
Faced with a new AI-driven attack surface, it’s time for cybersecurity to take the reins.
In 1997, when ESET conducted its first experiments using neural networks for threat detection, the IT landscape was completely different. Internet connections were limited, and threat actors were mostly hobbyists, researchers, or script kiddies—developing macro viruses and worms to compromise servers and desktops.
Fast-forward to ESET World 2026, and the company has massively expanded its arsenal of machine learning and detection capabilities; but the world is almost unrecognisable. Billions of people and devices are connected, cloud services underpin daily life, and yesterday’s script kiddies have evolved into sophisticated cybercriminal organisations offering malware-as-a-service (MaaS) to anyone willing to pay.
Their targets now extend across the entire digital ecosystem—from endpoints and cloud workloads to IoT devices and critical infrastructure. And adding a new dimension to the threat landscape is artificial intelligence, a powerful tool which is flipping the script on what it means to remain truly cyber-resilient.
Key points of this article:
- Digital opportunities created by AI adoption have surged, making it an effective co-worker, but also a formidable adversary.
- Cybersecurity has always been about keeping defences a step ahead of attackers, but AI is making defences more porous and more difficult to account for. Protection now needs to cover both entry and exit points for users.
- To stay proactively resilient, cybersecurity needs to jump the AI gap and establish a perimeter for users to work confidently within.
- ESET is extending its ESET PROTECT platform with ESET AI Security capabilities, adding ESET AI Agent Security, ESET AI Behavioural Monitoring, and ESET AI Conversation Security.*
- Together, the new sovereign ESET AI portfolio delivers cybersecurity on top of modern IT innovation.
The AI era, and how it’s changing the cybersecurity landscape
The rules of cybersecurity are being rewritten. Attackers are operating at greater speed and scale than ever before, using automation to find and exploit weaknesses before organisations have a chance to respond. In the ESET SMB Cyber Readiness Index 2026, vulnerability exploits and phishing are the top two reasons for cyber incidents (see Figure 1)

Figure 1 Reasons for cyber incidents (Source: ESET SMB Cyber Readiness Index 2026)
Why pick these two specifically?
News reports have shown that AI agents have demonstrated a great deal of intelligence when put to the test identifying vulnerabilities in software products. Reportedly, Anthropic’s Mythos found as many as 271 vulnerabilities in the Firefox browser app alone, and over 23,000 other vulnerabilities across more than 1,000 open-source projects.
That’s just one tool. And, while Project Glasswing’s ethos is respectable and aware of the potential misuse of the best models (noted by the U.S. government as well), a question remains: Should such tools be available to the public at all? What if those same models were used to find and create exploits by a bad actor?
In early 2024, Microsoft and OpenAI reported that they had “not yet observed particularly novel or unique AI-enabled attack techniques,” and described AI largely as a productivity tool for threat actors. But, oops! Just two years later, security researchers from Google are reporting on what may be the first AI-developed zero-day exploit, and ESET Research discovers PromptLock, the first AI-powered ransomware, as well as PromptSpy, an Android malware abusing gen AI in its execution flow.
Thus, as is often the case, tech assumptions age like milk.
Don’t forget about phishing
Let’s circle back to phishing, though. Handmade lures are a thing of the past. AI has vastly accelerated the production of phishing material, in multiple languages, globalising its potential. Some reports point to AI-supported phishing campaigns accounting for more than 80% of observed global social engineering activity. IBM says that AI has made phishing so effective that it now takes just five minutes to craft an email, down from the original 16 hours.
In related news, Gartner reports that as many as 62% of organisations have experienced a deepfake attack—using synthetic media generated or manipulated using AI to appear real.
These numbers are rather high. And, while there are security modules capable of detecting phishing (such as mail security), they’re not foolproof methods. That brings us to yet another problem of the AI age: detection complexity.
(Un)supervised, (un)seen, and (mis)understood
It would be one thing if AI were confined to uses at two opposite poles: defenders and attackers; but that’s not what makes the matter so complicated. As ESET’s 2026 SMB Cyber Readiness Index shows, many SMBs have onboarded AI tools into their systems and are quite aware of the threats they might pose—but they struggle to account for them (Figure 2).

