AI Agents Are Getting Better at Hacking. Cybersecurity Could Be the Next Spending Boom.
The concern is particularly acute because agentic AI is designed to operate independently of human oversight.

The artificial intelligence spending boom may be entering a new phase as increasingly capable AI agents demonstrate that the same technology companies are pouring billions into developing could also become a formidable cybersecurity threat.
A series of recent incidents involving models from OpenAI, Anthropic and Meta has intensified concerns about what happens when autonomous AI systems escape controlled testing environments and gain access to real-world computer networks.
The episodes are now helping push cybersecurity toward the top of corporate technology budgets, CNBC noted. The concern is particularly acute because agentic AI is designed to do more than answer questions or generate text.
AI agents can independently plan and execute multistep tasks and adjust their behavior as conditions change. Those abilities can be valuable for legitimate cybersecurity work, but they can also be turned toward finding and exploiting weaknesses.
The risks became difficult to ignore after OpenAI and Anthropic disclosed that models had escaped testing environments and accessed systems belonging to other organizations. Meta subsequently confirmed a similar incident involving one of its models during a cybersecurity evaluation.
Cybersecurity researchers say such testing failures are not entirely new, but the recent disclosures have brought greater attention to the problem as frontier models become more autonomous.
Gene Yu of cyber emergency response company Blackpanda described AI as a "force multiplier" for cyber threats. The technology does not necessarily create more vulnerabilities inside computer systems, he said, but it can dramatically accelerate the process of finding them.
The same capabilities that allow AI to identify attacks can allow it to discover "vulnerabilities and gaps," Yu told CNBC. That effectiveness becomes "alarming" when "AI is not held back."
Blackpanda has already seen signs of escalating demand. The company said its incident response cases across the Asia-Pacific region doubled year over year during the first half of 2026.
The financial implications could be enormous. Gartner previously projected worldwide end-user spending on information security would increase 12.5% in 2026 to approximately $240 billion, after reaching an estimated $213 billion in 2025.
That suggests cybersecurity could become another major leg of the AI investment cycle. Until now, much of the spending frenzy has centered on chips, servers and data centers needed to train and operate increasingly powerful models. Gartner expects total data center spending alone to surpass $650 billion in 2026.
Paul Meeks, head of technology research at Freedom Capital Markets, expects companies to increase cybersecurity budgets on top of their existing AI expenditures rather than redirect money away from the AI buildout.
Meeks expects companies such as Palo Alto Networks and CrowdStrike to be among the biggest beneficiaries, arguing that dedicated security companies are currently more sophisticated at preventing breaches than hyperscale technology providers.
He believes hyperscalers will "take a while to develop something advanced enough." Yu similarly expects "major cybersecurity players" to capture the first wave of additional spending, describing cybersecurity services as "one of the most resilient sectors in the AI revolution."
However, he said large cloud providers could eventually claim a significant share because they have the resources to develop security technology internally or acquire companies quickly. The technological arms race is also increasing pressure for stronger safeguards. "If governments do not have some rules of the game, we're going to be in trouble," Meeks said.
© Copyright IBTimes 2026. All rights reserved.
























