Offensive Security Investments Surge as AI Threats Increase

As cyberattacks become increasingly sophisticated, organizations are turning to artificial intelligence (AI) to gain a competitive edge in cybersecurity. However, this trend has also raised concerns about the potential risks of using AI for malicious purposes. Recent research from Omdia highlights the growing need for offensive security strategies, but also warns of the dangers of relying on autonomous agents that can go rogue.

Theresa Lanowitz, principal analyst at Omdia, spoke with Dark Reading’s senior news director Rob Wright at Black Hat USA 2026 about the shift in enterprise investments towards offensive cybersecurity practices. These include penetration testing, vulnerability assessments, and red teaming – all of which are being fueled by AI-driven threats. According to Lanowitz, organizations are recognizing that traditional cybersecurity methods are no longer effective against AI-enhanced attacks.

One key area of concern is the increasing speed at which threat actors are exploiting new vulnerabilities and launching attacks. To counter this, organizations are looking to use AI on defense as well. However, Lanowitz cautioned that using autonomous agents comes with risks, including the potential for unintended activities or “going rogue.” This can occur when AI models are not properly trained or when they are exposed to adversarial inputs.

The industry’s reliance on resource-hungry and high-cost AI solutions is another concern. Lanowitz noted that organizations are looking to limit the blast radius of these agents, ensuring that they do not cause more harm than good. This requires a delicate balance between leveraging the benefits of AI while mitigating its risks.

The use of agentic AI for penetration testing, red teaming, and other practices is still in its infancy. While it has proven effective for cyberattacks, there are concerns about its potential misuse. Lanowitz emphasized that building trust and responsibility is essential when using AI for offensive security. This includes ensuring that agents are properly trained, monitored, and controlled to prevent unintended consequences.

The research highlights the need for organizations to adopt a more proactive approach to cybersecurity. By investing in offensive security strategies and leveraging AI responsibly, they can stay ahead of the threat landscape. However, this requires careful consideration of the potential risks and consequences of using autonomous agents.

For readers who are considering implementing AI-powered solutions for their organization’s cybersecurity needs, it is essential to weigh the benefits against the risks. This includes ensuring that your team has the necessary expertise to train and monitor AI models, as well as having a clear understanding of the potential consequences of using autonomous agents. By taking a responsible approach to AI adoption, organizations can minimize the risks and maximize the benefits of this powerful technology.


Source: Dark Reading — 2026-08-28