Opens in a new tab
vmblog logo 2024 wht (updated)

Six AI in Cybersecurity Trends for the New Year

Share: 

David Marshall | Published: December 26, 2025

vmblog-2026-prediction-series   

Industry executives and experts share their predictions for 2026.  Read them in this 18th annual VMblog.com series exclusive.  

By Chris Scheels, vice president of product marketing; Steve Holmes, senior product manager; Nagesh Swamy, product marketing manager, Gurucul

AI is an ongoing boon and bane to cybersecurity operations. What changes over time are the degree and scope of AI’s benefits and issues. Next year’s SIEM, for instance, won’t look like this year’s. Organizations will need to keep close tabs on these changes and work with providers who do the same. Gurucul asked three of its experts to predict what security teams will need to keep top of mind for 2026, and their responses should help teams keep their companies safe while remaining competitive.

Organizations must address the business disruptions caused by AI and automation

As AI-driven response becomes embedded in security operations center (SOC) workflows, organizations can experience a new class of self-inflicted outages. AI systems will confidently take “correct” actions without grasping business context, such as locking out key authentication pathways or shutting down critical operations to contain perceived anomalies. This will require less tolerance for relying too much on AI and accepting such inconsistencies. In 2026, companies will need to stop accepting “the AI did it” as an excuse and formalize human-in-the-loop governance to prevent AI-triggered business downtime. – Steve Holmes

Insider threat behavior will become more successful and evasive via AI

Insider threat actors will increasingly offload the riskiest parts of their actions to AI systems, exploiting gaps in how organizations secure internal AI tools and access models. Instead of creating a noisy footprint, insiders will rely on AI to automate exfiltration, reconnaissance and privilege escalation, which will also make them harder to trace. 2026 is the year insider threats become AI-augmented by default. And what’s more, insiders will no longer be only human; we’ll also see the rise of AI copilots, digital employees and autonomous agents in this mix. – Steve Holmes

The new SIEM baseline will be a shift to real-time threat storytelling

The transition is already underway: SIEMs that deliver isolated alerts are losing ground to platforms that provide full “threat stories.” AI is correlating identity, behavior, asset and timeline data into contextual narratives – giving analysts a complete picture instead of fragmented events. This transition will expose the inadequacy of event-centric SIEMs, pushing the market toward story-first analytics as the new baseline. By 2026, story-first analytics will no longer be a differentiator; it will be table stakes. – Nagesh Swamy

Incident response playbooks that are predictive will reduce response times – and increase accountability worries

AI-driven predictive incident response (IR) is already cutting containment times dramatically, but it will ignite a new challenge: accountability. Security teams will need to justify why predictive models flagged an employee, locked down a resource or initiated early containment activities. As a result, 2026 will see the rise of explainable, auditable IR workflows, especially as federal regulators accelerate AI compliance and transparency. – Nagesh Swamy

AI SOC analysts and data pipeline management will be essential prerequisites for today’s SIEM

By the end of 2026, Data Pipeline Management (DPM) and AI SOC analysts will no longer be “nice to have” add-ons; they’ll become core, bundled components of next-gen SIEMs. Buyers will expect native, integrated AI assistance at every tier of the SOC stack, and vendors relying on bolt-on architectures will lose ground as customers gravitate toward unified, outcome-driven platforms. – Chris Scheels

For AI-driven cyber defense, power infrastructure will be the new bottleneck

Growth in demand and use of AI is exponential, but questions remain on how the AI revolution will be powered. As AI models grow larger and SOC workloads become more compute-intensive, power consumption and cooling limitations will become a genuine cybersecurity risk. Organizations will find that how they power their AI infrastructure, not their talent, will be the new cybersecurity frontier. With new AI resiliency concerns tied to energy availability, expect massive innovation and rapid development of micro-nuclear and non-nuclear power generation technology. – Chris Scheels

Prepare for what’s ahead

AI disrupts business, both for good and for ill. SOC teams and SIEMS will need to continually adjust to maximize security and enable innovation and competitive advantage.

## 

ABOUT THE AUTHORS

Chris Scheels, vice president of product marketing, has been aligning people, processes and technology to drive companies forward for over 20 years.? He has a decade of cybersecurity experience in product marketing and product management.

Steve Holmes, senior product manager, is a product and cyber security leader with 6+ years in product management and over 20 years of experience in IT and cybersecurity. Nagesh Swamy is a seasoned product marketer with 15+ years of expertise across cybersecurity, IT infrastructure and enterprise software.