Industry executives and experts share their predictions for 2026. Read them in this 18th annual VMblog.com series exclusive.
By Jaya Baloo, Co-Founder, COO, and CISO, AISLE
This year brought widespread adoption of AI across the enterprise. Security teams now depend on AI for decision support, workflow management and operational efficiency within all areas of the business. They’re now dependent upon these models to increase the speed of response for security incidents, improve the resilience of the model and secure long-term cryptography. Below are predictions for 2026, outlining where organizations will focus as they move to modernize their security programs and prepare for the next round of operational and regulatory requirements.
Autonomous Remediation Will Be a Board-Level Priority
The recent exploitation of MOVEit and F5 BIG-IP illustrated how quickly malicious actors take advantage of the window of opportunity between the disclosure of a vulnerability and the deployment of a patch. CISOs will push AI-native remediation to the forefront as organizations strive to reduce exposure windows from days or weeks to hours. AI-driven systems will classify vulnerabilities based on their real-world exploitability and process approved fixes that comply with regulatory requirements, enabling timely action. Many organizations still encounter considerable delays related to their backlogs of open vulnerability tickets and service-level agreement (SLA) failures. Increased pressure resulting from these vulnerabilities will drive the automation of policy-based controls that will prevent known vulnerabilities from remaining in production environments.
Adversarial AI Testing Will Be Treated Like Pen Testing
Organizations will begin to conduct adversarial stress testing for their AI models in the same manner as they do traditional penetration testing. This becomes more crucial as LLMs are incorporated across operations, including areas like customer support, accounting, finance and security operations centers (SOC) workflows. Every time an AI model is deployed, it opens up additional pathways for potential abuse through prompt injection attacks and indirect prompt poisoning. Standards bodies like NIST and ENISA are formalizing expectations for secure AI deployments, which adds structure around how these risks must be managed. As these requirements take shape, organizations that build adversarial testing into their regular review process will be the ones that meet them and will be in a better position to defend against attacks.
Quantum Readiness Will Decide Vendor Survival in Regulated Supply Chains
Security and procurement teams will screen vendors to determine their ability to migrate to post-quantum cryptography (PQC) standards. NIST’s standardization of Kyber, Dilithium and Falcon has transitioned PQC from a theoretical concept to a real-world deployment model, and governments are establishing timelines that mandate the use of hybrid classical and quantum-safe algorithms in new systems starting in 2026. Cloudflare, AWS, and Google have already begun implementing quantum-safe options for TLS, DNSSEC and firmware signing, creating momentum for the rest of the ecosystem to adopt this practice as well. Regulatory bodies, such as BSI in Germany and MAS in Singapore, have issued adoption roadmaps for the finance and telecom industries, and many contracts now contain cryptographic upgrade clauses. The infrastructure built today will be operational when quantum attacks occur, making early alignment with PQC standards a primary consideration when selecting vendors.
Organizations will need to adapt their approach to managing risk, evaluating vendors and maintaining trust in their systems in response to the rapid changes currently underway. The emergence of new standards for validation, speed of remediation and quantum readiness regarding AI will guide engineering, operations and governance decision-making. Teams that prepare for these changes early will foster increased resiliency and enhanced visibility of their environments.
##





