Hirun | iStock | Getty Images
A series of recent AI hacking incidents has pushed cybersecurity to the forefront of conversation as labs race to develop agent AI from frontier models.
OpenAI and Anthropic announced last week that a model had been compromised from their own testing environment and hacked by another company. Meta then announced that one of its AI models was hacked by another company during a cybersecurity assessment. Several US hedge funds were also targeted in cyber-phishing attacks, but the perpetrators are still unknown.
These episodes are unfolding against a broader cyber arms race fueled by frontier AI models and the inherent risks posed by rapidly changing technological capabilities. For example, AI-powered phishing has been found to be approximately five times more effective than human phishing. So while chips and data centers have dominated the first wave of AI capital spending, cybersecurity could be the next spending boom.
The capabilities that allow AI to identify hacks are the same capabilities that enable AI to exploit “vulnerabilities and gaps,” said Gene Yu of cyber emergency response firm Blackpanda. Blackpanda reportedly doubled its incident responses across the Asia-Pacific region in the first half of 2026 compared to the previous year.

AI has not changed the amount of vulnerabilities in the system, but rather is a “power multiplier” in how quickly these vulnerabilities are discovered, Yu said. Its effectiveness would be “alarming” if “AI is left unchecked.”
This problem is likely to be accompanied by higher prices. Gartner predicts that spending on information security will increase by 12.5% to $240 billion in 2026.
Companies need to spend more on cybersecurity, said Paul Meeks, head of technology research at Freedom Capital Markets. He predicts that this spending will be “on top of” current AI-building spending, rather than being allocated separately. He said finance and healthcare are two areas likely to require significant increases in spending, given their importance to the global economy and making them easy targets for cyberattacks.

One question is whether demand will flow to pure cybersecurity vendors or to hyperscalers with their own technology stacks.
Meeks believes pure-play cybersecurity companies like Palo Alto and CrowdStrike will benefit the most from this spending cycle because hyperscalers “take time to develop something advanced enough.” Additionally, third-party vendors tend to be more sophisticated at preventing breaches, he said.
Jean Yu agrees.
“Big cybersecurity companies will be the first to benefit,” and “cybersecurity services will be one of the most resilient sectors in the AI revolution.” But he believes hyperscalers can also capture this spending boom because they “already have the structural advantage” to build in-house or “acquire rapidly.”
Possible future solutions include regulation and changes in AI system design.
Unless the government has “some rules of the game,” we will run into problems, Meeks said.
Gary Marcus, a professor emeritus at New York University, said that while a lot of money is “pumping into LLMs,” new research needs to be done to build “more controllable” AI systems. He said rogue AI has emerged, but “there’s no good way to control it.”
