AI Is Transforming Both Offense and Defense — The Security Market in 2026 and the Decade Ahead

AI Is Transforming Both Offense and Defense — The Security Market in 2026 and the Decade Ahead

Over the past few years, the premises of the cybersecurity conversation have shifted substantially. The old center of gravity was "how do we prevent intrusion" — but today, both attackers and defenders have begun using AI. As attacks become automated and scale at machine speed, defense too is entering territory where human effort alone cannot keep up. In this article, drawing on publicly available market data, we map the security market of the AI era from three angles: where it is growing, where segments overlap, and where caution is warranted.

"AI and Security" Is Actually Three Markets

First, let us sort out the terminology. Lumping everything together as "AI security" obscures more than it reveals; in practice, at least three distinct themes are advancing simultaneously.

The differences among the three become clear when you ask "who is using the AI" and "what is being protected."

The first is the "defend with AI" domain, where the defenders use AI.
Regardless of whether attackers are using AI, enterprises and security vendors use AI to detect, analyze, and block cyberattacks and incidents. Analyzing large volumes of logs and alerts, prioritizing threats, detecting anomalies, and assisting initial response are already entering production use.

The second is the "defend against AI-powered attacks" domain, where the attackers use AI.
The problem here is not attacks on AI systems themselves, but attackers using AI as a tool to make conventional cyberattacks faster, cheaper, and larger in scale. This includes mass generation of phishing copy and voice deepfakes, accelerated vulnerability discovery and reconnaissance, assistance with malware creation, and automated analysis of exfiltrated data.

The third is the "protect AI systems" domain — defending AI itself from attack.
In this domain, AI is neither a tool of defense nor a tool of attack; it is itself the asset to protect. The focus is on the new attack surfaces created by embedding AI into business systems: training-data poisoning, model theft and tampering, prompt injection, contamination of RAG reference data, and abuse of AI agent privileges.

In short, the first is about defenders using AI, the second is about attackers using AI, and the third is about AI itself being attacked.

We have been tracking the third domain from early on. For example, in "LLM-Audit: The Front Lines of LLM Offense and Defense," we laid out the landscape of attacks targeting LLMs themselves and how to defend against them. The starting point of this article is that a theme we have discussed repeatedly since then is now clearly taking shape as a market in its own right.

NIST likewise organizes the relationship between cybersecurity and AI into roughly three areas: "security of AI systems," "AI-enabled attacks," and "AI-enabled defense" [7]. These overlap with one another, but the products involved, the budgets, and the nature of the risks are not identical. When reading market-size figures, it is essential to check what each source includes under "AI security."

The Current Position, in Numbers

For the global cybersecurity market, estimates differ substantially across research firms depending on scope.

MarketsandMarkets projects roughly $227.6 billion for 2025 and about $351.9 billion for 2030 [1], while Grand View Research estimates about $271.9 billion for 2025 and about $663.2 billion for 2033 [2].

Fortune Business Insights, for its part, puts 2025 at about $219.0 billion, reaching roughly $699.4 billion by 2034 [3].

Broadly summarized, the global cybersecurity market stands at roughly $220–270 billion as of 2025 and is projected to exceed $350 billion by 2030.

Some research firms further project it reaching the $660–700 billion range by 2033–2034.

The differences among firms arise less from anyone being simply wrong than from how far each includes hardware, software, professional services, managed services, and so on within the market. Market size is best read not as a single definitive value but as a range conditioned on definitions.

Figure 1: Global cybersecurity market forecasts from three research firms. Definitions and forecast periods differ, so direct comparison is not possible. Chart: Qualiteg

Within that, AI-powered cybersecurity is expected to grow faster than the overall market.

Fortune Business Insights estimates the 2025 market at about $34.1 billion, with a compound annual growth rate of roughly 21.7% from 2026 through 2034 [4]. The share of security spending accounted for by AI is likely to keep rising.

An even newer domain now taking shape is "Agentic AI Security" — protecting and monitoring the behavior, privileges, communications, and tool usage of AI agents.

MarketsandMarkets projects this market growing from about $1.65 billion in 2026 to about $13.52 billion by 2032, a compound annual rate of roughly 42% [5].

A point worth noting here: this does not refer only to "the market for autonomous AI performing security work."

It broadly includes the products and services needed to operate AI agents safely — prompt protection, guardrails, AI red teaming, and agent identity and privilege management. Among the market forecasts referenced here, this is by far the highest growth rate.

That said, it is a projection anchored on a small, newly defined market, so the absolute figures and the market's boundaries themselves carry substantial uncertainty. Even so, as a signal that investment is beginning to concentrate on managing agents' privileges, behavior, and communications, it merits attention.

