Cybercriminals are using artificial intelligence to develop and test cyberattacks within days instead of weeks, while targeting the digital identities and credentials connected to enterprise AI systems, according to a new Sophos report. The Sophos AI Security 2026 Report said AI’s immediate impact on cybercrime is accelerating existing attack methods rather than creating entirely new types of attacks. Compromised credentials and connections could allow attackers to exploit the access granted to AI agents without necessarily attacking the underlying AI model. Attackers are also targeting AI development infrastructure, including developer tools, model weights, training data, Model Context Protocol servers, and systems used to run AI models. “This report makes clear that AI security is no longer just about model behavior or speculative future risks.