Skip to main content
Return to TrendAI™ Security Blog
AI & emerging technologies

AI and the Evolving Threat Landscape: What Public Sector CISOs Need to Know Now

Public sector CISOs need to grapple with challenges brought about by AI threats: up to 3,600 AI CVEs in 2026, autonomous ransomware, and critical infrastructure risk.

Experts' view (Expert perspective)AIGovernment

Key Takeaways

  • TrendAI™ Research projects between 2,800 and 3,600 AI-related CVEs in 2026, a 31 to 69% increase over the 2,130 disclosed in 2025. AI is amplifying familiar security failures, such as unauthenticated exposure, unpatched software, weak secret management, and abused trust, rather than creating entirely new ones.
  • The Qilin ransomware group went from nearly nonexistent in 2024 to the most active in 2025, with 1,262 confirmed breaches, and ransomware is becoming increasingly autonomous.
  • State-aligned groups tied to China, Iran, North Korea, and Russia are pre-positioning inside critical infrastructure OT environments.
  • For public sector CISOs, the biggest gains come from operationalizing existing security controls and shifting from reactive detection to proactive prevention.

I’ve spent 30 years in cybersecurity watching the threat landscape evolve in ways that would have seemed like science fiction two decades ago. I have to tell you, however, that what’s happening right now with AI and autonomous systems feels fundamentally different. This isn’t just another tool malicious actors have adopted, but rather a force multiplier that’s reshaping how attacks are conceived, executed, and scaled.

If you’re a CISO or security leader responsible for protecting critical infrastructure, government networks, or an educational campus, this is essential reading. The threat landscape we’re operating in today demands a new mindset, and I wanted to walk you through what our research at TrendAI™ is showing us about where we stand and where we need to focus. If you want to go deeper after reading this, you can find all of our research at our Deep Research page and our latest blog posts at the TrendAI Security Blog.

How is AI changing the cyberthreat landscape?

We’re living through what we call the AI-fication of cyberthreats. Attacks are faster, more automated, and more coordinated than anything we’ve seen before. Nation-states are now using AI in more stages of the intrusion lifecycle than we’ve ever tracked. China-aligned threat actors are using generative AI to sharpen exploits and iteratively build malware with speed that manual operations simply can’t match. This is not a theoretical concern anymore. It’s happening today.

Our security predictions report for 2026, titled “The AI-fication of Cyberthreats,” walks through exactly what this looks like on the ground. But here’s what keeps me up at night as someone who’s been tracking threats for this long: We’re seeing autonomous attacks now. An AI agent has run a complete ransomware intrusion on its own, from initial break-in to data destruction, with minimal human oversight. That’s not a prediction anymore. That’s a reality we need to defend against.

How fast are AI vulnerabilities growing?

Here’s a stat that should concern every CISO in the government sector: We’re projecting between 2,800 and 3,600 AI CVEs (Common Vulnerabilities and Exposures) in 2026 alone. That’s a 31 to 69% increase from the 2,130 we saw in 2025. Those numbers come from our report on AI security covering 2025, titled “Fault Lines in the AI Ecosystem,” which analyzed more than 330,000 CVEs and identified more than 6,000 unique vulnerabilities disclosed from 2018 to 2025 that directly affected AI systems. Why the increase? It’s because of the rapid adoption of agentic systems, an expanding landscape of large language models (LLMs), and the continued exposure of critical AI infrastructure that wasn’t designed with security baked in.

The problem isn’t just volume. It’s that we’re operating in a complex ecosystem where AI systems are being deployed faster than security teams can assess them. Our AI security report covering the first half of 2026, titled “Aftershocks: The Hidden Cost of Speed at Scale,” shows that AI isn’t creating a brand-new category of threats. Instead, it’s amplifying the old ones. Unauthenticated exposure, unpatched software, weak secret management, and abused trust are all now playing out at machine speed, and malicious actors are taking advantage. The gap between deployment speed and security maturity is real, and that gap is a target.

Why is operationalization the real security gap?

I’ve observed a consistent pattern across our threat research that I think every government security leader needs to hear: The real problem isn’t that we lack the technology to defend ourselves. The problem is that we’re not operationalizing what we already have.

Misconfigurations persist in security solutions that are absolutely capable of enforcing optimal settings. Identity risks accumulate in platforms that can automate account lifecycle management. We see medium-severity CVEs deprioritized even though we have documented evidence that they enable high-severity exploits. This is an execution problem, not an invention problem.

The TrendAI™ 2026 Cyber Risk Report breaks down this operationalization gap in detail. The government sector, in particular, faces unique challenges with legacy systems, change management processes, and resource constraints that make consistent operationalization even harder. But that’s also where the highest-return defensive work lies.

How is ransomware becoming autonomous?

Ransomware groups like Qilin (aka Agenda) have exploded onto the scene. They went from nearly nonexistent in 2024 to first place in 2025 with 1,262 confirmed breaches, a 1,270% increase, according to the TrendAI™ 2026 Cyber Risk Report.

