Each year, for over a decade, we have asked Australian senior decisionmakers how they see cyber risk, what they are doing about it, and from where they think the next test will come. The themes change each year. However, the underlying question is the same: how do we run a digitally-enabled business when those trying to compromise it are getting faster and more capable?
This year, the answer is shaped by one factor above all others: artificial intelligence (AI). The defining feature of the 2026 cyber environment is the speed at which AI is reshaping both the threat landscape and the defence toolkit. AI has reached nearuniversal adoption across the cohort we surveyed, with 98% introducing AI in the last 24 months.
Threat actors are equally AI-enabled. AI-enabled threats now sit alongside ransomware as the leading concern identified by our respondents; three of the top five named concerns are AI-adjacent. The threat surface is not justlarger, it is mutating, as AI accelerates concentrated attacks, exposes AI systems themselves as targets, and increasingly acts as the attacker with limited human involvement.

