Industry executives and experts share their predictions for 2026. Read them in this 18th annual VMblog.com series exclusive.
By John Carberry, Solution Sleuth, Xcape, Inc.
During 2026, enterprise technology will undergo a significant transformation as AI evolves from a productivity tool into a core operational layer. This shift, along with the rise of quantum computing, will reshape cybersecurity, infrastructure investment, and workforce priorities.
1. Agentic AI Restructures Work and Security Leadership
The most significant development will be the advancement of Agentic AI systems that can autonomously plan, reason, and act with limited human oversight. This will create dual impacts on the workforce.
Expect targeted layoffs in roles involving repetitive tasks, such as entry-level SOC analysts, junior coders, and help desk staff, as roles centered on repetitive, procedural tasks will continue to compress as automation accelerates.
Conversely, companies will aggressively recruit for strategic roles focused on managing, directing, and auditing large-scale AI systems, leading to high demand for AI Security Engineers, Prompt Engineers, and AI Governance Officers.
The IT sector won’t shrink, but will fundamentally restructure, eliminating procedural roles to fund the hiring of strategic positions.
2. Identity, Deepfakes and the Collapse of Trust
The speed of autonomous AI hacking will also spark a crisis of authenticity. Realistic, real-time AI deepfakes like “CEO doppelg�ngers” will make identity forgery increasingly difficult to detect using traditional methods.
Static authentication and simple passwords are becoming major security risks. Security investment will continue shifting towards unified security, enforcing Zero Trust principles across identity, endpoints and applications.
The biggest organizational threat is the “Shadow Agent”, uncontrolled AI tools operating without proper oversight. Legal repercussions are coming, with the first significant lawsuits holding executives personally responsible for rogue AI actions, creating a new standard of executive accountability.
3. Quantum Computing Forces Cryptographic Change
The rise of quantum computing further complicates things by undermining cryptographic trust. The threat is immediate: adversaries are using “Harvest Now, Decrypt Later” (HNDL) attacks, collecting encrypted data now to decrypt it later.
Information security teams must view current asymmetric encryption (RSA, ECC) as a time bomb. A complete overhaul is needed to implement Post-Quantum Cryptography (PQC), requiring teams to build a Cryptographic Bill of Materials (CBOM) and use hybrid encryption, layering new PQC algorithms with existing ones for extended protection.
To enable this massive computational shift, infrastructure spending will move from generic cloud services to AI-optimized platforms using diverse computing resources. Geopolitical divisions will also drive a focus on AI sovereignty, forcing multinational companies to adopt region-specific IT frameworks to manage data residency and regulations.
4. External Attack Surface Management Becomes Foundational
By 2026, External Attack Surface Management (EASM) will be considered essential security practice, as most successful breaches will still stem from external assets that are either unmanaged or poorly understood.
The attack surface will keep growing as companies embrace cloud-native development, implement AI services, expose more APIs, and become deeply integrated with third-party and machine-to-machine ecosystems. This expansion will increasingly involve transient infrastructure, non-human identities, and AI-powered services that appear and disappear faster than traditional security reviews can keep up with.
EASM monitoring will shift to continuous, automated discovery across DNS, cloud accounts, SaaS platforms, certificates, and exposed identity paths, rather than periodic assessments. AI will become more crucial by correlating ownership, business context, and potential vulnerabilities, enabling security teams to prioritize likely attack targets.
Shadow IT, shadow AI, and shadow multi-cloud presence will continue to be persistent challenges, fueled by the need for speed and decentralized development. Managing these “shadows” will require policy-as-code, deployment guardrails, and real-time visibility integrated directly into CI/CD and AI workflows.
5. Continuous Offensive Security and Threat Hunting Converge
By close of 2026, offensive security has evolved from a sporadic “stunt” to a continuous, machine-speed adversarial-as-a-service approach. The broader idea is developing into Continuous Threat Exposure Management (CTEM), where mapping the whole “exploit chain” spanning cloud, identity, and AI stacks is the objective, rather than merely identifying a vulnerability.
Human red teams will continue to be crucial for ethical oversight and inventive adversary emulation, but fully autonomous, single-AI red teams will emerge for baseline testing.
In close collaboration with engineering and product teams, mature offensive teams will be evaluated by 2026 on their ability to drive repair, retesting, and quantifiable risk reduction in addition to the number of issues they uncover. While AI will significantly automate reconnaissance, attack path mapping, basic exploit generation, and reporting, making offensive security quicker and more continuous, human red teams will still be necessary for inventive weakness chaining, navigating politics and ethics, and turning findings into narratives that have an impact on business. Instead of being completely replaced, agentic AI will begin to resemble a constant “virtual red team” that operates in the background, with human operators guiding goals, establishing boundaries, and managing difficult or delicate tasks.
Threat hunting is inherently proactive, assuming attackers are already inside the network. IAs AI and polymorphic malware transform attack methods, hunting shifts from signature-based detection to focusing on attacker intent and behavior. This is where predictive analytics and high-quality telemetry provide human hunters a significant advantage. Automation is already streamlining threat hunting workflows like data collection, correlation, and initial triage, and agentic AI will further accelerate this. However, replacing human hunters entirely is unlikely, as creativity, intuition, and adversarial thinking are uniquely human skills.
##
ABOUT THE AUTHOR
As Chief Marketing Officer and “Solution Sleuth” at Xcape Inc., John Carberry transforms difficult cybersecurity problems into understandable and practical solutions for clients. With an emphasis on identity, software supply chain security, and cloud resilience, he oversees brand, product marketing, and analyst relations. Carberry is an expert at converting technical details into commercial actions for boards of directors and CISOs. He frequently provides commentary on emerging corporate risk and advocates for practical security. This includes measurable outcomes – not hype – so businesses can advance their technology stack more quickly without introducing unnecessary risk.