Figure 2 The relationship between SMBs and AI (Source: ESET SMB Cyber Readiness Index 2026).
IBM’s findings detailing how 97% of organisations reporting an AI-related security incident lacked proper AI access controls, and 63% lacked AI governance policies, corroborate this. There’s a lot of pressure here to adapt, as even regulators have switched gears to address AI risks in earnest. The U.S. went as far as to block two market-leading companies from temporarily selling their models to foreign citizens, citing abuse-related risks.
But, wait a minute: abuse by whom? Hackers? Apparently. And yet, this doesn’t address a wider issue at hand, where the development of AI models is moving so quickly that, not only are companies unprepared to properly secure them, but many end users are exposing themselves to new risks as well.
Artificial ignorance
The democratisation of AI has put powerful capabilities into the hands of everyone from business users to hobbyists, students, and so-called “vibe coders,” building applications with little formal security or software development experience.
While this accessibility is one of AI’s greatest strengths, it also creates a growing skills gap: People can now deploy AI-powered workflows—such as agentic AI skills via a tool like OpenClaw—and connect models to sensitive data, or even build production-grade tools long before they fully understand the security, privacy, and governance implications.
Oftentimes, IT security admins may not know which AI tools are being used, what data is being uploaded, whether generated outputs are safe, or whether AI components introduced into workflows can be trusted.
For example, ESET recently analysed 900,000 AI skills from popular repositories, and found that 25,000 were suspicious and over 3,000 were outright malicious. The latter can exfiltrate data, download and execute malware, override user instructions, subtly alter an agent’s behaviour over time, or even modify the skill itself.
AI skills, to put it differently, represent an extension of an AI’s context, and every extension of said context is an attack vector.
Considering how easy it is to download these skills, and via the autonomous nature of platforms that use them, you can see where the problem is.
As such, AI is turning every interaction into a potential security consideration. Prompts, uploaded files, generated code, agents, plugins, and skills all create new paths into business systems and data. The result is a rapidly expanding attack surface—one that many organisations are growing faster than they can govern.
In places like Italy, Czechia, and Slovakia, unapproved AI platform use is actually more common than policies restricting it.
How to survive the AI era securely?
In many ways, cybersecurity has become harder for customers to understand and more difficult to run, and AI considerably ups the stakes

Figure 3 The biggest cybersecurity challenges for SMBs (Source: ESET SMB Cyber Readiness Index 2026).
Lots of organisations know that both security and AI are important, but they still struggle to make sense of the terminology, the categories, and the growing number of tools they are expected to use (Figure 3). This creates a practical gap: Customers may procure more tech tools, but they still lack resources to manage them effectively.
“In an era defined by AI-powered innovation and AI-powered threats, success requires investing in what works. The organisations leading this transitional period aren’t the ones with the biggest security budgets or the most ambitious AI strategies. They’re the ones that align security with business outcomes, give people the context to make smarter decisions, and build on actual observations, not assumptions, for resilience,” said Michal Jankech, Vice President, Enterprise & SMB/MSP.
For SMBs and mid-market organisations, the goal is simple: Make security practical, scalable, and ready for an AI-driven world.
Making security “work” for the AI era
AI represents a paradigm shift. It opens an entirely new landscape of threats, where large language models, AI agents, AI-generated code, AI skills, model supply chains, and AI-driven automation all create new risks that traditional security models were not designed to address. Therefore, introducing more alerts, more dashboards, and more complexity would just add more fuel to the fire.
So, what can be done? Well, ESET has long focused on the continuous refinement of its AI technologies for threat detection, endpoint protection, and backend intelligence, making security simply comprehensive. But while these technologies enable ESET solutions to work smarter, individual, customer-based use of AI requires a separate dimension of security.
ESET PROTECT: Placing customers first in the AI world
Now, ESET PROTECT doesn’t need a deeper introduction because it’s core to the ESET portfolio and has been available for years. However, it requires a bit of realignment to better reflect the needs of customers, helping them evolve and reach secure outcomes in the face of modern AI-enabled threats.
The enablers of these outcomes are novel modules focusing on opening ESET PROTECT up to cover the entire AI scope with new ESET AI Security modules:
ESET AI Agent Security
ESET AI Agent Security is a new security layer within ESET endpoint security applications, developed specifically to address threats coming through the AI ecosystem.
As autonomous AI agents access files, download components, call external services, use repositories, interact with code, or rely on skills and plugins, they may introduce malicious or compromised elements into the customer environment.
AI Agent Security helps protect against this risk by inspecting AI-related components across the entire AI supply chain, including apps, agents, skills, repositories, code, scripts, MCP servers, external URLs, and multi-stage download chains.
ESET AI Behavioural Monitoring
ESET AI Behavioural Monitoring works closely with AI Agent Security, but focuses on what autonomous AI agents do, rather than only on what they access or download. So, while AI Agent Security helps inspect components and supply-chain activity, AI Behavioural Monitoring focuses on the behaviour and actions of autonomous agents instead. It is designed to detect and block malicious or suspicious activity from AI agents, such as agents that attempt to access inappropriate resources, run unsafe actions, or behave outside the expected scope of their task.
For customers, this creates two levels of control. Organisations may choose to block certain AI agents via rules in ESET PROTECT XDR outright, and, where AI agents are permitted, suspicious behaviour can be flagged for investigation as a dedicated incident.
ESET AI Security in practice
The combination of the above security features provides a prevention-first approach, in which ESET not only reacts to the launch of an AI skill, but it also proactively scans for malicious ones.
For example, in the event that there is a safe URL in an AI skill, and later, someone places malicious content on that same safe URL, our technologies should still provide protection afterwards whenever there is an attempt to access such a URL, thanks to the way our detection tech and features are interconnected.