Industry executives and experts share their predictions for 2026. Read them in this 18th annual VMblog.com series exclusive.
By Girish Chandrasekar, head of product; Daniel Regalado, principal AI security researcher; Amanda Rousseau, principal AI security researcher; Phimm Phonpaseuth, head of AI security solutions engineering; Amy Heng, head of marketing, Straiker
AI has become a major disruptor in just a few years, both for good and evil. That trend will continue into the foreseeable future as white hats and black hats find novel uses for its capabilities. But our experts have zeroed in on specific developments that will significantly impact business in the coming year in terms of security and operations. Here are our top five predictions.
Prediction 1: Secret AI-based “mini apps” will threaten security
In 2026, enterprise employees with no coding experience will create AI-based “mini apps” that connect enterprise tools and data using natural language. This has a lot of potential for productivity, but it also carries major risks, and we are going to see a public incident in which one such mini-app enables critical data exfiltration or other unauthorized actions. As low-code AI spreads faster than governance, enterprises will need to treat these agents like software: with approvals, runtime guardrails and least-privilege access to critical systems. Shadow AI isn’t just prompts; it’s homegrown agents wiring into your crown-jewel systems, and organizations will have to take proactive steps to avoid becoming another breach headline – and significant losses.
Prediction 2: AiPTs will emerge – autonomous, persistent, economically motivated
AI-powered Persistent Threats (AiPTs) will emerge as a new class of threats in 2026. These are autonomous, malicious agents that can replicate, adapt and re-plan against defenses. As AI tool-calling, memory and multi-agent orchestration mature, attackers will weaponize autonomy just as defenders have. Enterprise security teams will need to assume adaptable, self-healing adversaries that live between tools and APIs, and they will need to adopt agent-level telemetry, containment and deception as part of their overall strategy. APT was human-directed; AiPT will be goal-directed. Watch for multi-stage LLMs, botnets using autonomous planning, and red-team findings citing agentic persistence.
Prediction 3: AI agents will power every core cyber function within five years
Soon, AI agents will accelerate every core cybersecurity function, from vulnerability management to detection engineering to digital forensics and incident response (DFIR). Wherever workflows have structured inputs, known decision trees and measurable service-level objectives (SLOs), agents can be embedded as narrow specialists. The result is faster triage and containment, fewer manual errors, and human attention reserved for novel investigations. Security won’t be replaced by AI; instead, it will have tighter coverage thanks to security AI agents, measured by outcomes and governed by policy guardrails.
Prediction 4: Enterprises will formalize a red/blue program to secure AI
2025 was about testing the waters; 2026 is about diving in. As agents integrate into real workflows, enterprises will formalize a red/blue program for AI: pre-deployment agent red-teaming plus continuous runtime guardrails. For enterprises, this will mean adding AI scenarios to existing attack simulations; it will also require pre-production AI penetration testing and deploying guardrails at the tool/API boundary with policy as code and audit trails. We should expect to see new AI red-team budgets in the coming year as a result, and we expect to see control frameworks adding “agent runtime sections,” as well as procurement ask-lists for guardrails and AI incident response.
Prediction 5: AI-native engineers will arise, with significant impact
The new cohort of software engineers may not ever write code from scratch as they rely on AI.
They’ll be incredibly productive, but they’ll fall into pitfalls if they start relying too much on AI, because it isn’t infallible. Already, we’re starting to see applications designed for the agentic future – orchestrating agents, tools and business policies. For enterprises, this change will mean updating SDLC to AADLP (agentic app development lifecycle) and will impact design tool scopes, abuse cases and runtime policy tests. Hiring will shift from “lines of code” to “agent architecture and safety.” Tomorrow’s 10x engineer is a 1x coder and a 10x agent orchestrator.
The human-AI loop
AI has massively changed the cybersecurity landscape and will continue to do so. This includes how software is created, tested and secured. Though it may seem that threats loom from all directions, the digital world’s defenders will continue to apply their expertise and insight to AI solutions and practices designed to safeguard what’s most important to modern organizations.
##
ABOUT THE AUTHORS
Girish Chandrasekar is the Head of Product at Straiker, helping take the company from zero to one. He was previously on the product team at Robust Intelligence (acq. Cisco), and prior to that, he worked in technical roles on Machine Learning teams at Postmates and JPMorgan Asset Management.
Phimm Phonpaseuth, head of AI security solutions engineering, has over 15 years of IT industry experience including roles in support, consulting, systems engineering, software QA and development, and software sales.
Dan Regalado, Principal AI Security Researcher at Straiker, has worked on companies like Symantec, FireEye and Palo Alto Networks hunting APTs and analyzing malware or exploits in the wild.
Amanda Rousseau is a Principal AI Security Researcher at Straiker and a veteran malware reverse engineer who previously served on Facebook’s Red Team and Microsoft’s Offensive Research & Security Engineering (MORSE) team, following earlier roles at Endgame, FireEye, and the U.S. DoD Cyber Crime Center.
Amy Heng is the Head of Marketing at Straiker, where she builds narratives that bridge deep technical insight with powerful storytelling.






