AI in Cybersecurity: The AI vs AI Arms Race Reshaping Security in 2026
We talk to a lot of security founders. In 2026, one line keeps surfacing no matter whether the conversation starts on fraud, email, or AI agents: attackers already have AI working for them, and defenders who don't are already behind.
Attack Timelines Are Collapsing From Weeks to Seconds
Rod Schultz, CEO of Bolster AI, points to a "zero-day clock" that's gone "from months to weeks to minutes," heading toward seconds. "The minute it's found, it's going to then be pushed into some sort of attacking apparatus... built using artificial intelligence."
Bolster's own research counted 11.9 million malicious domains registered in 2025 alone, with criminals now running what Rod calls "very sophisticated marketing campaign engines" - buying ads, cloning brand sites, and diverting traffic.
Cyber and Fraud Are Now One CISO-Owned Problem
Rod’s sharpest point is organisational, not technical: "CISOs have been fired when five of their employees got phished. They were not fired when 500 of their customers were phished. That is changing."
Bolster AI calls the resulting exposure a "shadow attack surface." Cyber and fraud, once split between the CISO and legal, are converging onto one desk.
Stopping Phishing Now Requires an AI Agent of Your Own
Shay Shwartz, CEO of Ocean, sees the same shift from the inbox: "nation-state social engineering attacks have become commodity," and every employee now faces attacks once reserved for top-tier targets.
His bet is agents that actively enrich context on a sender or bank account in real time, rather than pattern-matching past attacks. "It's AI against AI... this equation can position us one step ahead of attackers finally."
Following its Lightspeed-led Series A funding round, Ocean says its agents replace "six or even twelve people" per customer, work that was still eating 25-30% of SOC time.
Securing Agents: Discover, Govern, Then Prevent
Archit Lohokare, now CEO of AppViewX after its acquisition of his company EOS, frames agent security in three steps: discover the agents running across the organisation, govern their configuration and risk posture, then prevent harm outright - the step CISOs actually want, "not just see what they're doing."
He expects the category to consolidate fast, predicting "immense amounts of M&A activity" over the next year.
Watch What the Agent Is Thinking, Not Just What It Does
Max Corbridge of Secure Agentics is building on an OpenAI/DeepMind finding that monitoring an agent's reasoning trace, not just its actions, boosted detection accuracy by 35%.
His premise: prompt injection is "an unsolvable problem as declared by the frontier labs," so agents need runtime checks before every move. The UK's NCSC now says offensive AI capability is doubling every four months, down from every two years.
What This Means for Security Hiring
The defenders pulling ahead aren't adding headcount to review alerts; they're hiring engineers who can build the AI doing the reviewing - detection builders at Bolster and Ocean, identity and platform engineers at AppViewX and Secure Agentics who treat an agent's reasoning trace as a security signal.
Max even hires directly from his open-source contributor community. This isn't a traditional SOC hiring plan.
FAQ: AI vs. AI in Cybersecurity
What does "AI vs. AI" mean in cybersecurity?
It refers to attackers using AI to automate phishing, fraud, and exploit development, forcing defenders to deploy their own AI agents to detect and respond at matching speed.
How is AI changing cybersecurity hiring in 2026?
Companies are hiring fewer alert-reviewing analysts and more engineers who can build detection agents, monitor AI reasoning traces, and secure AI agent identities.
Why are cyber and fraud teams merging?
Attackers use the same infrastructure for both, and CISOs are now held accountable for customer-facing fraud, not just internal breaches.
Bottom Line
- Attackers are automating with AI on their timeline, targeting, and campaigns; defenders now need their own AI, not just faster humans.
- Cyber and fraud are converging into a single CISO-owned problem that extends past the firewall to any customer who can be tricked.
- Agent security is fragmenting into discovery, governance, prevention, and runtime monitoring - the winners are precise about which one they solve.
Related reading: What Security Leaders Actually Want From AI SOC Tools · Inside Vorlon: How SaaS and AI Security Found Its Moment
Building a team that can compete on AI-native defence? Talk to Aspiron Search about finding the talent that can out-automate the attacker.