AI cybersecurity predictions for 2026

January 2026 AI & Data Analytics, Information Security

Kaspersky experts outline how the rapid development of AI is reshaping the cybersecurity landscape in 2026 for both individual users and businesses. Large language models (LLMs) are influencing defensive capabilities while simultaneously expanding opportunities for threat actors.

Deepfakes are becoming a mainstream technology and awareness will continue to grow. Companies are increasingly discussing the risks of synthetic content and training employees to reduce the likelihood of falling victim to it. As the volume of deepfakes grows, so does the range of formats in which they appear.

At the same time, awareness is rising not only within organisations, but also among regular users: end consumers encounter fake content more often and better understand the nature of such threats. As a result, deepfakes are becoming a stable element of the security agenda, requiring a systematic approach to training and internal policies.

Deepfake quality will improve through better audio and a lower barrier to entry. The visual quality of deepfakes is already high, while realistic audio remains the main area for future growth. At the same time, content generation tools are becoming easier to use, even non-experts can now create a mid-quality deepfake in just a few clicks. As a result, average quality continues to rise, creation becomes accessible to a much broader audience and these capabilities will inevitably be leveraged by cybercriminals.

Online deepfakes will continue to evolve but remain tools for advanced users. Real-time face and voice-swapping technologies are improving, but their setup still requires advanced technical skills. Wide adoption is unlikely, yet the risks in targeted scenarios will grow, increasing realism and the ability to manipulate video through virtual cameras, making such attacks more convincing.

Efforts to develop a reliable system for labelling AI-generated content will continue. There are still no unified criteria for reliably identifying synthetic content and current labels are easy to bypass or remove, especially when working with open-source models. For this reason, new technical and regulatory initiatives aimed at addressing the problem are likely to emerge.

Open-weight models will approach top closed models in many cybersecurity-related tasks, which creates more opportunities for misuse. Closed models still offer stricter control mechanisms and safeguards, limiting abuse. However, open-source systems are rapidly catching up in functionality and circulate without comparable restrictions. This blurs the distinction between proprietary and open-source models, both of which can be used for unintended or malicious purposes.

The line between legitimate and fraudulent AI-generated content will become increasingly blurred. AI can already produce well-crafted scam emails, convincing visual identities, and high-quality phishing pages. At the same time, major brands are adopting synthetic materials in advertising, making AI-generated content look familiar and visually “normal.” As a result, distinguishing real from fake will become even more challenging for both users and automated detection systems.

AI will become a cross-chain tool in cyberattacks and be used across most stages of the kill chain. Threat actors already employ LLMs to write code, build infrastructure, and automate operational tasks. Further advances will reinforce this trend: AI will increasingly support multiple stages of an attack, from preparation and communication to assembling malicious components, probing for vulnerabilities and deploying tools. Attackers will also work to hide signs of AI involvement, making such operations harder to analyse.

“While AI tools are being used in cyberattacks, they are also becoming a more common tool in security analysis and influence how SOC teams work. Agent-based systems will be able to continuously scan infrastructure, identify vulnerabilities, and gather contextual information for investigations, reducing the amount of manual routine work. As a result, specialists will shift from manually searching for data to making decisions based on already-prepared context. In parallel, security tools will transition to natural-language interfaces, enabling prompts instead of complex technical queries,” adds Vladislav Tushkanov, research development group manager at Kaspersky.

For more information contact Kaspersky SA, +27 11 783 2424, [email protected], www.kaspersky.co.za




Share this article:
Share via emailShare via LinkedInPrint this page



Further reading:

Protect More with SecuVue
Secutel Technologies Surveillance AI & Data Analytics
Whether you are responsible for electronic key management, securing safes and containers, transport operations or high-value equipment, every asset represents an investment that deserves intelligent protection.

Read more...
Amplifying the value of CCTV systems with AI
IoT & Automation Surveillance Entertainment and Hospitality (Industry) Retail (Industry) AI & Data Analytics
Smart AI platforms enable retail and hospitality organisations to turn their existing CCTV investments into proactive security systems and smart retail ecosystems that boost customer service and ROI.

Read more...
Zero-touch automation certificate life cycle management loop
Products & Solutions Information Security Security Services & Risk Management
ManageEngine completes the certificate life cycle management loop with CA-agnostic, zero-touch automation. New post-deployment automation in Key Manager Plus removes the last manual step in certificate renewal as lifespans gradually shrink to 47 days

Read more...
Sophos launches AI-native cybersecurity defence system
News & Events Information Security Security Services & Risk Management
Built for a threat landscape reshaped by AI, Sophos Fusion unites security operations, endpoint, network security, identity, email, and cloud into one defence system that prevents, detects, investigates, and responds at AI speed.

Read more...
From hype to practical value
Genetec AI & Data Analytics
Artificial intelligence is drawing more attention across the physical security industry. In the 2026 Genetec State of Physical Security report, AI ranked alongside access control and video surveillance as a key priority for the year ahead.

Read more...
African cities need intelligence, not smart infrastructure
AI & Data Analytics Government and Parastatal (Industry) IoT & Automation
Too many smart city conversations still begin with the visible symbols of progress: cameras, sensors, apps, dashboards, connected streetlights, smart meters, and control rooms. While useful, none of them on their own makes a city intelligent.

Read more...
How ‘TikTok Brain’ is breaking legacy security training
Training & Education Information Security
Between doomscrolling, rapid-fire Slack notifications, and algorithmic video feeds, the average employee is trapped in an aggressive, highly engineered dopamine loop that automatically shuts down in traditional training situations.

Read more...
Quantum is coming
Infrastructure Information Security
The global cybersecurity landscape is approaching a turning point as quantum computing accelerates faster than most organisations realise; the shift is not a distant, theoretical concern, but a present-day business risk that demands immediate action.

Read more...
Outpacing cyberthreats in the age of AI
SMART Security Solutions Technews Publishing News & Events Information Security
SMARTpod talks to Fred Streefland, Global Field CISO for EMEA at Check Point Software Technologies, about framing modern cyber defence around adaptability, rapid decision-making, and the OODA loop adapted for cybersecurity.

Read more...
Malware attacks on SMBs disguised as AI services
News & Events AI & Data Analytics
From January to April 2026, Kaspersky detected more than 33 300 attacks on small and medium-sized businesses (SMBs), in which malicious or unwanted software for PCs was disguised as popular artificial intelligence (AI) services.

Read more...










While every effort has been made to ensure the accuracy of the information contained herein, the publisher and its agents cannot be held responsible for any errors contained, or any loss incurred as a result. Articles published do not necessarily reflect the views of the publishers. The editor reserves the right to alter or cut copy. Articles submitted are deemed to have been cleared for publication. Advertisements and company contact details are published as provided by the advertiser. Technews Publishing (Pty) Ltd cannot be held responsible for the accuracy or veracity of supplied material.




© Technews Publishing (Pty) Ltd. | All Rights Reserved.