Opens in a new tab
vmblog logo 2024 wht (updated)

Wallarm 2026 Predictions: AI, APIs, and the Coming Convergence

Share: 

David Marshall | Published: November 11, 2025

   

Industry executives and experts share their predictions for 2026.  Read them in this 18th annual VMblog.com series exclusive. 

By Tim Erlin, VP Product, Wallarm 

In the last year we’ve seen massive growth in the API threat landscape, driven in large part by the growth in generative AI. Generative AI apps and agents are built on top of APIs. Agents interface with the world around them through APIs. All of this AI-API growth takes place against the already booming backdrop of partner integrations, product integrations, and revenue generating APIs. In other words, 2025 was the year of the API, and 2026 will be the year of API security.

AI Breaches Abound

I just said 2026 would be the year of API security. Am I already contradicting myself? Actually, AI security is API security, and so this prediction fits right in. As noted, AI apps and agents are built on APIs, so you can’t secure AI without securing those APIs. 

We’ve seen a few notable breaches that involved AI already, but attackers are really just testing the water and AI deployment hasn’t yet reached critical mass. We’re headed there quickly, however. 2026 will be the tipping point for mainstream AI adoption, and along with that adoption will come mainstream AI attacks. I don’t just mean attacking AI apps and agents, but also using AI to become better, more effective attackers. AI-driven exploits give attackers the ability to chain more complex sequences together, effectively targeting business logic instead of atomic exploits. Imagine an AI agent that evaluates the response to each exploit and reasons what the next step might be. Imagine an AI agent that can take an objective and figure out multiple ways to achieve it. Today, multi-step, complex attacks require human involvement (or they have to have deterministic outcomes at each step). AI changes that, and we’ll see those results in 2026. 

Market Convergence on the Horizon

There’s a cyclical relationship between cybersecurity market problems, market definitions, and budget allocation. It’s not a stretch to include VC funding into that equation either. Market segments exist because analysts declare they do, and analysts are influenced by the market problems customers bring to them. In turn, organizations often allocate budget to recognizable market segments that the analysts have declared as valid. 

Application Security has been an established market for decades, but as technology has shifted, new sub-segments have emerged. First Web Application Firewalls (WAF), then API security, Web Application and API Protection (WAAP). Now we’re looking at a heavily funded AI security market emerging. Analysts work hard to define these markets and provide practitioners with sage advice on the tools and capabilities they should care about. 

2026 represents a key turning point for these market definitions. WAF is barely hanging on as a separately defined space, having been largely merged into WAAP. In 2026 we’re going to see the cybersecurity challenge of protecting applications finally encompass both APIs and AI, because ultimately the funding and market definitions usually succumb to the customer problem. In this case, organizations need to protect the utilities they use to generate revenue, whether they’re web applications, APIs, or AI apps. The technology used, for both delivery and protection, are ultimately just the tools to get the job done. 

The Advent of AI Security Standards 

It’s early days for AI security. There are plenty of vendors vying for both the VC funding and customer budget. Organizations, for the most part, are still early in their adoption of generative AI.  While the technology is impressive, this isn’t the first time we’ve seen this pattern. Exciting new tech shows up, adoption feels faster than anything before it, organizations sacrifice previously accepted policies to adopt and deploy, companies are built on it, companies fail when its promise doesn’t pan out, and ultimately, standards emerge to help create that low bar of security. We’ve seen this with virtualization, with cloud computing, and now we’re in the middle of this pattern with AI. It’s time for security standards to start emerging. Personally, I’m betting on A2AS.org. 

## 

ABOUT THE AUTHOR 

Tim Erlin 

Tim Erlin has more than 20 years of experience implementing, evangelizing, conceptualizing, and selling cybersecurity solutions. He spent the early part of his career developing the vulnerability management market at nCircle, growing the customer base from a handful to thousands around the world. Tim has managed products through multiple acquisitions, including nCircle’s acquisitions of Cambia and Clearpoint Metrics, as well as being acquired by Tripwire, Belden, and Fortra. He is an accomplished contributor to the cybersecurity community as a speaker, writer, podcast host, and frequently quoted source in the media. He has expertise in multiple cybersecurity markets, including vulnerability management, configuration assessment, compliance assessment, cloud security, threat intelligence, attack surface management, and cyber risk quantification.