Note also that these markets overlap. Simply summing the cybersecurity market, the AI security market, and the Agentic AI Security market would double-count — a point to keep in mind.

Figure 2: Comparison of compound annual growth rates (CAGR). The closer a segment is to AI, the faster it grows. Chart: Qualiteg

Why It Is Growing — Five Drivers

The growth is not driven by any single factor. Broadly, there are five.

First, the expanding attack surface. Cloud migration, the spread of IoT devices, and the entrenchment of remote work have dramatically widened the "surface" that must be defended. The era when hardening the perimeter was enough is over; defense is now required per endpoint and per cloud environment.

Second, attackers' use of AI. Mass generation of phishing copy and voice deepfakes, accelerated vulnerability discovery and reconnaissance, assistance with malware creation, automated analysis of exfiltrated data — AI makes existing attacks executable at low cost and large scale.

Third, attacks on AI systems themselves. Techniques that exploit AI-specific weaknesses — training-data poisoning, model theft and tampering, prompt injection, abuse of tools and privileges, contamination of RAG stores and agent memory — have become real-world threats. The more an enterprise entrusts decisions to AI, the more protecting that AI becomes a precondition for business continuity.

What must be protected here is not limited to external attacks. In business use, unintended information leakage is a major risk as well — users entering personal or confidential information into prompts, or model outputs containing such information. Japanese personal information in particular — names, addresses, organization names, context-dependent identifiers — can be hard to capture with simple pattern matching. We have covered this challenge on an ongoing basis in "Defending Corporate Information in the LLM Era" and our articles on Japanese PII detection technology.

Fourth, tightening regulation. In the EU especially, a series of measures is in motion: NIS2, which requires risk management and incident reporting from essential entities; DORA, which defines digital operational resilience for the financial sector; the Cyber Resilience Act, which imposes security requirements on digital products; and the EU AI Act, which requires AI risk management, transparency, and governance. The EU AI Act entered into force in August 2024; its prohibitions and AI-literacy obligations began applying in February 2025, and its governance rules and GPAI (general-purpose AI) obligations in August 2025. Most provisions apply from August 2026, but the political agreement of May 2026 set out a schedule under which the rules for certain high-risk uses under Annex III apply from December 2027, and AI systems embedded in regulated products from August 2028 [8]. Corporate motivation has shifted from "should do" to "must do."

Fifth, shortages of people and skills. In ISC2's 2025 study, the shortage of needed skills has come to be recognized as a heavier problem than simple headcount shortfalls. AI-related skills topped the most-sought list for the second consecutive year (41% of respondents), followed by cloud security (36%) [6]. That year, the study also discontinued publishing its long-running "workforce gap" headcount estimate, shifting emphasis from numbers of people to capabilities and skills. The need to process floods of alerts and logs with limited staff is pushing automation of analysis, prioritization, and initial response.

In AI-versus-AI Combat, What Actually Separates Winners

The pattern of attackers using AI and defenders countering with AI will only become more common.

What decides the outcome, however, is not simply whose model is more capable or who learns faster. What matters is how much high-quality telemetry (monitoring data) you can gather; whether you can see the whole picture across identities, endpoints, cloud, and network; how well you suppress false positives; whether you can connect anomalies to safe, controlled responses; and whether those judgments and actions can be audited and explained.

A point of caution here: two different kinds of "error" must be managed separately. One is the detection model's false positive — judging a normal event to be an attack.

The other is hallucination — an LLM generating explanations or facts without grounding. For the latter, hallucination detection that verifies consistency against evidence is effective (a technology we continue to track ourselves), but for real actions such as isolating endpoints or revoking credentials, separate controls are indispensable: least privilege, approval flows, and rollback capability. Mechanisms that refuse to take AI output at face value matter most precisely in the AI-versus-AI era.

Automation of defense itself will advance. According to MarketsandMarkets, semi-autonomous (human-in-the-loop) operation is projected to account for about 74% as of 2026 [5]. The same report treats fully autonomous security agents as their own market segment.

Still, lumping everything under "fully autonomous" is too coarse. Isolating an endpoint, revoking credentials, cutting communications, and applying patches have completely different blast radii when the judgment is wrong. What to let the system execute autonomously, and how far — drawing that line is decisively important in practice.

How Do You Manage Identities That Are Not Human?

A central theme that must not be overlooked going forward is the "identity and privileges" of AI agents.

Once AI agents deploy code, send email, and operate databases, new questions arise: on whose behalf is that agent acting, what is it allowed to do, and when are its privileges revoked? The idea is that agents — like human employees — need identity verification, authentication, authorization, and an offboarding mechanism.

