2026 Tech Industry Predictions

Australian Tech Industry Leaders Make Their Predictions for 2026

Surprisingly Useful AI Article Enhancements

Itโ€™s that time of year where the technology industry predictions start rolling-in. Hereโ€™s what you can (apparently) expect in 2026. Weโ€™ll post newer contributions at the top:

Table of Contents


Paulย Davis, US Field CISO, JFrog

AI Risks

The explosive acceleration of AI, especially agentic AI, throughout 2025 has left many organizations struggling to keep pace. As organizations race to adopt these advanced technologies, on average they are now managing 20 times more non-human identities than human identities โ€“ a number that is predicted to jump to 100 to 1 by the end of the year. While these capabilities are driving unprecedented innovation and productivity, this autonomy introduces unpredictable risks, rogue actions, hidden vulnerabilities, and AI-driven exploits that are increasingly difficult to detect and control. Whatโ€™s more, these agents also possess the ability to bypass certain guardrails, underscoring the urgent need for layered security in the new year. 

Attackers are now using AI to automate and scale their methods, generate new exploits, and adapt tactics in real time. As a result, threats have become faster, more persistent, and significantly harder for security teams to anticipate or contain. Security teams face a new class of risks, including exploitation of open-source AI/ML models through the exploitation of public OSS repos for popular repos such as npm, PyPI, Maven, and Open VSX, and new threat vectors affecting MCP ecosystems

The surge in advanced AI tools, such as Model Control Platforms (MCPs), is raising urgent questions for security teams: How do we build trust in AI, govern its adoption, and ensure secure integration? Governance will play a pivotal role such as the EU AI Act, Cyber Resilience Act (CRA) ,DORA and various state regulations such as Californiaโ€™s AI Transparency Act (SB 942), providing clear standards and accountability to help organizations manage AI risks and ensure secure, responsible deployment.

Ultimately, for agentic AI to be used productively in 2026, developers must remain actively engagedโ€”never taking their hands off the wheel. AI cannot simply be set loose; it requires rigorous testing and continuous security checks/oversight at every stage of development through to production to ensure these powerful tools remain safe and reliable. For example, teams must establish a collective evidence ecosystem, where every model and its components are verified by leading organizations in the industry. This will establish a single source of truth and automated trust at every stage of the AI development lifecycle.

Leaders who combine strong processes with intelligent technologies will build resilient, compliant ecosystems, where AI security and data protection is not just a technical requirement but a strategic advantage driving sustainable growth.

Zero Trust

In 2026, Zero Trust will remain a cornerstone of security, but its implementation will become significantly more complicated adding not a replacement, but an additional burden for CISOs and security teams. The rapid adoption of agentic AI and non-human identities is reshaping the security landscape, introducing unprecedented complexity to access management and threat detection. In fact, machine identities outnumber human identities by a factor of 45 to 1 on average, and in large organizations, non-human identities outnumber human users by 50 to 1. What’s more, these intelligent agents often bypass traditional silos, making it increasingly difficult to enforce granular permissions and isolate access.

As we move into the new year and beyond, developers and security leaders must contend with environments where access is not just about human credentials, but also about controlling intelligent agents whose permissions are far less transparent. Security leaders must rethink how they verify and monitor every interaction, moving beyond legacy controls to embrace continuous authentication and real-time oversight. This includes embedding security into every phase of the software development lifecycle, leveraging continuous authentication, real time monitoring, and automated threat detection to address risks that are no longer confined to just human users. 

As these new threats evolve, security leaders must shift to a compliance as code approach in 2026, bringing compliance standards to the business level. This means having the tools and visibility needed to determine and demonstrate whether applications are trustworthy, confirm they meet required criteria, and being able to validate every component within their environment.

Traditionally Zero Trust has focused on people (and now NHIs), and IT infrastructure.  We can foresee a greater focus on Attribute-Based Access Control (ABAC), or the data being leveraged in AI. At the moment, there are few mechanisms to monitor and control data in the context of Zero Trust access within an AI service, but regulations, and exposure management will drive the need for greater accountability and oversight around how data is integrated into these solutions. The organizations that will thrive are those that treat Zero Trust as a strategic enabler of innovation, not just a compliance checkbox. With this focus, security leaders can build resilient ecosystems where AI accelerates growth without compromising trust.

Quantum

As quantum computing advances, the โ€œDecrypt Laterโ€ dilemma will become a pressing issue for governments and enterprises alike. While the solution may seem straightforwardโ€”simply update the software to quantum-resistant standardsโ€”the reality is far more complex. Legacy systems are often deeply intertwined with business operations, and updating them can risk data loss, incompatibility, and operational disruption. The sheer scale of technical debt across industries makes quantum resilience a complex, urgent priority that demands visionary leadership.

Looking ahead to 2026, forward-thinking organizations must treat quantum migration as a strategic imperative, not a technical afterthought. By developing comprehensive migration plans, security leaders can help ensure that systems are resilient against both current and future attack vectors, while rigorous validation and continuous monitoring will further strengthen defenses.

Ultimately, those who act now, will set the standard for software security in the quantum era. Proactive planning and decisive action will not only mitigate the risks posed by quantum-enabled threats but also transform quantum migration into a catalyst for sustainable digital transformation and long-term resilience.

Yuval Fernbach, VP & CTO ofย JFrog

Prediction 1: AI Governance Will Become the New โ€œDevOpsโ€ for the Enterprise

In 2026, enterprises will realize that AI adoption isnโ€™t primarily a modeling challenge โ€” itโ€™s an operational one. As every team from development to security to business operations begins using AI tools and agents, CIOs and platform leaders will be forced to standardize how AI is discovered, approved, secured, and monitored across the company. The result: AI governance will evolve into a new enterprise discipline, much like DevOps did a decade ago. Companies that treat AI as a governed supply chain, rather than a collection of disconnected pilots, will scale faster and avoid compliance and security pitfalls that slow their competitors.

Just as DevOps faded into the background so developers could focus on building, AI governance will mature to the point where developers barely realize itโ€™s there.

Prediction 2: Shadow AI Will Become a Bigger Risk Than Shadow IT

With open-source models, SaaS AI tools, and API-based agents now one click away, organizations will see a surge in โ€œshadow AIโ€ โ€” teams adopting unvetted models outside formal processes. In 2026, this will eclipse shadow IT as the top operational risk CIOs face. Security teams wonโ€™t just worry about rogue infrastructure; theyโ€™ll worry about unapproved models with hidden vulnerabilities, poisoned datasets, and undocumented behaviors. To counter this, enterprises will adopt centralized AI catalogs and enforce model allow-lists as standard practice, similar to how software artifact governance became mandatory during the DevOps era.

Prediction 3: Companies Will Shift Standalone Models to Deeply Integrated, Context-Enriched Systems

While todayโ€™s AI adoption often starts with generic LLMs and isolated prototypes, enterprises are realizing that real value doesnโ€™t come from the model alone โ€” it comes from how well that model is connected to their internal systems. In 2026, the focus will move away from โ€œbuilding your ownโ€ models and toward deploying AI that natively integrates with internal assets: data sources, tools, APIs, operational workflows, and governance layers.

Models and agents will increasingly use MCP-like connectors to enrich prompts with internal organizational context, retrieve real-time business data, and perform actions across existing enterprise systems. This shift turns AI from a static text generator into an operational participant โ€” one that queries, validates, updates, and orchestrates tasks based on live internal information.

As a result, companies will reduce drift, improve reliability, and unlock far faster time-to-value. Instead of experimenting in isolation, enterprises will rely on integrated, governed, production-ready AI systems that understand their business, operate within their environment, and continuously stay aligned with their internal truth.


Andrew McCarthy GM of ANZ, SEA and India, Notion

True AI-native companies arenโ€™t built on models – theyโ€™re built on unified knowledge

AI’s first wave failed because we asked the wrong question. Companies spent billions asking “What can AI do?” when they should have been asking “What does AI need to know?”

The biggest challenge holding back enterprise AI today is no longer model capability; itโ€™s context fragmentation. The first wave of generative AI proved its potential, but its failure to deliver consistent, measurable outcomes stems from tools being too siloed. This challenge forces teams into manual search and context switching, creating a severe outcomes gap. The majority of organisations are still grappling with this, injecting generic AI into fragmented workflows, which only leads to generic outputs โ€” a top frustration for over a third (34%) of Australian, according to recent Notion data.

