Summary
- Microsoft’s 2026 Digital Defense Report treats AI systems both as attack targets and as technology that can increase the speed and scale of conventional attacks.
- The report places agent risk across identities, permissions, data, tools, models, and the wider systems with which autonomous software interacts.
- Existing security controls such as least privilege, identity management, monitoring, and access revocation become more important as agents gain authority to act.
The security problem around enterprise AI is moving beyond protecting models, because autonomous software increasingly derives its useful power from the identities, data, tools, and business systems it is authorised to reach.
Microsoft’s 2026 Digital Defense Report describes artificial intelligence simultaneously as an attack target, a tool that can accelerate conventional cyber operations, and a new enterprise layer whose connections to trusted systems can create additional paths for compromise.
Microsoft says 88% of enterprises are already experimenting with AI agents, while 82% of leaders expect wider deployment within the next 12 to 18 months. Industry projections cited in the report put the number of agents in production at roughly 1.3 billion by 2028.
Those figures are forecasts and survey results rather than a count of autonomous systems already operating, but the direction raises a practical security problem because an agent may be able to read documents, query databases, call APIs, send messages, modify files, trigger workflows, or interact with infrastructure.
Useful permissions create useful attack paths
A conventional chatbot producing an unsafe answer creates one category of risk, whereas an agent that can act on the answer creates another. The same permission that allows software to complete a legitimate task can increase the effect of prompt injection, stolen credentials, malicious tools, compromised memory, or incorrect reasoning.
Microsoft’s report frames the agentic attack surface across several connected areas rather than treating the model as the sole security boundary. Identity, access rights, data, tools, supporting services, and the integrity of software around an agent can all influence what happens after the system receives a malicious or misleading input.
That makes familiar access controls more important rather than obsolete. Agents require identities and permissions much as employees and conventional software services do, but organisations may create large numbers of new machine identities as automation spreads across departments.
An agent should therefore not receive broad access simply because additional permissions make a demonstration more impressive. Least privilege, short-lived credentials, approval gates, audit logs, data classification, network restrictions, and reliable revocation remain relevant when the user of those controls is software.
Microsoft also documents AI systems becoming targets themselves. One case discovered in December 2025 involved a malicious browser extension with more than 600,000 installations harvesting ChatGPT and DeepSeek conversation history, affecting almost 10,000 organisations before mitigation.
Conversation history can contain source code, architecture, customer information, internal documents, and credentials supplied during legitimate work, which gives attackers a reason to target the AI layer even before an agent has permission to execute anything.
AI accelerates familiar cyber operations
Alongside those new targets, Microsoft is seeing AI used across vulnerability discovery, reconnaissance, phishing, malware and exploit development, data analysis, and post-compromise work. The company stresses that fully autonomous attacks are not yet the norm, although portions of the attack chain can increasingly be delegated or repeated with less operator effort.
The report therefore describes change in speed and scale more than a complete replacement of existing tactics. Attackers still rely heavily on people, valid accounts, exposed systems, software dependencies, and trusted access, while AI can help them identify and exploit those weaknesses faster.
Security teams face the same time pressure in reverse because AI can also assist with vulnerability discovery, correlation, investigation, and response. The advantage depends on organisations having enough context around their own systems to distinguish the risks that require action from another stream of automated alerts.
Microsoft says its security environment processes more than 165 trillion signals daily, giving the company a broad but still vendor-specific view of the threat landscape. Its geographic and sector rankings should therefore be read as observations across Microsoft’s environment rather than a census of all cyber activity.
The more durable finding is architectural. AI agents are being connected to the same identities, applications, cloud systems, and data stores attackers already pursue, which means the technology does not create a separate cyber problem so much as enlarge the network of trusted relationships that can be abused.
As organisations give autonomous software more authority, governance decisions around data access, tool use, memory, approvals, and identity become cybersecurity decisions at the same time. The security question is no longer only whether a model can be manipulated, but what the surrounding system allows it to do once manipulation succeeds.