We took up this issue in "The Complete Guide to LLM Security in the Zero Trust Era", where we discussed how to protect LLMs and agents under a "trust nothing" premise, and introduced the concept of the "guardian agent" that monitors and controls agent behavior. The "management of non-human identities" discussed in this article sits directly on that same line. NIST, too, has begun treating the identification, management, and authorization of software and AI agents as an independent topic [9].

The Changes to Watch — on a Timeline

Laying all future themes on the same plane makes investment priorities hard to see. Let us organize them on a rough timeline.

TimelineMain themesRepresentative measures and technologies
Now–3 yearsAreas already moving into implementationAI SOC (log/alert analysis and triage), countermeasures against deepfakes and impersonation, AI governance (AI TRiSM)
3–5 yearsExpanding autonomy and monitoringAutonomous response in limited domains, multi-agent monitoring, protection of the AI supply chain (training data and model procurement)
5–10 yearsRebuilding the security foundationMigration to post-quantum cryptography (PQC), broader autonomous defense
Table: Future AI security themes organized on a timeline. Rather than placing them on the same plane, use this to gauge priorities for getting started.

Now (2026) to 3 years. These are the areas already moving into implementation. The center consists of the AI SOC, which automates log and alert analysis and triage; countermeasures against fraud and information manipulation such as deepfakes and impersonation; and AI governance, which controls the use of AI itself. The governance area in particular is emerging as an independent market segment Gartner calls "AI TRiSM (AI Trust, Risk and Security Management)" [10]. From a security standpoint, the concrete topics include discovering and inventorying AI assets, monitoring inputs/outputs and data flows, enforcing policy at runtime, continuously evaluating models and agents, and securing incident records and audit trails. Under the market concept of AI TRiSM, the guardrails, data protection, model monitoring, and input/output controls that used to be discussed separately are beginning to be organized into a single operational framework. On this blog as well, starting with Llama Guard, we have continuously tracked the technologies that make up this stack.

3 to 5 years. Autonomous response in limited domains, multi-agent monitoring that oversees fleets of agents, and protection of the AI supply chain (the procurement paths for training data and models) are expected to move into full swing.

5 to 10 years. The full-scale migration to post-quantum cryptography proceeds. Future quantum computers could compromise the public-key cryptography in wide use today, such as RSA and elliptic-curve cryptography (the impact on symmetric ciphers and hash functions is of a different nature). NIST formalized its first set of standards in August 2024 [11], and inventorying cryptographic assets and planning migrations is already ceasing to be a "topic for future consideration." Broader autonomous defense will also become realistic on this horizon.

Even in a Growth Market, Not Everything Is New Budget

Finally, one perspective that tends to be overlooked. The expansion of AI security is not purely a stacking-up of brand-new product categories. A large part of it is existing products — IAM (identity management), SOC, EDR, SIEM, cloud security, data protection — being restructured for the AI era.

McKinsey likewise points out that functions such as identity, detection, and security operations will not disappear, but will be rebuilt to absorb AI capabilities and the governance of autonomous systems [12]. Rather than the simple equation "the market grows = it is all new market," the reality is closer to a mix of reallocated existing budgets and genuinely new investment.

From Individual Defense Technologies to a Control Plane for AI Operations

We do not read the market changes traced above as merely "more security products appearing."

We see them as a shift in which capabilities that used to be handled separately — prompt guardrails, personal-information detection, model-output auditing, zero trust, agent identity and privilege management — are being integrated into a single AI operations foundation.

When LLMs only generated text, guardrails inspecting inputs and outputs were the center of defense. But once AI agents call external tools, update data, and execute business actions, watching the text alone is not enough. You must manage under whose authority the agent acted, what it referenced, which operations it performed, and how the results were recorded.

From guardrails to data protection; onward to identity, privileges, behavioral monitoring, and audit trails. This expansion of the scope of control is, in our view, the major current shaping the AI security market ahead. The themes we have covered individually on this blog — guardrails, PII detection, hallucination detection, zero trust, guardian agents — line up, in retrospect, along this single current.

Control layerPrimary asset protectedRelated insights from our blog
Input/output guardrailsPrompts and model outputsLlama Guard: A First Step in AI Safety
Data protectionPersonal information (PII) and confidential dataDefending Corporate Information in the LLM EraJapanese PII Detection Technology
Output auditingHallucination and answer faithfulnessZero-Resource Hallucination DetectionLynx
Zero trustTrust boundaries for accessThe Complete Guide to LLM Security in the Zero Trust Era
Identity, privileges, and behavioral monitoringAgent execution control and audit trailsWhat Is a Guardian Agent?
Table: From guardrails to agent control — the expanding scope of control, mapped to the insights we have built up piece by piece. These are converging into a single AI operations foundation.