While competitors race to add more AI features, they’re missing the fundamental insight: agents in isolation are smart assistants; agents with access to your entire knowledge graph become team members.

The year ahead marks a shift towards autonomous AI – agents that run on heightened context and are able to actually execute tasks end-to-end. In my conversations with business leaders, the number one fear is AI hallucination. The solution is ensuring agents can draw from a truly connected, single source of truth, giving teams confidence in AI outputs. By centralising context where the work happens, we allow AI agents to accurately execute complex, multi-step tasks as an extended member of the team.

For enterprises, this can mean allowing AI to handle work that currently slows teams down. Whether that’s taking on repeated tasks or automatically answering recurring team questions using your internal knowledge base, agents work 24/7 whether you are online or not. This focus on end-to-end delivery, powered by context, provides the operational smoothness enterprises need to scale. By automating patterns in our day-to-day work, we finally allow every employee to work to their best potential.

My prediction: By the end of 2026, ‘AI-native’ companies will be defined not by their AI models, but by their unified knowledge architecture. Companies that don’t solve context fragmentation this year will find their AI investments delivering diminishing returns while competitors with connected workspaces pull decisively ahead.


Dropbox’s company predictions

If 2025 Was The Year Of Ai Experimentation, 2026 Will Be The Year Ai Becomes An Integral Part Of Everyday Work

If 2025 was the year of AI experimentation, 2026 will be the year AI becomes an integral part of everyday work. We don’t just expect to see โ€œmore AIโ€ but better AI – systems that understand context, connect the dots and reduce digital noise.

Hereโ€™s what this will look like in practice:

1. Ai Will Stop Being A Tool And Start Acting Like A Teammate

In 2026, AI will move beyond generic assistants and start behaving more like a collaborator. Rather than responding to isolated prompts, AI teammates will understand what youโ€™re working on, who youโ€™re working with and how your work fits together.

These systems will proactively surface relevant information, connect insights across tools and help people make decisions – not just generate content. The shift will be from AI that reacts to AI that genuinely supports the flow of work.

2. Context Will Become The New Competitive Advantage

The biggest limitation of todayโ€™s AI is that it lacks context. In 2026, winning platforms will be those that can securely connect context across cloud drives, instant messaging chats, email threads, screenshots and video recordings. Businesses will increasingly judge AI on its ability to understand their internal information – not on raw model power alone.

The result will be AI that references real projects, understands role-specific needs and dramatically reduces time spent chasing information – freeing up teams to focus on high-value judgment and creativity. Specialist tools will emerge across functions – from legal and sales to operations and risk – turning pilots into scaled deployments and unlocking meaningful productivity gains.

3. Productivity Will Be Redefined As โ€œLess Noise, More Signalโ€

After years of digital overload, 2026 will be the year teams push back. The next wave of productivity tools will focus on reducing cognitive load – cutting down on app-switching, unnecessary notifications and repetitive work – so people can focus on what actually matters.


Kumar Mitra, Executive Director, CAP & ANZ, Lenovo ISG.

Maximising productivity remains at the top of the agenda for Australian businesses across all sectors, the solution is in building and scaling trusted, human-centric, efficient Ai. The organisations who succeed will be those that acknowledge Hybrid AI as the architecture that makes this possible – moving from the experimentation phase and into execution.

Kumar Mitra Lenovo ISG
Kumar Mitra.

In 2025, Hybrid Ai has proven its value, enabling speed, resilience, cost control and compliance. Now, the focus must be on scaling Ai responsibly and efficiently, with clear business outcomes.

Execution at scale relies on confidence, and confidence starts with trust. This year is about proving that Ai can be trusted, as only trusted Ai can accelerate decision making. Leadership teams are asking for Ai that can explain its recommendations, respect customer privacy, and reflect local nuance. When Ai falls short on this, it can become a brake on progress, rather than an accelerator.

Once Ai is trusted at the leadership level, its impact can extend beyond decision-making and into how innovation itself happens.

Looking to the year ahead, perhaps the most exciting shift is how Ai is changing who can participate in innovation. The most sustainable productivity gains come when Ai empowers people rather than replacing them. Natural-language interfaces and agentic Ai allow domain experts, doctors, plant managers, supply-chain leaders, etc. to design and orchestrate Ai-driven workflows without needing to be Ai specialists. When combined with secure, well-governed infrastructure, this unlocks rapid experimentation and faster time to value.โ€‹โ€‹

As Australia looks to lift productivity in 2026, the focus must shift from standalone Ai initiatives to building systems that are trusted, hybrid by design and sustainable at scale. Organisations that get this right will not only scale Ai more efficiently, but unlock faster decision-making, stronger workforce participation and more sustainable economic growth.


John Deeb, GM ANZ, Field CTO APAC, Workato

Ai adoption is accelerating, but 95 per cent of generative Ai pilots are failing to deliver meaningful business outcomes. The issue is not the technology, but the way generic Ai is bolted onto businesses rather than integrated into the systems and workflows where real work happens.

Big models are great at broad tasks, but most business value sits inside messy workflows. Approvals, hand-offs, edge cases and systems that do not talk to each other are where many Ai initiatives stalled in 2025. The models worked fine on their own, but their potential was limited by a lack of integration.

What changes in 2026 is not more Ai, but more deliberate Ai. Instead of dropping a general-purpose assistant on top of the business, teams will start building narrowly focused capabilities tied to specific jobs. Protocols like MCP (Model Context Protocol) are making it practical to connect Ai directly to existing enterprise systems – CRM, ITSM, HRIS, financial platforms, so models can act on live data within governed workflows. When Ai is embedded directly into existing workflows and connected to the systems people already use, it stops being a novelty and starts being useful.

The future of enterprise Ai is not about having the most advanced software or AI model. It is about getting real work done, reliably, in the flow of the business.


Ed Keisling, Chief Ai Officer, Progress Software

If 2023โ€“2025 were the years of pilots and prototypes, 2026 will be about orchestration, governance and scale.

The signal across various pieces of recent Ai research is consistent: adoption is widespread, and business impact concentrates where companies redesign workflows, measure outcomes and hard-wire trust and controls into the stack. And while McKinsey reports that ~80 per cent of companies use generative Ai, most still arenโ€™t seeing material earnings contribution – because scaling practices and operating models lag the hype.

Here are five predictions that all organisations investing in Ai in 2026 need to be across:

  1. Ai plumbing: For true competitiveness, organisations need to reevaluate their Ai foundation – updating retrieval, governance and audit systems to match new regulations and threats. Agentic RAG is now essential: while classic RAG used trusted data, agentic RAG adds multi-step reasoning, tool use and secure coordination. This offers ready-made scaffolding, especially valuable for mid-market and SMBs that lack resources for custom solutions. Instead of building complex systems from scratch, teams can adopt platforms delivering secure retrieval, reasoning and auditability, democratising Ai and reducing risk.

  2. The compounding curve: The gap in productivity between the innovators, early adopters and the laggards will quickly expand. The innovators and early adopters will accelerate their ability to leverage Ai to automate and orchestrate more complex tasks. Organisations will need to come up with innovative ways to foster growth and learning to bring the rest of the organisation along. Companies that prioritise structured learning and platform adoption will be best positioned to narrow the gap and fully realise Aiโ€™s transformative potential.

  3. Smaller is better: While the trend in Ai has often focused on building ever-larger and more powerful models, organisations in 2026 will increasingly recognise the benefits of smaller, more specialised models. These compact models can be trained or fine-tuned on a companyโ€™s own data, making them highly relevant to specific business needs and internal processes. Because they require less computational power and storage, smaller models are less expensive to run and can be deployed in a wider range of environments. This allows for faster, more secure and more private Ai operations, as sensitive data can remain within the organisation’s own infrastructure rather than being sent to the cloud or third-party providers.

  4. As Ai hype fades, what endures is trust: Early enthusiasm around โ€œAi everywhereโ€ is giving way to a more mature set of expectations. Organisations will demand Ai systems that are transparent, auditable and fair – especially in regulated or sensitive industries. For example, consider a financial services firm that must comply with strict regulatory requirements. Instead of deploying a black-box Ai model for loan approvals, the company implements an Ai platform that provides clear explanations for each decision, maintains a complete audit trail and allows internal and external reviewers to trace every step in the process.

