S&P Global Ratings — RatingsDirect
April 1, 2026
The Frontier Of Cyber Risk: AI Will Multiply Threats And Bolster Defenses
AI is changing and amplifying cyber risk in equal measure — speeding up existing threats and existing defenses alike, while introducing genuinely novel risks tied to agentic autonomy and edge deployment.
Key Takeaways
- AI is changing and amplifying cyber risk, increasing both the speed and power of existing threats and defenses, and introducing novel risks — including those related to the autonomy of agentic AI and the distributed, physical nature of edge AI.
- Exposure to AI-related cyber risks is likely routinely underestimated due to assessment frameworks that are insufficiently mature, and due to blind spots created by shadow AI, shadow governance, and unseen escalating autonomy.
- Organizations proactively integrating AI governance as fundamental infrastructure — and adapting it to AI's evolving capabilities — will be best positioned to mitigate AI-related cyber risks and avoid remediation costs, regulatory penalties, and operational disruption.
There is an old adage that change happens slowly, then all at once. Nowhere is this more apparent than at the intersection of AI and cybersecurity, where AI's speed, scalability, and autonomy is revolutionizing both cyber threats and mitigations.
Much of this change stems from AI's amplification of cyber risks. By reducing the cost of attacks and increasing their speed and power, AI empowers attackers. Simultaneously, it is increasing cyber resilience by improving threat and vulnerability identification and shortening defense response times.
The change is not just evolutionary, though. The rise of agentic AI amplifies the threat of attackers compromising and even controlling autonomous AI systems via prompt injection. The deployment of large language models is expanding cyberattack surfaces and exposing organizations to new threats. And risk also arises from AI governance itself, including unmanaged and unregulated AI that threatens to bypass cybersecurity systems.
AI Amplifies Cyber Threats, Old And New
The growing risks posed by prompt injection are emblematic of how AI is introducing and amplifying cyber threats. The attack involves concealing malicious instructions within content that AI agents are designed to trust — emails, documents, webpages, tool outputs. When processed, these instructions can be misinterpreted as legitimate, causing agents to override safeguards, enabling attackers to steal information, and directing AI systems to take unauthorized actions. Prompt injection is characteristic of the low cost and scalability of AI-related cyber threats, and demonstrates how AI is expanding the attack surface beyond coding to semantic inputs.

The speed with which AI system design flaws — particularly in agentic AI systems — can be exploited with prompt injection was demonstrated in early 2026 with attacks on the OpenClaw agentic system. The incident, which resulted in data theft and system hijacking, demonstrated the extent to which AI's increasing capabilities and autonomy exacerbate cyber risks.
The OpenClaw Wake-Up Call
OpenClaw (formerly known as Clawdbot and Moltbot), an open-source agentic system designed to run on personal hardware and act autonomously, suffered widespread breaches in January 2026. OpenClaw's architecture proved highly susceptible to prompt injection — malicious instructions hidden within communications — which led the agent to execute unauthorized commands and exfiltrate confidential data. This vulnerability was compounded by a default trust of all local host connections that enabled the bypassing of authentication and granted attackers control of the agent, while sensitive security and access information stored in plain-text files further exposed it to infostealer malware. OpenClaw's failures highlight a core tension of agentic AI: the features that make agents genuinely useful — broad file access, cross-system command execution, and external service integration — also create danger when governance is lacking.
Prompt injection has evolved into several related attack vectors, each exploiting a different aspect of AI processing and trust architecture, with impacts ranging from data exfiltration to operational disruption and supply-chain risk.
| Type of attack | Description | Primary effects |
|---|---|---|
| Direct injection (jailbreaking) | Attackers directly input commands, often using role playing, instruction overrides, and coding designed to avoid safety policies. | Model misalignment, safety policy violations, unauthorized tool usage, policy-breaking content generation. |
| Indirect injection | Malicious instructions are hidden in websites, documents, and emails that are processed by an AI system. | Data exfiltration and hijacking of AI actions. |
| RAG poisoning | Malicious content is injected into an AI's knowledge base using compromised source documents, search engine manipulation, or direct tampering. | Persistent manipulation of agent reasoning and decision-making. |
| Multimodal injection | Malicious prompts embedded in images or audio inputs — a particular risk for sectors such as health care that use visual data. | Bypassing of text-only safeguards. |
| Session poisoning | Gradual encoding of malicious intent across multi-turn interactions. | Trigger responses and persistent hijacking of agent behavior, typically session-bound rather than system-wide. |
AI Will Be A Key Building Block Of Cyber Defense
AI's strengths as a cyber weapon — speed, scalability, and autonomy — will also make it an effective tool in defense. AI-enhanced security tools can correlate data across millions of endpoints simultaneously, quickly identifying anomalies humans might miss and reducing response times to milliseconds. AI also enables proactive defense: by modeling normal behavior at the user, network, and application levels, AI systems can flag deviations before compromises occur.
