Industry executives and experts share their predictions for 2026. Read them in this 18th annual VMblog.com series exclusive.
By Peterson Gutierrez, Vice President of Information Security and Interim CISO, Barracuda; Adam Khan, Vice President of Global Security Operations, Barracuda; and Siroui Mushegian, CIO, Barracuda.
The novelty of generative artificial intelligence (AI) is rapidly fading, replaced by a much more demanding operational reality. By 2026, AI will no longer sit on the periphery as a theoretical experiment or a standalone tool for early adopters. Instead, it will form the fundamental architecture of the modern digital landscape, altering not just workflows but entire business models and industry expectations. This shift demands that companies adapt quickly, as failure to do so risks obsolescence in an era defined by rapid technological acceleration.
This transition from novelty to necessity may also bring some friction. As companies attempt to scale from isolated pilot programs to enterprise-wide deployment, they face complex challenges that can easily stall progress. Specifically, organizations are witnessing a collision between legacy security models and autonomous agents, a widening gap between strategic intent and technical execution, and a critical shift in investment from simple accumulation to complex governance. To navigate the year ahead, leaders must accept that AI is fundamentally rewriting the rules of identity, strategy, and operational resilience.
Identity Under Siege: The Rise of Invisible Authentication
Identity is reaching its breaking point as users face fatigue around multifactor authentication (MFA), rotating credentials, and app-specific logins. AI agents will add a new layer of complexity as these tools require user credentials to act on their behalf, often with security as an afterthought. This friction is undermining productivity and creating new vulnerabilities for attacks to exploit. The future of authentication lies in smarter, invisible systems that continuously verify users based on behavior, context, and device trust while reducing the need for passwords or tokens. The industry needs to shift from proving who you are to proving you’re still you.
Balancing Tension Between Attackers and Defenders with GenAI
In 2026, we’ll see that the organizations that succeed with GenAI are those that adopt it with discipline. The technology’s power to exponentially scale capabilities will continue to accelerate for both attackers and defenders. The leaders who pull ahead will shift from a �tool-first’ to an outcome-driven mindset, asking what problems GenAI is truly solving before deployment. They’ll establish robust governance frameworks to mitigate risks like data leakage, enabling safe innovation rather than restricting it. Those who fail to strike this balance will expose their enterprises to unnecessary vulnerabilities.
The AI Implementation Gap: From Pilot Success to Production Reality
2026 will mark a definitive shift where the hype of AI meets the hard ground truth of operational reality. Success will no longer come from simply adopting the fastest algorithms, but from solving the foundational challenges of digital identity, security governance, and scalability. Companies must develop adaptive frameworks not just to deploy AI, but to maintain agility and control as the technology and threat landscape evolve.
As the race between attackers and defenders intensifies, organizations must move beyond isolated pilots to build resilient systems that verify users invisibly, safeguard sensitive data, and manage information with strict discipline. The era of unbounded experimentation is over. Leaders must now focus on building a foundation strong enough to support the future, ensuring that they don’t just possess powerful tools but have the strategic maturity to control them and foster innovation responsibly.
Furthermore, industries that rely on complex data ecosystems like finance, manufacturing, and healthcare will be particularly vulnerable to conflicting data pipelines, inconsistent architectures, and uneven security practices. Without AIOps frameworks and strong governance structures, organizations risk losing visibility and control of their tech stacks and long-term operational resilience. The winners won’t be those with the most AI pilots – it’ll be the organizations that invested in the operational infrastructure to scale securely and effectively.
##