  5. Integrate or get left behind: The organisations that excel ahead over the next 12โ€“18 months wonโ€™t be the ones with the largest models – it will come down to those who can unlock the value of the unstructured data within their organisation to drive more meaningful business outcomes for their customers. The secret sauce is turning scattered protocols, tribal knowledge and unstructured documentation into actionable retrieval pipelines. Agentic RAG can power this transition. Take for example a security team who today may rely on a slow, manual search for incident-response playbooks, regulatory requirements or architectural documentation. Instead, this same team can instantly surface the tools they need in real-time, relying on a unified, contextual retrieval layer that becomes a competitive advantage. Combining retrieval, reasoning and secure orchestration revolutionises the way teams access internal knowledge.

Organisations aiming to succeed with Ai in 2026 must adopt a more disciplined and strategic approach to building and deploying their solutions. This year marks a pivotal shift from experimenting with pilots to implementing scalable platforms, where the focus is on orchestrating and governing Ai at scale. Agentic RAG plays a crucial role in this transformation by merging generative reasoning with robust, accountable retrieval. Every response is grounded in verifiable data, every process is clearly tracked with an audit trail and every interaction maintains strict separation between environments, ensuring governance is never compromised.


Callum Eade, Vice President, APAC, PagerDuty

on the trends shaping the tech landscape this year. Callum is available for interviews or commentary to unpack these predictions and discuss what they mean for Australian and APAC organisations: 

Data Repatriation Will Accelerate as Organisations Rethink Cloud Strategy

Australian organisations will increasingly repatriate data from cloud environments back to on-premises infrastructure throughout 2026. This shift represents a fundamental reassessment of data storage strategies, driven by cost optimisation, data sovereignty concerns and performance requirements. 

Australia Poised to Lead Global Incident Management Adoption

Australia will emerge as an early adopter of advanced incident management practices, setting the standard for how businesses approach system reliability and recovery. Why? A combination of geographic isolation, joined with an innate appetite for tech adoption. As an example, Australia leads the way in AI adoption,  51% of Enterprises have already integrated AI into their IT and business strategies.  

Small and Medium Businesses Face Disproportionate Outage Risk

Smaller organisations often lack dedicated DevOps teams and robust monitoring infrastructure, leaving them exposed to extended downtime that can significantly impact revenue and customer trust.  

IT Spend will Rise to Safeguard Digital Resilience

Organisations across APAC will increase IT budgets in 2026, viewing spend as a strategic safeguard against system disruptions. Investments will focus on AI-driven continuity solutions to address consumer expectations for zero downtime. Our consumer Australian based survey saw $5.3b lost in the last 12 months, as a direct link to system outages. In 2026, I believe organisations will match this figure, or more, in spend to ready their organisations over the coming 24 months. 


Simon Howe, AVP ANZ, ExtraHop

2026 Shifts Toward High-Velocity Cyber Extortion

In 2026, the cyber threat landscape will be characterised by a shift from broad, opportunistic strikes to highly industrialised, surgical operations. Ransomware remains a dominant force and has become more sophisticated as attackers now favour extortion-based models, often bypassing encryption entirely to focus on data exfiltration, while leveraging Ai to identify the targets with the highest financial or strategic leverage. This precision is amplified by a relentless focus on supply chain vulnerabilities, where threat actors aim to compromise a single, pivotal vector, such as a ubiquitous software dependency or cloud service provider, to achieve a “force multiplier” effect across entire industries. While Ai has not fundamentally changed the ultimate goals of cybercriminals, it has dramatically accelerated the velocity and scale of attacks, allowing for rapid, wide-reaching exploitation that leaves defenders with a near-zero response window.

Poisoning The Well Will Fuel The Next Wave Of Cyber Attacks

Next year we will see threats evolve their approach to attacking the enterprise in new ways as a result of accelerated Ai adoption. Ai being used by organisations, whether it be LLMs or agents, is only effective if backed by a robust, accurate dataset that powers responses or tasks. I predict that attackers will find ways to target those datasets, compromising the foundation of how enterprises are operating their internal Ai solutions. An attack like this can directly impact operations and productivity, especially for enterprises heavily relying on Ai agents for tasks, and create a moment of weakness that allows a threat like ransomware to take hold of other proprietary data. The same risk goes for public Ai solutions in use by businesses which could cause hallucinations and inaccuracies for an employee’s workflow. Defending against this risk will be a key focus area and itโ€™s only a matter of time before attackers focus their efforts in this direction.

Systemic Fragility Threatens Global Cloud Stability

The global reliance on a handful of hyperscale cloud providers will reach a critical tipping point next year. A cascading cloud platform outage would trigger catastrophic disruptions across international finance, healthcare and logistics, fuelled by the sheer density and interconnectedness of modern digital infrastructure. A significant new catalyst for these failures will be Ai poisoning, where malicious actors inject corrupted data into the very models used to manage global traffic and resource allocation. As cloud providers push their servers to the absolute edge to meet the voracious compute demands of 2026, even a minor internal misconfiguration caused by a threat can evolve into a global network blackout. This concentration of risk means that the failure of a single provider no longer affects isolated apps, but instead acts as a systemic shock to the global economy, turning a routine technical incident into a full-scale societal crisis.


Jarryd Tuyau, Ai Lead APAC, Genesys

CIOs will move from Ai experimentation to outcome-driven agentic Ai
After a year of intense experimentation, CIOs in ANZ have discovered that generative Ai alone is not the path to transformation. In fact, only 12 per cent of organisations saw consistent returns on investment. However, those experiments have delivered valuable insights, showing leaders where data is fragile, where governance needs to be strengthened and where Ai can provide the most value within the organisation.

In 2026, the organisations that act on these insights will be those that see the most success in making the shift from generative Ai to agentic systems that can act autonomously.

To achieve this, CIOs will prioritise four areas:

  • trusted data foundations
  • context engineering
  • agent orchestration
  • robust Ai governance

When organisations invest in a strong foundation, Ai becomes less of an experiment and more of a partner that can help shape intuitive, personalised and empathetic experiences.


Shannon Davis, Principal Ai Security Researcher, SURGe/Foundation AI, Splunk

In 2026, machine data will step into the spotlight as companies accelerate their use of Ai. With Ai models, infrastructure and data centres all expanding at once, the volume of information systems produce will rise. Making sense of this data – and importantly, staying in control of it – will become essential for managing cyber risk, performance and resilience.

Machine data is data generated by all the systems running in data centres and the new world of connected devices. It is all the data generated by everything that powers an organisation- from applications and servers to security and network devices.

As Ai systems become more interconnected and complex, machine data becomes the single source of truth for both observability and security. Many early warning signs – a spike in errors, a slowdown, an unexpected process – can indicate a performance issue or an attack. Without unified machine data, teams risk chasing the wrong problem.

That gap will only widen as cyber threats intensify. Ai will increasingly support security operations, but the Ai systems organisations rely on will also require safeguards to ensure they operate safely and canโ€™t be exploited. Neither can happen without accurate, timely machine data feeding those decisions.

2026 is the year companies start to take control of their machine data as the foundation that will allow them to scale Ai safely, respond to cyber threats faster and keep complex environments steady as the pace of change accelerates.


InvestmentMarkets Outlook 2026: What 17 Fund Managers Are Watching

As investors look ahead to 2026, fund managers are weighing a complex mix of inflation uncertainty, interest rate volatility, structural supply constraints, technological disruption and shifting global dynamics.

To cut through the noise, InvestmentMarkets has brought together views from 17 leading fund managers across property, private credit, infrastructure, equities, fixed income, FX and alternative assets.

Rather than a single house view, this outlook captures the diversity of thinking shaping portfolios heading into 2026 – highlighting where opportunities may emerge, where risks are building and why selectivity and flexibility are expected to matter more than ever.

Darren Connolly, Chief Executive Officer, InvestmentMarkets
As investors look ahead to 2026, the data shows a clear shift in priorities. Self-directed investors are spending less time chasing momentum and more time focusing on income, stability and capital preservation. Property, private credit and income-focused strategies are no longer defensive sidelines – theyโ€™re becoming core allocations as investors position for the next phase of the cycle.

Steve Bennett, Direct Chief Executive Officer, Charter Hall
In our view, the supply response is completely underestimated by the market. For investors already positioned in high-quality real estate, this could deliver outsized benefits as rents rise without the usual supply response. We are now at an inflection point, with valuations already bottoming across sectors including industrial logistics and convenience retail, and improving in core office markets such as Sydney and Brisbane CBD. This is a compelling entry point before the cycle fully turns.

