversight, and governance; defining intent, validating outputs, managing exceptions, and ensuring that automated decisions align with business objectives and regulatory expectations. Human judgment will become more strategic, not less, concentrating on where automation should stop – and how risk is evaluated.
Securing AI
Cybersecurity will undergo a parallel reckoning. The dominant lesson of 2025 was that breaches are no longer driven primarily by novel exploits or technical sophistication, but by the quiet accumulation of exposure. Identity sprawl, misconfigured networks, excessive permissions, and unmonitored access paths across hybrid and multi-cloud environments have created conditions where small failures cascade quickly.
In 2026, successful organizations will move from reactive security controls to continuous security posture management. Security will be treated less as a defensive perimeter and more as an ongoing exercise in understanding connectivity, access, and how to mitigate the blast radius across the enterprise.
AI as an Attacker and a Defender
AI will be deeply embedded on both sides of the conflict. Attackers will continue to use it to automate reconnaissance, scale social engineering, and adapt tactics faster than manual defenses can respond.
Defenders, meanwhile, will rely on AI to analyze complex network relationships and prioritize remediation based on real risk, rather than theoretical vulnerability. Winning will not mean preventing every breach, something that’s always been an unrealistic goal, but ensuring that breaches cannot become existential events. The focus will shift toward containment, segmentation, and rapid recovery, with success measured by resilience rather than the absence of incidents.
The Role of Data
Data governance and ethics will increasingly sit at the center of this transformation. As AI systems grow more capable of inference, the risk profile changes. The concern is no longer just data leakage, but data misuse, unintended inference, and erosion of legitimacy when decisions cannot be explained or justified. In 2026, enterprises will be judged not only on how well they protect data, but on whether they can clearly articulate how it is sourced, used, transformed, and retained. Regulators, customers, and partners will expect transparency, consistency, and defensibility. High-value outcomes will come from smaller volumes of trusted, well-governed data rather than indiscriminate collection. Privacy-preserving techniques, lineage tracking, and policy-driven controls will move from best practices to baseline requirements for AI at scale.
Digital identity will emerge as a critical connective layer between AI, security, and data. Stronger, cryptographically verifiable identity frameworks have the potential to reduce fraud, enable more precise access control, and support consent-driven data sharing across systems and organizations. They can serve as the foundation for zero-trust architectures and more accountable AI decision-making. At the same time, identity represents a concentrated point of power and risk. In 2026, successful identity strategies will balance assurance with restraint, emphasizing transparency, interoperability, and user trust to avoid becoming tools of overreach or systemic failure.
When Intelligence Becomes Infrastructure
2026 will be defined by a shift from acceleration to accountability. Intelligence will be everywhere, embedded into systems, workflows, and decisions. Organizations that can govern that intelligence, secure it continuously, and earn trust in how it is used will have an advantage. When intelligence becomes infrastructure, security can no longer be a technical afterthought; it has to become a strategic discipline that determines resilience, credibility, and long-term success.
##
ABOUT THE AUTHOR
Erez Tadmor holds a two-decade career in the ever-evolving information security field, marked by his diverse background in managing various product portfolios and verticals. His expertise spans cloud and network security, automation & orchestration, IAM, fraud detection and prevention. As Tufin’s Field CTO, he bridges the gap between customers, marketing, and product teams, educating stakeholders on network security technologies, cybersecurity best practices and Tufin’s solutions. Erez holds a track record of strong leadership in both enterprise and startups cybersecurity product management and strategy development.





