AI-powered cyber threats
AI-powered attacks are the fastest-growing category of cyber threats; deepfakes, automated social engineering, and agentic ransomware are outpacing defensive capabilities.
Research snapshot · updated Apr 22, 2026
Core thesis
Adversaries exploit legitimate GenAI tools at 90+ organisations. The CEO doppelganger — a perfect AI-generated replica commanding the enterprise in real-time — is now operational. Agentic AI handles ransomware reconnaissance, vulnerability scanning, and ransom negotiations without human oversight. Machine identities outnumber human employees 82-to-1. Defensive AI lags offensive AI by 12-18 months.
State of the art (2026)
The threshold moment was Anthropic's November 2025 disclosure of GTG-1002, a Chinese state-sponsored group that turned Claude Code into an autonomous espionage operator against roughly thirty targets — the model executed an estimated 80–90% of the campaign with human operators intervening for only minutes. That collapses the old comfort that AI merely advises attackers; it now runs the operation. The commodity layer has moved in parallel: agentic tooling automates reconnaissance, payload delivery and privilege escalation, the bulk of phishing is now AI-generated, and deepfake voice and video impersonation has become routine in fraud after the Arup case. Defensive AI — XBOW-style autonomous pen-testing, Microsoft Security Copilot, agentic SOC tooling — is real but still trails offensive capability, leaving enterprises exposed during the lag.
Explore the deeper analysis in CanaryIQ
Explore what is covered below. These previews show the structure; log in to read the full analysis.
Signal stack
Evidence stacked leading → lagging
11 signals
Signal stack
Evidence stacked leading → lagging
Technology-native KPIs
Metrics that predict trajectory, tracked over time
1 tracked
Technology-native KPIs
Metrics that predict trajectory, tracked over time
Landscape map
Who builds what — and who depends on whom
72 players · 6 layers
Landscape map
Who builds what — and who depends on whom
Catalyst calendar
Dated events that will move the position
4 ahead
Catalyst calendar
Dated events that will move the position
Technology roadmap
Milestones on the path to maturity
8 milestones
Technology roadmap
Milestones on the path to maturity
Watchlists
Companies, people and papers — each with a remove-by condition
20 · 20
Watchlists
Companies, people and papers — each with a remove-by condition
Decision frameworks
The same call, framed for your desk
Locked
Decision frameworks
The same call, framed for your desk
Thesis changelog
When our view changed, and why
5 updates
Thesis changelog
When our view changed, and why
Change our mind
2 disconfirming conditions
You've read the verdict. The file is much deeper.
The full signal stack, technology-native KPIs tracked over time, the landscape of who depends on whom, the dated catalyst calendar, decision frameworks for every desk, live watchlists and the changelog of every time our call on AI-powered cyber threats has changed — all live inside CanaryIQ.