Patrick William, Managing Director, Rixon Capital
The flood of capital looking for returns will be very supportive for private credit, with family trusts and SMSFs increasingly looking for a safe place to park capital. The biggest risk is poor disclosure from bad actors, because when one fund fails it can unfairly taint the entire sector. Education and transparency will be critical.

Ben McVicar, Co-Head Of Infrastructure And Portfolio Manager, Magellan Investment Partners
Infrastructure should hold up relatively well if economic conditions weaken, with underlying earnings proving more resilient than broader equities. While unexpected moves in long-term interest rates can drive short-term price volatility, that disconnect can create opportunity for long-term investors.

John Di Monda, Chief Executive Officer And Fund Manager, GDA Group
While inflation remains a factor, the core fundamentals supporting commercial property are expected to hold. Supply constraints, population growth and broad-based capital growth across major property sectors are likely to continue underpinning the long-term investment case.

Mike Cameron, Commercial Director, Jarra
Early 2026 is likely to be challenging for some listed childcare operators, with occupancy under pressure, but the introduction of the Albanese Governmentโ€™s three-day guarantee is expected to drive a meaningful turnaround. From Q4 onwards, the outlook improves significantly as higher occupancy begins to flow through.

Rudi Filapek-Vandyck, Editor & Founder, FNArena
Australia is entering 2026 with significant uncertainty after three consecutive years of negative earnings growth, even as markets sit near all-time highs. Much is now riding on next yearโ€™s outlook – including Ai-driven growth, global policy settings and central bank decisions – but external catalysts such as US rate cuts or China stimulus could still provide support. Flexibility and an open mind will be essential.

Marc Jocum, Senior Product And Investment Strategist, Global X
Currency hedging is becoming a far more important portfolio consideration – itโ€™s not a sexy area, but it can be a meaningful tailwind or headwind for returns as market conditions shift. At the same time, Ai monetisation remains a major structural tailwind, supported by real revenue and earnings growth. We expect market leadership to broaden as investors look beyond mega-cap tech into the next leg of Ai growth.

Luke Moore, Chief Executive Officer, Oreana Investments
Technology and Ai present a real opportunity to improve governance, efficiency and margins across advice businesses, but they also bring risks that need to be carefully managed. As a new generation of clients becomes more comfortable with technology, the advice practices that thrive in 2026 will be those that use these tools well while staying closely aligned to their clients and doing the right thing.

Jarrad Stuart, Portfolio Manager, Sharpbridge Funds Management
Itโ€™s always hard to call where markets are headed, which is why we focus on building portfolios that can perform in all weather conditions. While Ai remains a powerful long-term driver and we still have exposure, valuations mean weโ€™re cautious in the short term and focused on managing downside risk.

Filippo Sciacca, Executive Director โ€“ Investor Relations, Asset Management And Compliance, Australian Secure Capital Fund
Ongoing housing undersupply continues to support residential values heading into 2026, with demand still outpacing new supply. While sticky inflation and interest rates may temper growth, strong fundamentals mean we donโ€™t anticipate a meaningful downside.

Renny Ellis, Director & Head Of Portfolio Management, Arculus Funds Management
With inflation re-emerging and credit margins already very tight, there is limited value in chasing yield. The opportunity lies in patience – staying short on the curve to preserve flexibility and be ready when yields or credit spreads reprice.

Jarrad Haynes, Managing Director, CapPru
Efforts to cut red tape and unlock housing supply are a genuine positive for the property sector, with governments starting to clear pathways for more projects to get off the ground. The bigger challenge is interest rate uncertainty – consistency matters far more than whether rates move up or down.

Christopher Tipper, Chief Economist And Strategist, Ainslie Wealth
We expect more uncertainty and volatility in 2026, with Bitcoin and precious metals continuing to reflect concerns around debt, liquidity and policy direction. As global liquidity shifts from central banks toward government-led spending, outcomes will depend heavily on how policymakers respond.

Robert Gregory, Portfolio Manager & Founder, Glenmore Asset Management
US tech performance, particularly the Nasdaq, is likely to play a major role in investor sentiment for Australian small to mid-caps, which often take their lead from the US. On the domestic side, interest rate policy remains the key risk to watch in 2026.

Craig Robertson, Chief Executive Officer, Trivesta Funds
FX is increasingly being recognised as an asset class in its own right, as investors look beyond traditional assets for diversification. While geopolitical uncertainty may create periods of caution, FX strategies can play a meaningful and increasingly established role within diversified portfolios heading into 2026.

Jessica Amir, Market Strategist, Moomoo
The biggest driver of investment returns in 2026 and beyond is the scale of spending flowing into the Ai economy. As investment accelerates across chips, data centres and the materials needed to build that infrastructure, the strongest earnings growth is likely to sit with the key beneficiaries of that build-out. Markets wonโ€™t move in a straight line and volatility is likely, but pullbacks are more likely to be viewed as buying opportunities for long-term investors positioned in high-quality names aligned to these themes.

Garreth Innes, Head Of Unit Trusts, Fixed Income
Heading into 2026, investment-grade corporate credit is starting from a far more attractive valuation point relative to both equities and private credit. After the recent lift in yields, investors can access senior credit at levels that offer a compelling pickup without sacrificing liquidity or credit quality. While supply dynamics – particularly from large issuers funding Ai investment – will need to be watched closely, we believe corporate credit offers a favourable riskโ€“return trade-off at this stage of the cycle.


Infosys’ Top 5 cloud shifts redefining enterprise transformation

Infosys has identified five cloud trends redefining enterprise transformation, shaping how organisations will build, scale and compete in 2025 and beyond. These insights come from Anant Adya, EVP and Service Offering Head at Infosys, who works closely with global enterprises navigating large-scale cloud and Ai transformation.

Cloud Evolves From Systems Of Record To Systems Of Engagement

Enterprises are re-architecting cloud platforms from passive systems of record into intelligent systems of engagement. Ai embedded in the cloud is enabling real-time insights, intuitive interactions and experience-led workflows across the enterprise. This shift reflects a broader change in priorities. Cloud is no longer just about operational efficiency; it is about responsiveness, simplicity and outcomes. Cloud-led engagement platforms are enabling faster issue resolution, simplified processes and lower costs through platform consolidation – transforming cloud from an efficiency engine into a growth enabler.

Democratisation Of Ai In The Cloud Drives Industry-Specific Innovation

Ai capabilities delivered through the cloud, combined with low-code and no-code tools, are enabling business users to build and deploy applications at speed. For enterprises, this means faster time-to-market and highly contextual, industry-specific solutions. Cloud is becoming the foundation for hyper-personalised workflows that allow enterprises to respond more quickly to market shifts and customer expectations.

Ai-Native, Self-Optimising Cloud Infrastructure Becomes The Norm

Cloud infrastructure is undergoing a fundamental shift: from reactive monitoring to predictive, autonomous operations. Ai agents and digital twins are enabling cloud estates to anticipate issues, remediate autonomously and continuously optimise performance. The result is improved resilience, reduced downtime, faster MTTR and lower operational costs. As enterprises scale their cloud estates, Ai-native infrastructure is emerging as a critical foundation for always-on digital operations.

Sustainability Becomes A Core Design Principle For Cloud

Sustainability is no longer an afterthought in cloud strategy. Enterprises are beginning to factor carbon intensity and renewable energy availability into how workloads are scheduled and orchestrated across cloud environments. This carbon-aware approach enables organisations to reduce emissions, meet ESG commitments and optimise energy costs without compromising on performance. Cloud is increasingly seen as powerful lever for delivering measurable sustainability outcomes at scale.

Trust, Sovereignty And Security Redefine Cloud Architectures

As regulations evolve and Ai adoption accelerates, trust has becomes central to cloud strategy. Data sovereignty, compliance and security are driving the rise of localised cloud zones and sovereign-by-design architectures. At the same time, cloud security is shifting toward Ai-native, zero-trust models that adapt dynamically to risk. This allows enterprises to innovate with confidence and adopt Ai and cloud technologies while safeguarding data, ensuring compliance and delivering secure user experience.


Mark Drasutis, Head of Value APJ at Amplitude

Ground-Up Ai Forces A Governance Reset

Mark Drasutis
Mark Drasutis.

In 2026, Ai adoption in Australia and New Zealand will accelerate from the ground up. Employees are increasingly using Ai tools independently, outside formal approval channels, creating new security and compliance risks. Organisations must formalise Ai access and establish governance that enables innovation while maintaining control. At the same time, conversational and agentic Ai are becoming the primary interface for digital experiences. Products must evolve from click-driven journeys to outcome-driven interactions, where businesses effectively harness Ai agents to deliver more natural, intuitive and valuable experiences for consumers. Governance needs to be built in, not bolted on.

