Artificial intelligence is helping cybercriminals develop and test attacks faster while creating new vulnerabilities inside organizations that deploy AI tools without adequate safeguards, according to a new Sophos report.
The cybersecurity company’s “2026 State of AI” report, released Thursday, July 23, said it had documented rare but confirmed cases in which attackers used AI to shorten attack timelines and operate at a scale that would normally require larger teams.
The report said AI has not yet created fundamentally new categories of cyberthreats. Instead, attackers are using it to accelerate and expand established techniques, including malware development, security evasion, social engineering, and deepfakes.
Sophos cited an operation it tracks as STAC6994, in which a threat actor left its development framework on a device that investigators could examine.
The attacker reportedly operated a software development environment inside a customer’s network and used about 12 AI agents to write and test attacks against endpoint security products from Sophos, CrowdStrike, and Microsoft Defender.
According to Sophos, the operation produced nearly 80 modules and more than 70 evasion techniques within days. Similar work would typically take a team of human operators several weeks, the company said.
“For the first time we have observed AI being actively used as an operational force multiplier. While the tools and techniques were familiar, the speed of development, testing, and iteration was materially different,” Sophos chief technology officer John Peterson said.
“That is the AI threat that security teams need to prepare against. It means faster cycles and shorter windows to respond, with greater pressure on defenders to detect and contain activity before impact,” he added.
Sophos said AI was also lowering the technical and financial barriers to social engineering and deepfake campaigns by making fraudulent content more realistic and easier to produce at scale.
The report cited a case in the United Kingdom in which a victim was persuaded to invest hundreds of thousands of pounds in a fraudulent AI-powered investment platform after months of AI-themed lessons and coordinated messages.
But Sophos warned that AI is not only being used as an offensive tool. Enterprise AI systems are themselves becoming an increasingly attractive attack surface.
“While the focus of concern is generally being placed on AI as the attacker, it can also be easy to forget that AI is a whole new attack surface for businesses and enterprises around the world,” said Rafe Pilling, director of threat intelligence at Sophos’ Counter Threat Unit.
Coding agents, AI assistants, and open-weight models are increasingly being given access to sensitive corporate systems. This makes their identities, credentials, OAuth connections, API keys, and permissions potential entry points for attackers.
Citing IBM X-Force, the report said more than 300,000 compromised ChatGPT credentials were offered for sale on the dark web in 2025. Sophos said it also observed API keys for Claude, ChatGPT, and Grok being traded in underground marketplaces.
The report found that 71% of large enterprises were already operating AI agents on core business systems, while the number of active agents in enterprise environments had increased by 466.7%.
However, only 16% of companies had implemented governance controls for AI agents, while just 1% had established a dedicated AI security budget, according to Sophos.
“Adoption is a business necessity, but it cannot provide the promised gains if it’s deployed at the cost of a business’s data security,” Pilling said.
“As we are on the ground flour of an AI revolution and we’re building a whole new generation of AI-powered technology stacks, we are at the perfect point to build-in effective governance and security, rather than making it a bolt-on as has happened with prior technological paradigm shifts,” he added.
Sophos said protecting AI systems requires more than faster threat-detection tools. Organizations must also address weaknesses in identity management, governance, third-party software, and supply chains through revised security policies and secure-by-design frameworks.
The report combined research from Sophos’ security and AI teams with endpoint and network observations drawn from the company’s more than 625,000 customers.


