Three shifts to plan for in 2026
1. Identity is the new perimeter — and it’s AI-tested.
Phishing kits with LLM-driven voice, real-time MFA fatigue orchestration, and OAuth abuse have collapsed the gap between “credential stolen” and “tenant compromised”. ITDR coverage is no longer optional.
2. AI features are shipping faster than AI red teams.
Most LLM features in production today were never adversarially tested. Prompt injection chained with tool use is the new RCE — and it routes around the WAF.
3. Detection engineering has compounding returns.
Static rules are now decisively outpaced. Programs that invest in behavioural detection see MTTD fall by an order of magnitude within two quarters.