The concept of agentic AI is gaining traction precisely because of this difference. These are systems capable of receiving an objective, analyzing their environment, making decisions, using tools, and executing a sequence of actions with an increasing degree of autonomy. In cybersecurity, this capability opens important possibilities for defense, but it also raises an uncomfortable scenario: attackers can leverage exactly the same advantages.
From Automating Tasks to Automating Decisions
The automation of cyberattacks is not new. For years, there have been bots dedicated to Internet scanning, automated phishing campaigns, malware distribution, brute-force attacks, and tools capable of searching for vulnerable systems at scale.The difference emerges when reasoning and adaptation capabilities are added.
An AI agent could, for example, receive the objective of finding an entry point into a specific infrastructure. Instead of simply executing a fixed list of instructions, it could gather public information, identify technologies used by the organization, prioritize potential attack surfaces, adapt its actions based on the responses obtained, and decide what the next step should be.
This does not mean that armies of artificial intelligences are independently compromising organizations, at least not as a widespread phenomenon. However, many of the building blocks required to create such a scenario already exist.
Until now, much of cybercrime depended on a human coordinating tools and making decisions between one stage and the next. AI agents make it possible to progressively reduce that human intervention.
Defense Is Learning to Act Too
The same transformation is occurring on the defensive side. For years, companies have used machine learning to detect anomalies, analyze user behavior, identify malware, and prioritize alerts. The evolution toward agentic systems seeks to go further, not only detecting a threat, but also investigating what happened and, under certain conditions, taking action.A defensive agent could correlate a suspicious authentication event with unusual endpoint activity, consult additional logs, review threat intelligence, and determine that sufficient evidence exists to temporarily isolate the device or block specific credentials.
A task that previously required several minutes or even hours of human analysis could be significantly reduced.
This introduces one of the most interesting changes of this new phase: response speed is beginning to become as important a variable as detection capability.
In an environment where a machine can execute hundreds of actions while an analyst investigates an alert, responding too late can become practically equivalent to not responding at all.
When One AI Faces Another
The most complex scenario emerges when both sides use autonomous systems. Imagine an offensive agent that detects a vulnerability, attempts to exploit it, and modifies its strategy when it encounters a defensive control. On the other side, a defensive agent identifies that behavior, blocks the source, temporarily adjusts certain rules, and searches for similar indicators across other systems.The attacker changes again, the defender reacts once more, and within minutes a sequence of decisions could occur that today would require the intervention of multiple specialists.
We are still far from claiming that these fully autonomous confrontations are the norm. However, the technological trajectory forces us to consider a question that until recently belonged mainly to theoretical exercises:
What happens when the speed of a cyberattack is no longer limited by the decision-making speed of a human being?
Digital Fraud Is the Perfect Laboratory
While the discussion surrounding autonomous agents advances, there is one area where the impact of artificial intelligence is much more immediate: fraud.Digital scams have rapidly benefited from tools capable of generating convincing text, imitating voices, producing synthetic images and videos, translating messages, and personalizing campaigns for different victims.
The old phishing email full of spelling mistakes no longer necessarily represents modern fraud.
A criminal can use publicly available information about a company to build credible messages, imitate the communication style of an executive, or create a phone call using a synthetic voice. What is concerning is not only the sophistication of each deception, but also the possibility of producing them at scale.
AI reduces time, costs, and technical barriers. All of this changes the economics of fraud.
Financial Fraud Landscape in 2026
The financial sector is particularly exposed to this transformation because it combines three elements that are highly attractive to attackers: money, identity, and enormous volumes of digital transactions.Traditional techniques continue to be effective, such as credential theft, account takeover, phishing, malware, and card fraud, but they now coexist with far more sophisticated social engineering mechanisms.
A phone call apparently coming from a relative, a video conference with someone who appears to be an executive, a perfectly written message that reproduces the usual language of a supplier, or a synthetic identity built from real data and artificially generated content.
The challenge for banks, payment platforms, and governments is that many anti-fraud systems were designed to identify technical patterns. The new generation of attacks seeks to exploit something much more difficult to protect: human trust.
Modern prevention systems can simultaneously analyze behavior, device characteristics, approximate location, transaction history, transaction velocity, and hundreds of additional signals to calculate transaction risk within seconds.
AI helps create more convincing fraud attempts, but it also makes it possible to detect anomalies that would be practically impossible to identify manually among millions of operations.
The Problem of Granting Too Much Control
There is, however, a contradiction. To defend against increasingly fast attacks, organizations need systems capable of responding with greater autonomy. But the greater that autonomy becomes, the greater the potential impact of a wrong decision.A poorly configured defensive agent could block legitimate users, isolate critical systems, or interpret normal activity as an attack.
In certain environments, the damage caused by an incorrect automated response could be comparable to the incident it was attempting to stop.
For this reason, one of the major challenges of agentic AI in cybersecurity will probably not be enabling machines to act, since that capability is advancing rapidly from a technical perspective.
The real challenge will be deciding how far we will allow them to act without asking us first.
A Race That Is Just Beginning
Cybersecurity has always been a competition between attackers and defenders. Every new technology eventually ends up being used by both sides, and artificial intelligence will be no different. What may change is the speed; over time, both sides will become increasingly faster at executing actions.For years, we have talked about automating tools. Now we are beginning to talk about automating decisions. Once both attackers and defenders can observe, decide, and act using machines, the time available to react shrinks dramatically. Perhaps that is the real transformation of 2026.
We are not simply entering an era of attacks created using artificial intelligence. We are entering a stage in which a growing portion of the digital battlefield may unfold at machine speed.
Cybersecurity will have to learn to think at machine speed.
As a conclusion, the evolution of digital fraud and agentic artificial intelligence means that organizations can no longer evaluate their security by considering only the threats they know today. The next challenge will be preparing for attacks capable of automating tasks, chaining actions together, adapting to defensive responses, and exploiting both technical vulnerabilities and human error.
It will no longer be enough to periodically verify whether an application has known vulnerabilities. Organizations will now need to assess much broader scenarios, including web and mobile applications, APIs, infrastructure, financial systems, automated teller machines (ATMs), artificial intelligence models, and, increasingly importantly, autonomous agents capable of interacting with tools, sensitive information, and corporate systems. For this reason, offensive testing will also have to evolve.
At Internet Security Auditors, we work precisely under this principle: evaluating systems from an attacker's perspective before a real attacker finds the path. Our experience includes penetration testing, controlled identification and exploitation of vulnerabilities, application and service assessments, security evaluations for financial environments and ATM systems, as well as specialized testing of artificial intelligence systems and emerging security scenarios involving AI agents.
Because incorporating artificial intelligence does not eliminate traditional risks. It transforms them, accelerates them, and in some cases creates entirely new attack surfaces.
The landscape emerging over the coming years will not simply involve humans attacking systems protected by other humans. Over time, organizations, cybercriminals, and security professionals will all be using automation and artificial intelligence simultaneously.
And in a race where both sides can operate at machine speed, anticipation ceases to be an advantage and becomes a necessity.
If your organization needs to understand how far an attacker could go, assess the security of traditional systems, or test new solutions based on artificial intelligence, Internet Security Auditors can help you validate the security of your environment and propose improvements.