Data Sovereignty Will Force A Balance Of Innovation With Localisation

In 2026, Australia and New Zealand businesses will continue to walk the line between data sovereignty and innovation. With privacy and compliance on the top of the national agenda, many are moving toward hybrid data strategies that combine local and global cloud infrastructure. The real differentiator will be unified, high-quality data that supports real-time decision-making while meeting local governance standards. Weโ€™re starting to see regional Ai models emerge that better capture ANZ nuance and behaviour. Those who get this balance right, innovation within local compliance, will lead in trust and performance.

Agentic Ai Will Redefine Personalisation, But Only When Itโ€™s Governed The Right Way

In 2026, agentic Ai will revolutionise personalisation across Australia and New Zealand. Many teams see the potential yet lack the governance or workflows to manage it safely. Rules-based marketing is giving way to real-time, generative personalisation and that demands new ways of working. There can be no manual processes within these workflows, and across Australian and New Zealand businesses today, this is still a challenge across all teams and sectors. In the new year, growth teams will need to move from manual testing to orchestrating continuous Ai-driven experimentation to deliver real ROI.

Ai Optimism Will Mask Deeper Job Anxiety Unless Leaders Act

In 2026, employees across Australia and New Zealand will feel more optimistic about Ai than ever, yet beneath that optimism, anxiety around job security and skills will persist. To unlock true productivity, leaders will need to move beyond adoption and focus on reassurance. In practice, organisations should redesign workflows, reskill managers and show how Ai amplifies human capability rather than replaces it. The next phase of Ai success in ANZ wonโ€™t be defined by algorithms, instead, it will be defined by confidence, trust and culture.


Adrian Briscoe, Business Development Manager APJ, Drivesavers

Looking ahead to 2026, the evolution of ransomware tactics against hypervisors is likely to accelerate rather than plateau. As attackers saw success in 2025 by directly targeting VMware ESXi, Hyper-V and other virtualisation layers to simultaneously encrypt or delete dozens – or hundreds – of workloads, we can expect more automation, precision and pre-attack reconnaissance at this layer.

Threat actors will increasingly combine stolen administrative credentials, living-off-the-land techniques and Ai-assisted environment mapping to identify snapshot repositories, backup integrations and management planes before launching destructive actions. Rather than blunt, noisy encryption events, 2026 ransomware campaigns will favour staged hypervisor compromise: selectively disabling recovery options, corrupting metadata and delaying detonation to maximise business impact and negotiation leverage. For defenders, this shift underscores the need to treat the hypervisor not as “infrastructure plumbing,” but as a high-value attack surface requiring dedicated monitoring, least-privilege access, immutable and offline backups and incident-response playbooks that explicitly assume the virtualisation layer itself may be compromised.

In 2026, threat actors are also expected to escalate their focus on backup infrastructure as a strategic vector for maximising impact and prolonging recovery timelines, giving them greater ransom demand leverage. Building on 2025โ€™s trend of attacking hypervisors and snapshots, adversaries will increasingly weaponise credential theft, Ai-enhanced environment reconnaissance and lateral movement to locate and compromise backup repositories – including cloud storage endpoints, nascent immutable backup systems and on-premises deduplicated vaults.

Rather than merely encrypting production workloads, attackers will deploy multi-stage campaigns that first identify backup schedules, retention policies and replication workflows, then stealthily disable or tamper with those systems ahead of a detonation window. Techniques such as targeted API abuse against cloud backup services, exploitation of backup orchestration platforms and even manipulation of snapshot chains or retention flags will be seen more frequently, effectively rendering point-in-time rollbacks unreliable.

For defenders, this evolution means not only hardening backup credentials and network segmentation but also validating the integrity of backups through independent verification, off-site immutable copies and anomaly detection tuned to subtle, pre-ransomware tampering patterns.


George Harb, VP ANZ, OpenText

Prediction 1: Ai Agents Will Be Treated Like Workers, With The Same Level Of Control And Scrutiny

Australian organisations will increasingly treat Ai agents and digital workers as if they were human employees when it comes to risk, access and oversight.

Right now, many organisations are using Ai in very siloed ways. They are moving beyond proof-of-concept deployments and starting to deploy agentic Ai across more systems, only to discover they do not actually know where all their data is or how it is exposed. Legacy databases and servers remain connected to the network, even after modernisation to the cloud and containerised software, which means sensitive data can be brought back online and exposed without people realising it.

The core risk does not change whether the decision maker is a person or an Ai agent. Organisations will need to manage Ai with the same controls they expect for humans, including clarity on what information it can see, how it uses that information, and how they prevent inappropriate access or leakage under evolving privacy and cyber laws.

Prediction 2: Context Engineering And Fit-For-Purpose Data Will Become The Real Ai Edge

The next step in enterprise Ai will be less about model size and more about whether the data feeding those models is clean, governed and fit for purpose.

You can have a high-performance vehicle tuned to perfection. If you put the wrong fuel in it, you will not get the result you expect. The same principle applies to Ai. Large language models can be powerful, but if you put dirty or poorly governed data into them, they will produce outcomes that cannot be trusted.

In response, more Australian organisations are appointing Chief Data Officers and Chief Ai Officers whose focus is to engineer data, not only to clean up what exists but also to change how the organisation captures and manages new data so it stays fit for purpose over time. The right data is king. Tech leaders who fail to get this right face not only wasted Ai spend but serious exposure under privacy and cyber regulation, including the risk of very large penalties if they mishandle sensitive information.

Prediction 3: Non-Human Identities Will Sit On The Frontline Of Identity And Access Risk

In 2026, non-human identities such as bots, digital twins, APIs and service accounts will move to the centre of identity and access management in Australia and New Zealand.

Every non-human identity will need to be managed in the same way as a human identity. That means applying the same identity and access management controls across every agentic Ai persona, every digital worker and every automated process that can act on behalf of an employee.

In practice, that includes authentication, authorisation, auditability and clear ownership for each identity, whether human or machine.

We are heading toward a world where many employees will have a virtual colleague by their side, taking action and handling their workload. If those machine identities are not properly governed, the risk is no different from a compromised employee account, but at a greater speed and scale.

Prediction 4: SME Data Exposure Will Become A Major, And Often Overlooked, Ai Risk

Small and medium enterprises will emerge as one of the most exposed segments in the Australian Ai and data landscape.

Most of the current Ai and data governance conversation is happening at the enterprise level, where large organisations have people and budgets dedicated to privacy, cybersecurity and compliance. In contrast, many SMEs still assume they are too small to be targets and lack the security measures, data governance and identity controls that larger organisations are now implementing.

As large enterprises become harder to breach, attackers will move down the chain of command. SMEs hold valuable customer and operational data but often operate with open or lightly protected systems. This creates a growing pool of data privacy and cyber risk that has not yet been fully acknowledged. Tech leaders and business owners in this segment will need to understand where their data resides, how it is protected and how Ai uses it, or risk finding out the hard way through regulatory action or a serious breach.


Rapid7โ€™s Cybersecurity Predictions For 2026

Prediction 1: Geopolitical Fault Lines Will Redraw The Cyber Battlefield, As Tensions Between Nation-States Spill Over Into The Private Sector

In 2026, rising geopolitical conflict will no longer remain concentrated within national borders. Private organisations, especially those embedded in critical supply chains, will become proxy targets for state-aligned or state-tolerated groups. These campaigns will blur the lines between espionage and economic sabotage and enable governments to maintain plausible deniability while causing real-world disruption.

Organisations will have to ensure that they utilise curated threat intelligence to track geopolitical flashpoints, emerging APT tools and evolving attacker infrastructure. This will be key to map exposure to geopolitical risk across third-party suppliers, tech partners and infrastructure dependencies. Organisations will also need to look to establish incident playbooks with executive approval for swift, pre-authorised response in case of politically motivated attacks.

Prediction 2: Insider Threats Will Dominate Breach Root Causes, From Simple Negligence To Monetised Access Selling

By 2026, threat actors won’t always break in. Instead, they’ll be invited. The workforce will become the doorway to organisationsโ€™ networks as we witness disgruntled insiders and careless employees become key vectors for compromise, especially as economic and cultural pressures intensify. It will be important for organisations to establish behaviour baselines across users and roles to flag anomalous access, downloads and logins.

