Experian says 40% of the 5,000 data breaches it serviced in 2025 were AI-powered, and predicts agentic AI will be the leading cause of data breaches in 2026
A few months ago, I received a congratulations letter on my upcoming enrollment at the Ultimate Medical Academy in Tampa, Florida.
Context & Ripple Effects
The related coverage shows a shift from an earlier cybersecurity-industry expectation that AI-enabled attackers would become commonplace to Experian reporting that AI already featured in a substantial share of the breaches it handled.
This arrives alongside broader workplace adoption of AI and rising demand for AI leadership roles, making the security implications of deploying more autonomous AI systems a more immediate operational issue.
First-order effects
- Experian’s clients and other security teams have a clearer signal that AI-assisted intrusion and fraud methods are already material to incident response, rather than a future-only risk.
- Experian’s forecast puts agentic AI at the center of 2026 breach planning, increasing pressure to test controls against autonomous, multi-step attack behavior.
Second-order effects
- Security vendors and enterprise buyers will be pushed to prioritize detection, identity controls, and response workflows that can distinguish and contain AI-accelerated attacks.
- Organizations expanding AI use at work may face stronger internal scrutiny of agent permissions, data access, and oversight, since broader deployment can create more opportunities for misuse or compromise.
Third-order effects
- If AI-enabled attacks continue to rise, cybersecurity competition will increasingly center on whether defensive systems can automate detection and containment as quickly as attackers automate reconnaissance and execution.
- The emerging fault line is likely to be governance of autonomous AI access: enterprises may treat agent authorization and auditability as core security architecture rather than an application-level feature.
The trend: AI is moving from a productivity tool to a dual-use operational layer, forcing security practices to adapt to both AI-enabled attackers and increasingly autonomous enterprise systems.