| Pillar | Effect |
|---|---|
| Predictive threat modelling | Shifts cybersecurity from a reactive system to one based on anticipation and pre-emption. |
| Automated incident response | Drastically reduces response times, to milliseconds; stops attacks spreading through and between systems. |
| Global scale | Scans millions of endpoints simultaneously for attack-signal correlation, expanding monitoring beyond human capability. |
| Continuous red teaming | AI probes its own infrastructure 24/7 to identify vulnerabilities. |
| Database monitoring | Auditing of RAG systems for poisoned documents. |
| Governance monitoring | Continuous monitoring for unauthorized (shadow) AI use. |
| Compounding resilience | AI-based defenses improve with exposure to risk, sharpening detection capabilities with each attack. |
Fragile Governance Could Prove Costly
While the advantages of AI-enabled cybersecurity make deployment attractive, many organizations will face challenges transitioning to these systems due to a lack of mature, flexible, and operational AI-governance structures. This situation resembles the late-1990s internet era, when companies raced to connect their networks without sufficient guardrails — a "build first, secure later" approach that led to decades of costly remediation for early web infrastructure. Reactive governance is far more expensive than proactive design.
The governance challenge is a balancing act with three distinct failure modes:
Restrictive governance leading to shadow AI
Excessive AI governance can encourage employees to bypass formal controls using easily accessed consumer tools. Unlike traditional shadow IT, shadow AI compounds dramatically with agentic AI — a single unauthorized AI assistant with tools-access can query databases, send emails, modify documents, and execute code entirely outside corporate security perimeters.
Weak governance leading to shadow governance
Transferring consequential decisions to AI systems that resolve by default, rather than following established policy, poses a greater risk than unauthorized use. Organizations deploying AI without rules dictating how it makes decisions allow model architecture and vendor defaults to govern in place of organizational policy — particularly risky in regulated industries where AI-mediated decisions may not meet requirements for human oversight, explainability, or auditability.
Absent governance leading to escalating autonomy
The absence of formal approval thresholds facilitates ungated expansion of AI capabilities. A system that starts as a Q&A interface might gain database access, then email permissions, then code execution rights — each incremental step appearing reasonable in isolation while collectively creating unauthorized autonomous capability, and expanding the attack surface without oversight.
Two Models Of AI Regulation: The U.S. Versus The EU
In the U.S., government agencies have principally taken on a guidance role — NIST's AI Risk Management Framework emphasizes security and robustness as the foundation of trustworthy AI. The EU, in contrast, has the legally binding AI Act, a risk-based framework setting mandatory cybersecurity requirements for high-risk AI systems, with existing systems given about two years to comply or face penalties of up to 7% of global annual revenue. We expect the EU AI Act will influence global regulatory standards, much as GDPR did for privacy.
Edge AI Creates Financial, Operational, And Physical Risks
The focus of AI is increasingly shifting from large cloud-based models to edge AI, where intelligence runs directly on or near devices, vehicles, and industrial systems. This extends cyber risk beyond the digital realm into the physical world, and from a single centrally monitored cloud system into thousands of distributed devices taking decisions and actions in real time. The resulting decentralized vulnerabilities present a qualitatively different risk profile that governance structures built for centralized systems cannot manage.
A key challenge is the permanence problem, in which long-lasting edge devices create a permanent, expanding attack surface of devices that will often outlast their support and security structures. Manufacturing, logistics, health care, and energy companies risk under-allocating capital to secure edge device networks by focusing on initial deployment costs rather than full lifecycle costs. Edge AI also introduces locational and contextual risks — where hackers circumvent digital security by manipulating a device's physical environment — and compromised edge AI can cause immediate physical harm before digital safeguards can intervene, resulting in product liability, safety, and environmental exposure.
Governance, AI Cyber Risk, And Creditworthiness
We expect AI-related cyber risks will increasingly impact creditworthiness, yet the ability of assessment frameworks to capture this risk typically lags exposure across corporate issuers. We consider the key indicators of this risk to be organizational, not technical. Organizations with extensive AI deployment but weak governance — unclear decision-making processes and limited AI-specific security controls — are likely accumulating hidden liabilities. Conversely, companies prioritizing AI governance as a fundamental, built-in pillar of management will be best positioned for resilience. For others, the question is not whether governance failure will result in costs, but when and in what form.
The views expressed are those of the authors and do not necessarily reflect the opinions of S&P Global.