The organisations that deal with this new threat will create a โ€œspeak-upโ€ culture where employees are equipped and incentivised to report suspicious behaviours and missteps. Organisations should make sure to review privilege models regularly to limit unnecessary access and reduce potential blast radius.

Prediction 3: You Canโ€™t Successfully Protect What You Don’t Fully Understand. Context Will Become The New Currency Of Cyber Performance

As threat actors leverage Ai to scale attacks, defenders need more than alerts, they need clarity. The evolution of MDR hinges on one thing: Context. In 2026, integrating exposure management into detection workflows will become the gold standard for defenders seeking faster triage, smarter response and measurable impact. Organisations will align SecOps and executive stakeholders using shared dashboards and context-rich incident briefings.

Focusing on readiness, gaps and the value of investment will be key in 2026. Security teams next year will need to rationalise the security stack around high-impact tools that improve time-to-detect, time-to-respond and analyst efficiency. This will be key to demonstrate the value of the security stack through metrics that matter such as time saved, dwell time reduced, risks remediated and workflows accelerated.

Prediction 4: Ai Will Become The Great Equaliser – Compressing The Response Gap Between Defenders And Attackers

Ai in 2026 will continue to industrialise cybercrime on a major scale. This means reducing barriers to entry and amplifying attacker scale and speed. Adversaries will use Ai to automate reconnaissance, craft personalised lures and accelerate exploitation, while defenders will harness it for faster detection, triage and response. The key differentiator will be context. Knowing which threat groups are targeting which industries and geographies, and using that insight to prioritise with precision.

We will see organisations fuse Ai driven analytics with threat intelligence to identify and prioritise attacks most relevant to their sector and region. Unifying Ai-driven threat detection and exposure context will become key to spot and stop threats earlier in the kill chain. Added to this, the continuous optimisation of SOC workflows by integrating automation, contextual enrichment and analyst decision support will be key.

Prediction 5: Collaboration, Not Just Consolidation, Will Define High-Performing Security Programs

While many teams will consolidate tools to reduce costs and complexity, the real differentiator in 2026 will be collaborative integration, bridging silos across SecOps, IT, risk and compliance. True resilience will not simply come from fewer tools, but from connected insights, shared context and aligned teams working as one. Organisations will begin to adopt a unified platform that connects detection, intelligence and exposure – enabling one view of truth across functions.

We will see the increased design of workflows that align SecOps, IT and Governance, Risk and Compliance (GRC) teams around shared accountability. Cross-functional incident simulations will become more commonplace to uncover gaps in communication, tooling and process handoffs before they break during real-world events.


Sumir Bhatia is President at AP at Lenovo ISG.

Over the past year across Asia Pacific, conversations with customers, from fast-growing digital natives to highly regulated banks and healthcare providers, all have shared a common thread: Ai has moved from experimentation to execution. The question is no longer โ€œifโ€ but โ€œhowโ€ to scale responsibly, efficiently and with clear business outcomes. As we look to 2026, the organisations that lead will be those that treat Ai not as a single project or model, but as a trusted, human-centric system embedded into their operations. Full article can be found here…


Bernd Greifeneder, CTO and Founder, Dynatrace

Organisations will prioritise building foundations that make Ai systems consistently reliable. The next phase of AI progress will depend as much on deterministic grounding and factual signals as on the generative power of stochastic models. Enterprises are recognising that creativity alone is insufficient. Reliable Ai requires both structured inputs and mechanisms that ensure outputs remain trustworthy.

Agentic systems add a new layer of complexity. As agents coordinate tasks, exchange context, and initiate downstream actions, even a small misunderstanding can propagate across the system. Greater capability amplifies this effect because a powerful agent can accelerate outcomes while also accelerating an error. This is how hallucination emerges at system scale, not from a single faulty model but from inaccuracies that compound across agent interactions. Deterministic grounding and end-to-end observability prevent that inaccuracy by ensuring agents act on the same factual signals and remain accountable to the human operator.

A common scenario shows what this looks like. A vehicle detecting a problem may trigger agents that review customer data, vehicle status information, identify service locations, evaluate schedules, estimate travel time, and plan the full resolution workflow. In each case, many agents collaborate behind the scenes to produce a single outcome. Organisations that want transparent and dependable Ai outcomes will prioritise deterministic guardrails, enabling agentic systems to behave safely, act predictably, and collaborate with clarity.


Andrew Carlton, Principal Consultant & CX Practice Director, Customer Science

Amazon founder Jeff Bezos famously said that the best customer service was when customers didnโ€™t need to get in touch with you or speak to you because everything just works. 2026 may be the year more Australian businesses finally begin to adopt his approach in earnest. Rather than seeking to improve their response mechanisms when things go wrong, theyโ€™ll start to put more effort into designing and implementing streamlined systems and processes that ensure they go right, first time, every time. Those that succeed in โ€˜embeddingโ€™ a superlative customer experience, as Gartner puts it, stand a better chance of retaining the loyalty of exacting Australian customers.

Meanwhile, rising concern about fraud and risk may lead to greater caution around the use of Ai in the delivery of services. Witness the recent Deloitte debacle which saw the consulting giant forced to give the federal government a partial refund after a report it prepared with the assistance of generative Ai was found to contain fabricated citations. Thatโ€™s a โ€˜customer experienceโ€™ few suppliers would wish to emulate!

Thus, we can expect to see a greater focus on Ai governance and guardrails from businesses that value the quality of their output and their reputations.  At the same time, a focused, measurable, agent-assisted Ai will start to be more common as Ai project success rates improve.


Jarrod Kinchington, Vice President ANZ, Smartsheet

I see two key trends ahead for ANZ businesses in 2026. First, an opportunity to improve productivity with Ai. And second, increasing pressure for project visibility and data governance. This is most acute in sectors like healthcare, aged care and construction, where operational consistency and compliance are non-negotiable. Clear strategies and tools that unify people, data and Ai are becoming essential, enabling leaders to maintain control while driving meaningful outcomes.

When it comes to Ai, choosing which tools to deploy is often the easy part. The true challenge lies in change management – getting employees to adopt new technology and fundamentally change their work practices. People are demonstrating high curiosity and a willingness to use Ai, but achieving integrated, organisation-wide adoption is the next frontier. One of the most effective ways to achieve this is to embed Ai directly into existing workflows so employees donโ€™t have to learn how to use a new tool. For example, Smartsheetโ€™s Ai features fit easily into existing workflows, so they donโ€™t disrupt the way teams already work.

Weโ€™re also seeing an increasing need for risk mitigation. Without structured processes and oversight, risks around inefficiency, miscommunication and biased outcomes remain high. This is compounded by the critical need for robust data governance. With data breaches becoming increasingly common, the ability to guarantee data residency, traceability and auditability is now non-negotiable for Australian businesses assessing new technology vendors.

At Smartsheet, we see a clear parallel: visibility is key. Just as leaders cannot approve a project for which they cannot see the ROI, organisations cannot optimise work or leverage Ai effectively if they lack oversight. Platforms that embed standardised workflows and provide real-time insights empower teams to act decisively and mitigate risk. For Australian businesses, the message is clear: proactively adopting integrated work management and Ai-driven practices isnโ€™t optional – itโ€™s a strategic imperative. Those that act now will improve efficiency, project outcomes and position themselves as leaders in operational and Ai-driven excellence.


Jeremy Pell, Country Manager & AVP At Elastic

Demand For Context Engineering To Soar As Australian Organisations Scale Ai

Looking ahead to 2026, the biggest evolution weโ€™ll see in Australiaโ€™s Ai landscape is the shift from simply deploying Ai models to ensuring those models can reliably understand and act on an organisationโ€™s data. Thatโ€™s why context engineering will become the defining capability for any successful Ai initiative.

Right now, many Australian organisations are experimenting with Ai, but the biggest barrier to scaling those projects is fragmented data, especially unstructured information like documents, emails, product notes and customer feedback. Most Ai failures donโ€™t occur because the model is flawed, but because the model isnโ€™t given the right context to interpret the problem accurately.

Context engineering changes that. It enables Ai systems and agents to locate, retrieve and apply the most relevant information from across an organisationโ€™s data estate, no matter where that data lives or what format itโ€™s in. As agentic Ai becomes more common, the need for strong context engineering increases. Autonomous agents can only make good decisions if the information theyโ€™re acting on is complete, current and trustworthy.