It’s not just the volume that’s concerning: Ransomware will become increasingly autonomous throughout 2026, using AI to automate exploitation, to analyze stolen data, and even to negotiate with victims.

Think about what that means for your incident response playbooks. Your team won’t negotiate with a human on the other end. They’ll be dealing with automated systems that can adapt faster than your legal and operations teams can move. That’s a different game entirely.

For a deeper look at these trends and how they specifically impact critical infrastructure and government networks, I recommend our research on securing autonomous AI agents with TrendAI™ and NVIDIA OpenShell, where we explore practical approaches to defending against autonomous attacks.

Why is critical infrastructure a prime target for AI-driven attacks?

If there’s one area where the stakes are highest for public sector security leaders, it’s critical infrastructure. Power grids, water systems, transportation networks, and hospitals have become prime targets for a new generation of AI-augmented threats. Our recent report titled “Critical Infrastructure Under Threat: How Frontier AI Changes the Risk Equation,” shows how AI is shrinking what used to be weeks of warning down to hours. This isn’t abstract. We’ve seen more than 75 compromised programmable logic controllers (PLCs) across US critical infrastructure, including water utilities, and more than 30 Polish renewable energy sites hit by the DynoWiper malware.

What concerns me most is pre-positioning. State-aligned advanced persistent threat (APT) groups tied to China, Iran, North Korea, and Russia are actively mapping operational technology (OT) environments to establish persistent access they can use later. At the same time, the convergence of OT and IT networks has become the single largest source of unmanaged exposure, and many operators still lack full visibility into what’s connected. Add in the reality that a power substation can’t be shut down during peak demand and a hospital medical device network can’t simply be taken offline, and you end up with vulnerable software running in these environments for years.

So where do you start? The report lays out eight recommendations, and the top three are ones I’d push every agency and operator to act on now: Build a complete OT asset inventory before malicious actors do, treat virtual patching as a permanent part of vulnerability management rather than a stopgap, and prioritize rapid containment alongside detection. Regulation like the EU’s Network and Information Security Directive 2 (NIS2) is raising the security baseline, but compliance alone won’t close the gap in time. Stronger public-private intelligence sharing matters just as much, because private-sector telemetry is often seeing threats before governments can on their own.

How should agencies shift from reactive to proactive defense?

The core challenge I see with the way the government and public sector (federal, state, and local agencies) have traditionally approached cybersecurity is that we’ve been reactive. We build walls, install sensors, detect intrusions, and then respond. That model is running out of time.

When malicious actors are using AI to compress the attack cycle and automate their operations, waiting for detection is a luxury we can’t afford. Defending against autonomous attacks shifts the conversation from blocking known indicators to understanding and detecting behavior. It means moving from “How do we know we’re under attack?” to “How do we prevent attacks from succeeding in the first place?”

This is where TrendAI™ is focusing our research and platform development. The shift isn’t just philosophical but also architectural. We’re moving toward security models that can predict, anticipate, and prevent attacks before they reach your perimeter. That means understanding your threat actor’s objectives, their tools, their tradecraft, and their likely next moves before they make them.

Our takeaways from the 2026 Threat Intelligence Forum and our research from RSAC 2026 both speak to this evolution. The organizations that win in the threat landscape ahead will be those that leverage their own AI and automation capabilities to shift the asymmetry back in their favor.

Why should public sector CISOs read this research?

I want to be clear about something: This research exists because we at TrendAI™ care deeply about the mission of protecting critical infrastructure and helping government organizations defend themselves. Our 38-year mission has been to make the world safe for exchanging digital information. This isn’t marketing. These are the facts on the ground, drawn from our telemetry, our incident response work, and our partnerships with organizations just like yours.

The research shows us where the threat landscape is headed. It tells you what to prioritize, where to invest your resources, and how to reshape your security posture to meet threats that move at machine speed. Whether you’re managing enterprise networks, critical infrastructure, or classified government systems, understanding AI-driven threats and autonomous attack capabilities is no longer optional.

The organizations that act now, invest in the shift from reactive detection to proactive prevention, and operationalize the security capabilities they already have will be the ones that sleep better at night. The ones that wait will find themselves increasingly outpaced.

I encourage you to dive into our latest research. Read the reports. Challenge the data. Think about what it means for your own organization and your threat model. And if you want to discuss how the threats specifically impact your agency or sector, reach out. This is a conversation we need to have with our partners in government, education, and critical infrastructure.

What are your biggest concerns about AI-driven threats and autonomous attacks? I’d love to hear your perspective. You can reach out to me on X and on LinkedIn, or connect with our threat intelligence team about how we can help strengthen your security posture.

Take care and keep your network secure.

About the author

Jon Clay is VP of Threat Intelligence at TrendAI™. He joined the company as a sales engineer in 1996 and has spent 30 years in cybersecurity, tracking how the threat landscape evolves and translating threat research into practical guidance for security leaders.