AI is driving cyberattacks with less and less need for human guidance. Check Point Research’s new AI Security Report 2026 shows that artificial intelligence can now carry out large parts of a breach on its own. At the same time, the time between discovering a vulnerability and starting to exploit it has shrunk from days to just hours.
Over the past year, researchers have seen a clear shift in how cybercriminals use AI. Previously, the technology was primarily used to plan attacks or create malicious code. Today, AI can carry out large parts of the attack itself: from identifying vulnerabilities and breaking into networks, to analyzing stolen information and continuing the attack without continuous control from an attacker.
The report is based on real incidents, telemetry data and our own analyses from Check Point Research. One of the most high-profile examples involves a breach against nine Mexican government agencies, where an attacker combined two commercial AI tools to execute over 5,300 AI-generated commands during 34 different attack sessions.
The new research also shows how quickly the threat landscape is changing. The time from when a new vulnerability is disclosed to when a working attack can be developed has dropped to a few hours. At the same time, the number of advanced so-called prompt injection attacks – where attackers try to manipulate AI systems through hidden instructions – has increased sharply in 2026. AI has thus become a new attack surface that organizations need to protect in the same way as networks, cloud services and user accounts.
Another clear trend is that traditional methods of identity verification are becoming less reliable. AI can now create highly convincing voices, faces, documents and videos, making visual checks no longer sufficient as a security measure. In addition, the number of high-risk interactions with corporate AI services has doubled in a year. According to the report, the greatest exposure of sensitive information occurs not through attacks, but when employees share more corporate data than they realize with approved AI tools.
– A year ago, we described AI as a tool that made attackers more effective, says Lotem Finkelstein, Vice President, Check Point Research. What we are seeing now is much more pervasive. AI is actively participating in the attacks themselves, and can perform tasks that previously required an entire team of experienced attackers. The threshold for advanced cyberattacks is rapidly lowering, and defenders can no longer assume that there is a human behind every step. The organizations that succeed most will be those that control how AI is used, protect the AI systems they depend on, and can defend themselves at the same speed as threats evolve.
The full AI Security Report 2026 from Check Point Research is available to read at Check Point blog








