AI Now Fully Autonomous in Cyberattacks, Check Point Report Reveals
Event summary
- AI has transitioned from assisting to fully operating cyberattacks autonomously, per Check Point's Annual AI Security Report 2026.
- A single operator breached nine Mexican government agencies using two commercial AI tools, executing 5,317 commands across 34 attack sessions.
- High-risk enterprise AI interactions doubled year-over-year, with 87-93% of organizations experiencing at least one monthly.
- Regulators have shortened critical vulnerability remediation timelines to as little as 12 hours due to AI's accelerated exploit development.
The big picture
Check Point's findings highlight a fundamental shift in cybersecurity dynamics, where AI is no longer just a tool for attackers but an autonomous operator. This evolution mirrors broader industry trends of accelerating digital transformation and the growing attack surface created by enterprise AI adoption. The report underscores the need for organizations to secure their AI systems as rigorously as they protect traditional IT infrastructure.
What we're watching
- Defense Speed
- How organizations will adapt to AI-powered attacks that operate at machine speed, requiring equally rapid defensive responses.
- Governance Gap
- Whether enterprises can implement AI governance controls fast enough to match the pace of AI adoption and associated risks.
- Identity Assurance
- The pace at which organizations transition from visual verification to stronger identity assurance methods as AI-synthesized media becomes more convincing.
Related topics