Very few solutions on the market can deliver this reliably today, and we expect demand to grow rapidly in 2026 as Australian organisations move to operationalise Ai beyond pilots. Businesses will prioritise Ai platforms that place context engineering at their core, because thatโ€™s what ultimately determines accuracy, trust and measurable outcomes.

In 2026, the organisations that gain the most from Ai wonโ€™t be the ones with the biggest models, theyโ€™ll be the ones that ensure their Ai has the clearest understanding of their own data.


Kalyan Kumar, Chief Product Officer, HCLSoftware

The HCLSoftware Tech Trends 2026 confirms a non-reversible shift in the enterprise landscape, moving from technology experimentation to building entirely new foundations for business value. Our findings highlight four critical and interconnected movements.

In Cognition & Compute, Ai is finally moving out of the lab and into the core of operations, driving intelligent, adaptable platforms that evolve business processes. This pivotal shift is immediately reflected in Experience & Engagement, where interactions are moving beyond static screens to continuous, environment-aware services powered by spatial computing and global connectivity.

Crucially, as systems become more intelligent and pervasive, Resilience & Responsibility emerges as a non-negotiable design principle. Leaders now view safety, trust, and accountability as fundamental prerequisites for innovation, driving proactive responsible Ai programs. This new era is underpinned by a quietly evolving architecture captured in Frontiers & Foundation. Here, next-generation compute, including chiplet-based designs, and space-enabled insights from satellite data are defining the new infrastructure stack, ensuring organizations secure an essential edge for the decade ahead.


LogicMonitor: The new shape of the enterprise in 2026

Artificial intelligence (Ai) is weaving into every operational layer of business, and the enterprise of 2026 will look fundamentally different from the organisations we recognise today. Intelligent agents, autonomous systems and real-time observability will converge to create a new operating model built on foresight rather than hindsight. Companies will compete on the sophistication of their Ai governance, the fluidity of their organisational design and the intelligence of their infrastructure. LogicMonitor executives have outlined what this transformation will look like and the capabilities enterprises will need to thrive.

Governance Becomes An Engine For Innovation

Governance will grow in importance as organisations introduce more autonomous systems and clear oversight will become a business necessity rather than a compliance requirement. Ethical, transparent Ai will distinguish organisations that scale confidently from those that hold back due to risk or uncertainty.

“Enterprises will institutionalise Ai accountability by 2026 with a new executive seat: the Chief Ai Agent Officer,” Garth Fort, Chief Product Officer, said. “This leader will define, audit and govern the rules of engagement between humans and autonomous systems. Every Ai action will be observable, explainable and aligned with enterprise ethics. The organisations that adopt this role first will become the ones most trusted, proving that governance acts as a moral accelerator for innovation.”

Ai Networks Replace Traditional Structures

Organisational transformation will follow as Ai becomes core to how enterprises operate. Rigid, hierarchical organisational charts will no longer support the speed modern enterprises operate. Businesses in 2026 will organise themselves as dynamic, intelligence-driven networks where humans and Ai agents coordinate work in real time.

“The old-school organisation chart gets benched in 2026,” Christina Kosmowski, Chief Executive Officer, said. “Hierarchies built for human workflows will give way to Ai-first networks where people and intelligent agents team up and execute in real time. Think less playbook, more quarterback-on-the-fly. Information will move at the speed of intent. Decisions that once took quarters will happen before the next timeout. The companies that win won’t organise by function; they’ll be built for foresight. Every team will connect by data, every action will be shaped by intelligence and the best leaders will see the play before it happens.”

Information will move rapidly in this new operating model and teams will make decisions more quickly. This structural evolution will also reflect the shift from data acting as a static asset to becoming a real-time pulse of the enterprise.

“Data will do more than power the business; it will be the business,” Christina Kosmowski said. “The smartest Chief Executive Officers won’t track performance, they’ll feel it, like a coach who can read the momentum shift before it hits the scoreboard. Enterprises will use Ai-first observability to sense every operational signal, anticipate market pressure and respond with the speed of a two-minute drill. Ai will drive decisions rather than simply inform them and it will turn raw telemetry into game-changing moves that separate contenders from champions.”

Ai-To-Ai Collaboration And The Efficiency Reckoning

Transformation will reach the technological core as systems begin to collaborate directly with other systems. These machine-to-machine interactions will unlock major operational gains and organisations will need to monitor this complexity closely.

“The most transformative conversations won’t happen in boardrooms; they will happen between machines,” Karthik Sj, General Manager of Ai, said. “Ai systems will communicate, negotiate and optimise autonomously. The challenge will come from keeping those conversations intelligent, ethical and efficient. The leaders who master Ai-to-Ai observability will unlock a new level of operational foresight, where machine collaboration becomes the backbone of enterprise innovation rather than its blind spot.”

This intelligence revolution will redefine the infrastructure race. Enterprises will shift from accumulating graphics processing units (GPUs) to orchestrating compute with precision. Intelligent orchestration will turn underused data centres into self-optimising environments and efficiency will become one of the defining differentiators of 2026.

“The Idle GPU Epidemic will ignite an industry-wide awakening in 2026,” Karthik Sj said. “The question won’t focus on how much compute you own but how intelligently you orchestrate it. Enterprises will use Ai-first observability to maximise the return on investment from every watt, workload and chip. Winners will turn underused data centres into self-optimising ecosystems that drive autonomous growth and regenerative impact.”

Ai will shape the organisation structure, guide decisions and manage operational systems. The organisations that excel will design operations for continuous adaptation, prioritise ethical oversight and leverage machine intelligence to anticipate what comes next. Foresight will define strategy in 2026 and Ai will operate as the engine of the modern enterprise.


Nick Schneider, President And CEO, Arctic Wolf

On Market And Strategy

In 2026, Ai will be the catalyst for sweeping market consolidation. The past few years of fragmented, single-purpose cybersecurity tools have given way to unified platforms built around shared data, automation and embedded intelligence. As Ai capabilities mature, these one-off features will increasingly be absorbed into broader ecosystems – and the companies that can integrate, not just acquire, will win. The market is moving from best-of-breed to best integrated, with scale, telemetry and workflow interoperability defining the next generation of security leaders.

At the same time, buyers are shifting from evaluating technology on feature lists to measuring it by outcomes. They care less about the number of tools deployed and more about how fast they can contain and recover from attacks. Security Operations is becoming the standard category label for how organisations manage risk – where success is defined by speed, visibility and resilience. As capital markets normalise, investors will reward the operators who can prove Ai-driven efficiency and measurable risk reduction, rather than those who only market it.

On People And Culture

Contrary to early fears, Ai will not eliminate cybersecurity jobs – it will transform them. Organisations that integrate Ai copilots into their operations and invest in upskilling will close the skills gap faster than those resisting automation. Arctic Wolfโ€™s own experience proves that Ai can enable companies to hire, train and retain talent at scale – especially among Gen Z professionals who now represent a quarter of its SOC workforce. These Ai-assisted analysts are not being replaced; they are being elevated. Finally, I believe that speed itself has become a cultural differentiator. Companies that empower teams, make decisions at the edge and reward outcome-driven execution will outpace slower, hierarchical organisations. As autonomous SOC capabilities become the norm, trust and agility will define the next generation of cybersecurity leaders.


Dan Schiappa, President, Technology & Services, Arctic Wolf

Ai

Agentic Ai is widely considered the next frontier in cybersecurity for its ability to adapt, learn and execute actions on its own, absent of any human input or intervention. Despite its promise, the industry is far from seeing a fully autonomous Security Operations Centre (SOC).

Instead, in 2026, we push for transformation of the SOC, not by automating how SOCs work, but by reinventing how SOCs work with an expert-based approach. We will see the growing use of agentic Ai taking the lead with human aid, versus human leading with Ai aid.

This will radically transform how SOCs work by using experts to replace human expertise, but it will not completely replace human expertise. So having humans in the loop to provide human expertise, but also humans on the loop, so the human can provide oversight to actions taken by Ai and help to further refine the domain specific fine-tuned models used in the agentic framework. While the growing availability of high-quality data will help further SOC automation, human-in-the-loop processes will remain critical.

Zero Trust

In 2026 Zero Trust wonโ€™t just be a security model, it will be a corporate lifestyle and a defining principle of digital leadership.

The era of implicit trust will end with 2025. In its place will be a culture of continuous verification and intelligence authentication. Forward thinking organisations will recognise identity as the new perimeter and understand safeguarding it – as well as that of every vendor, partner and supplier they work with – is fundamental to reputation and growth.

