August 3, 2026

When generative AI emerged just a few years ago, cybersecurity experts warned that it would make it easier for scammers to trick people into sending them money, or that deepfake videos would make it hard to know when to trust the news.  

In 2026, emerging generative AI proved much more capable. Newer models can identify exploits and vulnerabilities in the software that forms the backbone of the global economy. 

While these capabilities have raised alarms inside the world’s largest companies, IEEE Senior Member Kevin Curran emphasizes that day-to-day corporate vulnerabilities haven’t shifted as drastically as the headlines suggest. 

“It’s reframed the conversation from ‘AI helps attackers write better phishing emails’ to AI actually running the operation,” Curran said. “Still, most organizations breached this year will be hit by the same phishing, credential reuse and unpatched software as always.” 

The debate over how much AI has changed the game is no longer academic. We asked five IEEE security experts what’s real, what’s hype and what deserves your attention. Their answers, lightly edited, are below.

What’s the one trend everyone is talking about this year?

Kayne McGladrey

“‘AI agents are the new shiny object. Whether we should be paying attention to something else is a different question. Look at the monocultures, the shared backends and the security tools that process untrusted code by design — they become attack surfaces themselves, whether or not you’ve deployed a single LLM.” — IEEE Senior Member Kayne McGladrey

Has AI tipped the balance toward attackers or defenders?

“AI has tipped the scales toward attackers, for now. Offense only needs one working path, while defense has to remain solid everywhere, 24/7. The balance may even out as agentic detection matures, but the near-term edge is with offense.” — IEEE Senior Member Kevin Curran

What’s happening to the cybersecurity job market, and how is AI reshaping entry-level versus senior work? 

“The market looks less like a broad boom and more like a selective, skills-driven one. AI isn’t replacing cybersecurity work so much as changing the type of work that’s valued. Routine monitoring is being reduced, while judgment, validation and the ability to recognize when AI is wrong matter more. The differentiator is no longer just ‘can you use the tool,’ but ‘can you tell when the tool is misleading you.'” — IEEE Member Rebecca Herold

Learn More: If you want to learn about the future of cybersecurity, its key concepts and career paths, check out this resource page from the IEEE Computer Society

Interested in becoming an IEEE member?

INTERACTIVE EXPERIENCES

Close Navigation