AI agent hacks to lead to cybersecurity spending boom
Hirun | Istock | Getty Images
A string of recent AI hacking incidents has pushed cybersecurity to the forefront of the conversation, as labs race to develop agentic AI from their frontier models.
Last week, OpenAI and Anthropic said models broke out of their testing environments and hacked into other companies. Following that, Meta announced that one of its AI models had hacked into another company during a cybersecurity evaluation. Several U.S. hedge funds were also targeted by cyber phishing attacks, though it is still unclear who was responsible.
These episodes are unfolding against a broader cyber arms race being accelerated by frontier AI models and the inherent risks brought by fast-moving technological capabilities. For example, AI-enabled phishing has been found to be around five times more effective than human attempts. So while chips and data centers have dominated the first phase of AI capex, cybersecurity could become the next spending boom.
The capabilities that enable AI to identify hacks are the same ones that allow it to exploit «vulnerabilities and gaps,» according to Gene Yu from Blackpanda, a cyber emergency response firm that saw its incident response for cases across Asia Pacific double year-on-year in the first half of 2026.

AI has not changed the volume of vulnerabilities in a system, but rather is a «force multiplier» to how quickly these vulnerabilities are found, Yu said. Its effectiveness making it «alarming» when «AI is not held back.»
That problem is likely to come with a growing price tag. Gartner estimates that spending on information security is expected to increase by 12.5% in 2026 to $240 billion.
Companies are going to have to spend more on cybersecurity, according to Paul Meeks, head of technology research at Freedom Capital Markets. He predicts the outlays will be «in addition to» the current AI buildout spending, instead of an allocation away from it. Finance and healthcare are two sectors likely to need major increases in spending, he said, given their importance to global economies which also makes them tempting targets for cyberattacks.

One question is whether demand flows toward pure-play cybersecurity vendors or hyperscalers with their own tech stack.
Meeks thinks cybersecurity pure-plays like Palo Alto and Crowdstrike will benefit the most from this spending cycle, as hyperscalers will «take a while to develop something advanced enough.» Plus, third-party vendors tend to be more sophisticated with preventing breaches, he said.
Gene Yu concurs.
«Major cybersecurity players will be the first to capture the upside,» and «cybersecurity services are one of the most resilient sectors in the AI revolution.» However, he thinks hyperscalers can also capture this spending boom as they «already have the structural edge» to either build internally or «acquire at great speed.»
Potential solutions going forward include regulation and changes to AI system design.
If governments do not have «some rules of the game, we’re going to be in trouble,» Meeks said.
Gary Marcus, an emeritus professor at NYU, says that while a lot of money has been «poured into LLMs,» new research has to be done to build AI systems «that are more controllable.» Rogue AI has arrived, he said, and there is «no good way to control it.»
Fuente:
Leer la noticia original