56%. That is how much AI-driven attacks rose, according to IBM, a finding independently reported by ITPro's coverage of the 2026 breach study. The underlying dataset is still IBM's own, but the direction is corroborated: a criminal crew can now produce far more phishing copy, malware variants and reconnaissance without adding another person to payroll. The global average breach cost reached $4.99 million, according to IBM, turning an ordinary security failure into the financial equivalent of a small acquisition, one where the buyer inherits lawyers, downtime and angry customers instead of assets.
That is the cost side of the ledger. The revenue side, for attackers, has gotten cheaper to run.
The appealing investment thesis is that enterprises will answer machine-speed attacks with machine-speed defense. Security vendors are selling AI analysts that classify alerts, reconstruct attack paths, disable compromised credentials and draft incident reports before the human analyst finishes opening the ticket. Buyers have heard this pitch before, usually beside a dashboard with more red circles than anyone could reasonably investigate.
That skepticism does not erase the underlying shift in attacker economics.
Generative AI changes attacker economics before it changes attacker genius. A mediocre operator can localize social-engineering messages, mimic executive writing patterns, probe exposed infrastructure and vary payloads at a scale that once required specialists, or at least several reasonably caffeinated contractors. IBM's figure does not mean artificial intelligence has invented a new class of crime. It means familiar attacks have become cheaper to manufacture, which is a distinction with real consequences for what defense needs to prioritize.
The Identity Theft Resource Center tracked 3,322 US data compromises in 2025, according to UpGuard, meaning thousands of management teams had to explain to employees or customers that someone else might now possess their personal information. Verizon's latest incident corpus remains valuable precisely because it separates confirmed breaches from the broader sludge of alerts and attempted intrusions Verizon DBIR. That distinction matters when vendors describe every blocked email as proof that civilization narrowly survived Tuesday.
Automated defense has one real job: compress investigation time without creating a new source of reckless administrative action. That sounds pedestrian, but it is the product test. An AI assistant that summarizes endpoint telemetry saves labor; an autonomous agent that revokes a chief executive's credentials during earnings preparation can create its own incident. The winners will combine broad telemetry, reliable identity context and tightly governed execution: observe widely, act narrowly, preserve evidence.
The category is crowded and the incumbents are not standing still.
The market opportunity runs through several categories: security operations, identity, email, cloud posture, data protection and incident response. Existing platforms from Microsoft, Palo Alto Networks, CrowdStrike and Google have distribution plus oceans of telemetry. Startups have cleaner architectures and fewer committees. Neither advantage is permanent.
Automated investigation also threatens the security industry's own pricing model. If software resolves more alerts, customers will question contracts tied to analyst seats, endpoint counts or an ever-expanding pile of modules. Vendors may call the resulting bundles "platformization," a term investors repeat with admirably straight faces; customers may call them volume discounts.
Investors treating every AI security feature as incremental revenue are likely to be wrong. Much of the spending will be substitution. A buyer may fund an autonomous SOC product by eliminating a legacy orchestration tool, reducing outsourced monitoring or refusing another renewal increase. The harder question is whether a vendor owns a control point from which it can take action, whether identity, endpoint, network or cloud workload, or merely writes elegant summaries of somebody else's data.
That control-point question is difficult engineering, not a slide-deck feature.
Reporting pressure also favors automation. The Securities and Exchange Commission can require disclosure of a material cyber incident within four business days after a company determines it is material, according to SEC, meaning counsel, finance and security may be assembling a public account while responders are still working out what the intruder touched. The Federal Trade Commission's breach-response guidance likewise directs businesses to coordinate legal, law-enforcement and individual notifications FTC. Evidence collection is no longer a back-office chore. It feeds disclosure.
There is still a credibility problem. Vendors train models on security data while promising that customer data will remain isolated, decisions will be explainable and hallucinations will somehow respect production permissions. CISA's secure-by-design campaign puts responsibility back on technology providers rather than expecting every customer to configure away product risk, according to CISA, an awkward standard for companies shipping copilots faster than their trust teams can document them.
Attaching a chatbot to an alert queue will not clear that standard.
The best companies will not be those attaching a chatbot to an alert queue. They will prove that automation lowers time to containment, preserves forensic integrity and takes safe action across tools that were never designed to cooperate. Carnival's public breach notice shows the mundane reality behind the category: unauthorized activity, investigation, containment and notification, the ordinary sequence rather than a cinematic duel between rival neural networks Carnival breach notice. Attackers need that automation to work once. Defenders have to trust it every morning.