Industry executives and experts share their predictions for 2026. Read them in this 18th annual VMblog.com series exclusive.
By Paul Davis, Field CISO at JFrog
As artificial intelligence, and especially agentic AI, continues to grow in prevalence and adoption, the security landscape is evolving at a pace that few organizations can match.
In 2026, security leaders will face a convergence of emerging risks that challenge key areas including access, trust, and resilience. This new era will require a fundamental pivot in how organizations manage identities, both human and machine, govern and protect data, and prepare for threats that are not just faster and more complex, but often invisible until it’s too late.
Looking ahead to 2026, security leaders must move beyond reactive measures and embrace more adaptive, forward-thinking ecosystems. By embedding security into every layer of the software supply chain and fostering a culture of continuous innovation, organizations can not only stay ahead of the threat curve but also unlock new avenues for growth and transformation in the digital age.
Prediction 1: Agentic AI will escalate chaos
Agentic AI has already upended traditional security models, as organizations manage, on average, 20 times more non-human identities than human ones – a ratio projected to reach 100 to 1 in the near future.
Attackers are now using AI to automate and scale their methods, generate new exploits, and adapt tactics in real time. As a result, threats have become faster, more persistent, and significantly harder for security teams to anticipate or contain. Security teams face a new class of risks, including exploitation of open-source AI/ML models through the exploitation of public OSS repos for popular repos such as npm, PyPI, Maven, and Open VSX, and new threat vectors affecting MCP ecosystems.
The surge in advanced AI tools, such as Model Control Platforms (MCPs), is raising urgent questions for security teams: How do we build trust in AI, govern its adoption, and ensure secure integration? Governance will play a pivotal role such as the EU AI Act, Cyber Resilience Act (CRA) ,DORA and various state regulations such as California’s AI Transparency Act (SB 942), providing clear standards and accountability to help organizations manage AI risks and ensure secure, responsible deployment.
Ultimately, for agentic AI to be used productively in 2026, developers and ML practitioners must remain actively engaged-never taking their hands off the wheel. AI requires rigorous testing and continuous security checks at every stage of development through to production to ensure these powerful tools remain safe and reliable. For example, teams must establish a collective evidence ecosystem, where every model and its components are verified. This will establish a single source of truth and automated trust at every stage of the AI development lifecycle.
Leaders who integrate robust processes with advanced technologies will create resilient, compliant ecosystems where AI security and data protection become strategic assets, fueling sustainable growth and innovation.
Prediction 2: Zero trust will enter its most challenging phase yet
In 2026, Zero Trust will remain a cornerstone of security, but its implementation will become significantly more complicated adding not a replacement, but an additional burden for CISOs and security teams.
The rapid adoption of agentic AI and non-human identities is reshaping the security landscape, introducing unprecedented complexity to access management and threat detection. In fact, machine identities outnumber human identities by a factor of 45 to 1 on average, and in large organizations, non-human identities outnumber human users by 50 to 1. What’s more, these intelligent agents often bypass traditional silos, making it increasingly difficult to enforce granular permissions and isolate access.
Developers and security leaders must contend with environments where access is not just about human credentials, but also controlling intelligent agents whose permissions are far less transparent. As these new threats evolve, security leaders must shift to a compliance as code approach in 2026, bringing compliance standards to the business level. This means having the tools and visibility needed to determine and demonstrate whether applications are trustworthy, confirm they meet required criteria, and being able to validate every component within their environment.
Traditionally Zero Trust has focused on people (and now NHIs), and IT infrastructure. We can foresee a greater focus on Attribute-Based Access Control (ABAC), or the data being leveraged in AI. At the moment, there are few mechanisms to monitor and control data in the context of Zero Trust access within an AI service, but regulations, and exposure management will drive the need for greater accountability and oversight around how data is integrated into these solutions.
The organizations that will thrive are those that treat Zero Trust as a strategic enabler of innovation, not just a compliance checkbox.
Prediction 3: The role of the security leader will expand
In 2026, the responsibilities of CISOs and CIOs will become even more demanding, as both alert fatigue and change exhaustion intensify. For example, between 2016 and 2024, the number of organizational change initiatives increased by 67%, while employee willingness to support those changes dropped from 74% to 44%, highlighting the challenge of chronic organizational strain.
With expanding responsibilities that now include AI governance, regulatory alignment, and cross-functional risk management, CISOs must be able to communicate technical and business risks to executive leadership. The relentless pace of change, driven by agentic AI, data-centric Zero Trust frameworks, stringent governance requirements, and the looming impact of quantum resilience, means security leaders must evolve from reactive defenders to strategic business enablers.
In this environment, CISOs must be able to translate complex technical risks for C-suite audiences and actively break down organizational barriers. The shift toward this approach became evident in 2025 – a positive step forward for the industry. In 2026, we will see CISOs and CIOs continue to guide their teams through increasing complexity, maintain clarity of purpose, and position security as a fundamental driver of business growth.
As organizations navigate the accelerating convergence of AI, Zero Trust, and quantum-driven risks, the security landscape of 2026 will demand more than technical defenses. The most successful security leaders will be those who embrace change, foster cross-functional collaboration, and embed security into every layer of innovation.
With the right tools and forward-thinking strategies, security leaders have the power to set a new standard for resilient, trustworthy, and innovative software ecosystems. In doing so, they will ensure that business growth is not compromised, but accelerated, in the AI-driven era that will define 2026 and beyond.
##
ABOUT THE AUTHOR
Paul is an experienced IT Security Executive who, as Field CISO at JFrog, works to help CISOs, IT execs and security teams, enhance protection of their software supply chain. Additionally, he advises IT security startups, mentors security leaders, and provides guidance on various IT security trends. Paul also spends his time exploring the latest technologies, DJing, reading, and boating.





