Experian says 40% of the 5,000 data breaches it serviced in 2025 were AI-powered, and predicts agentic AI will be the leading cause of data breaches in 2026
Context & Ripple Effects
Earlier related coverage captured cybersecurity leaders anticipating more routine attacker use of AI; Experian now supplies operational breach-response evidence that AI-assisted incidents are already a material share of cases it handled.
The report also extends the risk from AI-enabled attacks to agentic systems, while related coverage of escalating digital threats against AI executives and data centers shows security exposure broadening around the AI ecosystem itself.
First-order effects
- Organizations using Experian’s breach-response services face a more immediate need to assess whether incident-response, identity, and data-protection controls can detect AI-assisted intrusion and fraud workflows.
- Experian’s forecast makes agentic AI a near-term planning priority for security teams, shifting attention from isolated AI-generated phishing or code to systems that can carry out multi-step actions.
Second-order effects
- Cybersecurity vendors and managed-service providers will face pressure to package defenses around autonomous attack behavior, including faster detection, access controls, and containment rather than solely user-awareness measures.
- Businesses deploying agentic tools internally may face greater scrutiny of permissions, data access, and audit trails, because the same autonomous capabilities that improve workflows can expand the impact of compromised credentials or poorly governed agents.
Third-order effects
- If breach-response data continues to show AI-powered incidents rising, cybersecurity competition is likely to center increasingly on machine-speed defense and identity-centric controls, with agent governance becoming part of enterprise AI adoption rather than a separate security concern.
- The pattern could also sharpen demands for clearer accountability over autonomous systems’ access to sensitive data, though the reported forecast alone does not establish what regulatory response will follow.
The trend: AI is shifting cyber risk from human-operated, episodic attacks toward more automated and potentially autonomous attack-and-defense cycles.