Sophos has released its AI Security 2026 Report, finding that attackers are operationalising AI to collapse attack workflows from weeks to days.
The report finds that AI’s most immediate impact on cybercrime is speed, as well as a rise in attacks using identity as the primary initial access vector (IAV), rather than inventing new attack types at this stage.

Key findings from the Sophos 2026 AI Security Report include:
- AI is compressing attack timelines and accelerating operational readiness.
- Enterprise AI identities, OAuth tokens, agents, APIs, and development tools are becoming high-value targets.
- AI-assisted social engineering and deepfakes are now operational tools.
- Threat actors are incorporating AI into underground markets, recruitment, prompt engineering, jailbreaking, malware development workflows and criminal services.
- AI development infrastructure and supply chains are being targeted.
“Attackers still need initial access, still move laterally and still exfiltrate through observable channels. What has changed is the clock,” said John Peterson, Chief Technology Officer, Sophos. “For the first time we have observed AI being actively used as an operational force multiplier. While the tools and techniques were familiar, the speed of development, testing and iteration was materially different. That is the AI threat that security teams need to prepare against. It means faster cycles and shorter windows to respond, with greater pressure on defenders to detect and contain activity before impact.”


