primedefence

AI agents in cyberattacks 2026: statistics for SOCs

2026 figures on AI agents used for attack and defense, with the SOC-CMM reading for detection, response and safeguard governance.

Headline figure

77%

of real software vulnerabilities identified by an AI agent in a controlled competition

Source: International AI Safety Report 2026 (DSIT 2026/001, chaired by Yoshua Bengio, more than 100 experts from more than 30 countries, February 2026); cross-checked with Fujitsu 2026 Cybersecurity Predictions and S2 Grupo Cybersecurity Trends 2026.

Executive reading

The 2026 International AI Safety Report, chaired by Yoshua Bengio with backing from the EU, OECD and UN, documents two practical findings for a SOC: AI agents already identify a very high fraction of real software vulnerabilities, and criminal groups plus state-linked actors are using general-purpose AI in their operations. The defense-attack boundary stops being hypothetical. Fujitsu adds a concrete vector: in 2026, prompt injections will appear in unexpected sources like SIEM logs, DNS or infrastructure data that agents process automatically.

For the SOC the implication is twofold. Defensively, AI in triage and enrichment has traction, but the report warns of a gap between pre-deployment and real-world performance. Offensively, SIEM, DNS and infrastructure feeds must be treated as injection surfaces. SOC-CMM measures both pieces: misuse detection capability in Services, safeguard governance in Process, telemetry monitoring in Technology.

Report data

MetricValueReading
Real vulnerabilities found by an AI agent in competition77%Bengio 2026.
Daily general-purpose AI users (global estimate)~1 BBengio 2026.
Companies that published Frontier AI Safety Frameworks in 202512Bengio 2026.
Data breaches related to ransomware in 2025 (estimate)44%S2 Grupo 2026.
Cyberattacks directly or indirectly involving employees88%S2 Grupo 2026.
Share of global ransomware victims in European organizations (2025)22%S2 Grupo 2026.
Time from initial breach to ransomware execution (observed)<24 hS2 Grupo 2026.
Trust in AI handling core functions without supervision42%Fortinet 2026.

What to do with this data

  • Treat SIEM, DNS and vendor feeds as potential prompt injection surfaces.
  • Define guardrails and human approval for high-risk automated actions.
  • Measure the gap between pre-deployment evaluation and production behavior.
  • Inventory production agents and operational dependency by process.
  • Document the telemetry chain and AI decision traceability for audit.

FAQ