Artificial IntelligencePress Release

Darktrace Report: Over Three-Quarters of Security Professionals Concerned About AI Agent Risk

Launches Darktrace / SECURE AI™, a New Solution Designed to Give Security Teams Visibility and Control Over AI Tools and Agents in the Enterprise

Darktrace, a global leader in Artificial Intelligence (AI) for cybersecurity, has announced the findings of its 2026 State of AI Cybersecurity Report, examining how the rapid adoption of AI into businesses is changing the nature of cyber risk for global enterprises.

The findings highlight increasing concern among cybersecurity professionals about the rise of agentic AI in their organisations, with more than three-quarters (76%) of security professionals surveyed worried about the security implications of integrating AI agents into their organization. That concern is particularly acute at senior levels, with nearly half of security executives (47%) saying they are very or extremely concerned as AI agents increasingly operate with direct access to sensitive data and critical business processes. At the same time, 97% of security leaders agree AI in their own security stack significantly strengthens their ability to defend against bad actors.

Security experts attribute agents’ access to sensitive and proprietary data, their ability to interact directly with critical systems, and a lack of mature governance around their use as key drivers of concern. Data exposure was identified as the top risk (61%), followed by potential violations of data security and privacy regulations (56%) and the misuse or abuse of AI tools (51%). Despite rising risk awareness regarding AI, just 37% of respondent organisations have a formal policy for securely deploying AI, down 8 percentage points from last year’s report.

“Enterprises are embracing AI fast, and while AI tools are helping security teams better defend against attacks, agentic AI introduces a new class of insider risk,” said Issy Richards, VP of Product at Darktrace. “These systems can act with the reach of an employee—accessing sensitive data and triggering business processes—without human context or accountability. Our research shows security leaders are already worried, and this cannot be treated as an afterthought. If AI agents are operating inside your organisation, their governance, access controls, and monitoring are a board-level responsibility, not just a technical one.”

 AI-Powered Attacks Accelerate

Beyond the manipulation of AI agents, the 2026 State of AI Cybersecurity report highlights growing concern that bad actors are using AI to accelerate and scale cyberattacks. Nearly three-quarters (73%) of security professionals say AI-powered threats are already having a significant impact on their organisation. In addition, 87% report that AI is significantly increasing the volume of attacks they face, while 89% say AI is making attacks more sophisticated overall.

Separately, 91% of professionals note that AI is making phishing and other social engineering attacks more sophisticated and effective. Hyper-personalised phishing emerges as the AI-powered attack posing the greatest risk (50%), followed closely by automated vulnerability scanning (45%), adaptive malware (40%), and deepfake voice fraud (39%). Despite widespread recognition of these threats, nearly half (46%) admit they feel unprepared to defend against AI-driven attacks, almost unchanged from 45% twelve months ago. 92%, meanwhile, say that these threats are driving major upgrades to their defences.

AI vs. AI: Defenders Fighting Back

As cyber threats accelerate and IT environments grow more complex, security teams are increasingly turning to AI as a critical weapon in the fight against cybercrime. More than three-quarters (77%) of security professionals reported that generative AI is now embedded in their security stack and nearly all (96%) said that AI significantly boosts the speed and efficiency of their work.

Security teams say AI delivers its greatest value where human analysts struggle most: detecting novel threats and identifying anomalies at speed, with 72% of professionals citing this as the area where AI delivers the greatest impact.

Many organisations are already moving beyond AI that only recommends and toward AI that can take action within defined guardrails. In the Security Operations Centre, 14% say they allow AI to act independently, while a further 70% enable AI to take action with human approval; only 13% keep AI limited to recommendations.

Darktrace Brings Visibility and Control to Enterprise AI

In response to the trends reflected in survey’s findings, and building on its unique Self-Learning AI approach to protecting organisations, Darktrace today also unveiled its latest offering, Darktrace / SECURE AI™. Darktrace / SECURE AI is designed to give security teams visibility and control of how AI tools and agents are being used, what data and systems they can access, and how they behave across the organization. The technology enables security teams to not only manage but safely enable AI usage at scale, across their enterprise.

Darktrace data shows that AI adoption is already creating new visibility gaps across the enterprise. In October, Darktrace observed a 39% month-over-month increase in anomalous data uploads to generative AI services. The average anomalous upload was 75MB, equivalent to around 4,700 pages of documents, significantly increasing the risk of sensitive data leaving the organisation unchecked.

“As AI becomes embedded across core business operations, many organisations are developing a dangerous blind spot,” added Richards. “They no longer have clear visibility into what AI systems can access or how they’re behaving inside the enterprise. Darktrace / SECURE AI isn’t about slowing AI adoption, it’s about giving leaders the visibility and control they need to deploy AI safely, responsibly, and at scale.”

CSA Editorial

Launched in Jan 2018, in partnership with Cyber Security Malaysia (an agency under MOSTI). CSA is a news and content platform focusing on key issues in cybersecurity in the region. CSA is targeted to serve the needs of cybersecurity professionals, IT professionals, Risk professionals and C-Levels who have an obligation to understand the impact of cyber threats.

Related Articles

Leave a Reply

Your email address will not be published. Required fields are marked *