In Closing

To sum up the overall picture: the security market is already large, still growing quickly, and the AI-related share within it is rising rapidly. The contest around autonomous AI in particular — though still small in absolute terms — looks set to be the focal point of the next decade, on both growth rate and strategic importance.

What is certain is that the three questions — how to defend with AI, how to defend against AI-powered attacks, and how to protect AI systems themselves — will become ever harder to separate. In an era when both offense and defense hold AI, the quality of judgment about what premises to invest on, and which risks to prepare for in which order, will shape each organization's safety.

Qualiteg Technology Consulting

Both offense and defense now run on AI. Is your security keeping up with that speed?

Attack automation driven by ultra-capable LLMs, the new attack surfaces created by AI agents, the data leakage lurking in in-house LLM operations — AI security threats keep rewriting the premises of conventional defenses. "The attackers are already armed with AI, but our own preparations are years old" is not a rare situation at all.

We have tracked attacks on and defenses of LLMs at the front line, building LLM-Audit for offense/defense assessment and pii-fi for PII protection in-house. Grounded in the latest threat landscape, we will design practical measures tailored to how your company uses AI. Feel free to start by talking through your current challenges with us.

Explore AI security consulting →

* The market sizes and growth rates in this article reference estimates published in 2025–2026 by MarketsandMarkets, Grand View Research, Fortune Business Insights, and others. Because market definitions, product/service scope, and base years differ by firm, the figures may not be directly comparable. The AI security, Agentic AI Security, and AI governance markets also partially overlap, so their sizes cannot simply be summed. All future figures are projections and do not guarantee actual results.

Our LLM Security Articles (Selected)

The themes touched on in this article are ones we have covered continuously on this blog. We invite you to read further.

The big picture and attack models

Data and PII protection

Guardrails and output verification

Zero trust and agent control

Sources

Primary sources: research-firm reports for market sizes, the European Commission for legislation, NIST for standards and technical taxonomy, and ISC2 for the workforce study. Numbers correspond to the citations in the text (all accessed June 2026).

  1. MarketsandMarkets, "Cybersecurity Market: Navigating an Era of Rapid Growth and Evolving Threats" (market blog, dated November 7, 2025, covering 2025–2030)
    https://www.marketsandmarkets.com/blog/ICT/cybersecurity-market
  2. Grand View Research, "Cyber Security Market Size, Share & Trends Analysis Report" (covering 2025–2033)
    https://www.grandviewresearch.com/industry-analysis/cyber-security-market
  3. Fortune Business Insights, "Cyber Security Market Size, Share & Industry Analysis" (covering 2025–2034)
    https://www.fortunebusinessinsights.com/industry-reports/cyber-security-market-101165
  4. Fortune Business Insights, "Artificial Intelligence in Cybersecurity Market Size, Share & Industry Analysis" (updated June 1, 2026, covering 2025–2034, CAGR for 2026–2034, Report ID: FBI113125)
    https://www.fortunebusinessinsights.com/artificial-intelligence-in-cybersecurity-market-113125
  5. MarketsandMarkets, "Agentic AI Security Market — Global Forecast to 2032" (report, covering 2026–2032)
    https://www.marketsandmarkets.com/Market-Reports/agentic-ai-security-market-97017233.html
  6. ISC2, "2025 ISC2 Cybersecurity Workforce Study" (published December 2025)
    https://www.isc2.org/Insights/2025/12/2025-ISC2-Cybersecurity-Workforce-Study
  7. NIST/NCCoE, "Cyber AI Profile" (the three-area framing of AI system security / AI-enabled attacks / AI-enabled defense)
    https://www.nccoe.nist.gov/projects/cyber-ai-profile
  8. European Commission, "AI Act — Regulatory framework for AI" (in force August 2024; application schedule including the May 7, 2026 political agreement)
    https://digital-strategy.ec.europa.eu/en/policies/regulatory-framework-ai
  9. NIST/NCCoE, "Software and AI Agent Identity and Authorization" (project under consideration)
    https://www.nccoe.nist.gov/projects/software-and-ai-agent-identity-and-authorization
  10. Gartner, "Market Guide for AI Trust, Risk and Security Management" (February 18, 2025)
    https://www.gartner.com/en/documents/6185655
  11. NIST, "Post-Quantum Cryptography Standards" (FIPS 203/204/205, formalized August 13, 2024)
    https://www.nist.gov/news-events/news/2024/08/nist-releases-first-3-finalized-post-quantum-encryption-standards
  12. McKinsey & Company, "Securing the agentic enterprise: Opportunities for cybersecurity providers" (March 24, 2026)
    https://www.mckinsey.com/capabilities/risk-and-resilience/our-insights/securing-the-agentic-enterprise-opportunities-for-cybersecurity-providers

Other references: European Commission (NIS2, DORA, Cyber Resilience Act).

Read more