Adam Marrรจ, CISO, Arctic Wolf

Threats & Risks

Humans have always represented a significant risk in cybersecurity because of the complexity of the modern technology environment and recent research shows that nearly 80 per cent of breaches involve a human factor. Attackers know itโ€™s easier to trick a person through social engineering than defeat a complex security system and Ai is making this process simpler.

In 2026 organisations will put an end to outdated security practices. Tick-box training is out of step with modern threats; its ineffectiveness highlighted by the fact even security leaders are fooled by certain social engineering tactics. Instead, new engaging training methods will be combined with a fundamental shift in mindset. Building a culture of shared ownership where all employees feel able to speak out about mistakes will be essential as the first line of defence in combating social engineering attempts.

CISO Outlook

2025โ€™s high-profile cyber-attacks on the likes of M&S and Jaguar Land Rover have put CISOs under a microscope. Growing awareness of the near-crippling operational, financial and reputational fallout of a successful hack is putting mounting pressure on CISOs.

Concerningly, two-thirds of technology leaders admit to clicking malicious links, proving the issue isnโ€™t only outside of the IT department. In 2026 CISOs will need to ensure they are both empowering employees to be vigilant and report suspicious activity but also setting the standard with their own security. Embedding cyber hygiene into company culture will be necessary to prevent and minimise threats before they become headlines in 2026.


ROI will be a focus for business leaders leveraging Ai in 2026

For Australian professional service businesses, 2025 was all about exploration and experimentation with Ai. Many organisations have spent the last 12 months running pilots, trailing, and evaluating AI software internally, and for many, that testing process has come to a natural end. Businesses are facing both internal and external pressure to validate and demonstrate the AI’s Return on Investment (ROI). 

Ai Adoption & Innovation will continue to drive business growth

Businesses that are quick to adopt new technologies, such as Ai, are often viewed as innovative, while those that donโ€™t adopt will quickly be perceived as lagging. This perception has the potential to negatively impact your business reputation, which, in turn, could ultimately affect your bottom line. As a result, there is growing pressure on businesses to leverage AI to maintain a positive public perception and gain a competitive advantage. 

Regulatory changes will continue to impact how businesses & professionals operate

Regulatory changes and court-issued guidance on Ai use will require companies to stay on top of the rules to ensure compliance and prevent reputational damage.


Adam Beavis, VP & Country Manager, Databricks Australia

#1 The move from generalised AI agents to domain-specific AI agents

General-purpose models trained on public internet data still struggle with the messy reality of enterprise processes because they lack deep organisational context. Moreover, in todayโ€™s regulatory and geopolitical climate, enterprises face growing demands for data and AI sovereignty – ensuring data privacy, security, and compliance within their specific jurisdictions and business environments.

Domain-specific agents, grounded in proprietary data with governed lineage, not only interpret internal rules, edge cases, and compliance constraints far more accurately but also uphold critical sovereignty requirements. This control over data and AI models reduces risk, meets legal and ethical obligations, and preserves competitive advantage.

Weโ€™ve already seen this play out. Suncorp Australia accelerated their AI experimentation and boosted model accuracy by pairing a flexible agentic Ai architecture with robust, enterprise-grade governance and monitoring. The lesson is clear: companies poised to succeed in the next AI wave will invest less in model size and more in data quality, domain depth, secure integration, and strong data and AI governance frameworks aligned with sovereignty demands.

#2 The move from single agent to multi-agent orchestration
Enterprise work rarely happens in a single step, and neither will enterprise Ai. Real workflows span retrieval, validation, approvals, and decisions across multiple systems and teams – far beyond what a lone agent can reliably handle. The next phase is multi-agent orchestration, where specialised agents handle tasks such as compliance checks, data retrieval, or reasoning, while a supervising agent coordinates them. 

Introducing a supervising agent sequences roles, delegates work, and synthesises results in natural language, enabling organisations to scale Ai beyond isolated pilots and into governed, auditable, adaptable workflows. 

#3 The move from one-off checks to continuous evaluation

As AI moves into production, continuous, real-time evaluation becomes nonโ€‘negotiable. Models that look strong in training often degrade on live data or drift as inputs change, and reliability erodes quickly without constant evaluation. The coming year will see enterprises adopt evaluationโ€‘centric practices, where agents are continuously measured against real tasks, real feedback, and changing conditions. 

Agent Bricks is built around this principle: it streamlines the development of domain-specific agents, lets teams define purpose and quality criteria in natural language, and automatically generates test suites and optimises performance based on enterprise data. By creating an environment where Ai evaluates Ai, enterprises can reduce uncertainty, accelerate deployment, and ensure agents continually learn from successes and failures to better fit their specific needs.

#4 The move from text to multimodality

AI has traditionally been text-first, but both consumers and enterprises now communicate through a mix of voice notes, videos, screenshots, sensor feeds, and chat messages. Multimodal Ai matches this reality by understanding and combining these diverse inputs, dramatically expanding what automation can do in real operations.

In practice, multimodal workflows augment human interpretation at scale. A customer service AI agent can read a userโ€™s message, analyse their tone of voice, and interpret screenshots or videos of the issue. In healthcare, models can fuse patient records, medical images, and sensor data to support more precise diagnoses and personalised treatment plans. In retail and e-commerce, multimodal agents can process reviews, product images, and usage videos to better understand customer preferences, improve recommendations, and spot fraud.

#5 The move from AI as a feature to invisible integration

The most successful Ai systems donโ€™t announce themselves. They disappear into workflows, quietly improving productivity without creating friction for employees or customers. 

Invisible Ai means that automation is embedded, consistent and intuitive. It becomes the environment teams operate within rather than a feature they must learn how to use. When systems are evaluated continuously, humans and AI can work together seamlessly in partnership and work accelerates. 

#6 A continued focus on skills

As Ai agents become embedded in day-to-day operations, organisations will need to keep investing in their people. This includes teaching them how to manage, guide, and collaborate with these systems, not just build them. You donโ€™t need to be a data professional to benefit: a marketer automating data entry, for example, mainly needs the prompting and workflow skills to direct an AI agent to take that work over.


Gagan Batra, Founder at MarTech Consultancy, Insighten

Martech Will Play A Pivotal Role In Driving Business Growth

Martech (Marketing Technology) is becoming a focus again for businesses in 2026 which is being driven by the volume of data organisations are producing. Businesses are generating more data than ever before; however organisations are still struggling to understand the best way to structure and leverage it to help propel business growth. Over the next 12 months weโ€™re going to see more brands looking to outsource that cross-functional Marketing and Technology expertise to support in the creation of data-based strategies that drive brand growth.

The Evolution Of Marketing Titles And Roles

In 2025 weโ€™ve witnessed the introduction of new roles such as โ€˜Chief Ai Officerโ€™ and โ€˜Chief Trust Officerโ€™ becoming more widely adopted within organisations. Over the next 12 months weโ€™ll see the death of traditional marketing titles and more combined marketing and tech titles will emerge as skill sets grow and cross-collaboration between marketing and tech teams continues. Iโ€™m expecting to see more roles focused on โ€˜Ai Strategistโ€™ and data governance becoming more mainstream especially within medium to large-sized organisations.

Weโ€™ll See The Rise In Privacy-First Marketing Strategies

Today much of digital marketing relies on both first-party and third-party data for targeting and personalisation. Ai-driven advertising initiatives such as Metaโ€™s Lookalike Audiences and Googleโ€™s Customer Match also depend on these data sources to train and optimise their models.

While this data is subject to privacy regulations enforcement in Australia has historically been less strict and less explicit than in markets with frameworks like the GDPR. That is changing quickly. With major privacy reforms underway the privacy conversation is set to further accelerate significantly in 2026.

Companies need to be proactive and adopt a privacy-first data and marketing strategy now rather than waiting for regulations to be fully enforced. Strengthening consent practices increasing transparency and building marketing strategies around first-party data will help organisations stay compliant reduce risk and maintain customer trust as the regulatory landscape evolves.


Steve Yen, Co-Founder Of Couchbase

Prediction 1: Before The Ai Bubble Pops, You Can Be Ready Ahead Of The Game

Whether the Ai bubble bursts in 2026 or 2027 forward-looking teams can prepare now for the opportunities that follow. As technologists weโ€™ve seen this pattern before: once the hype cools infrastructure becomes dramatically more accessible. That means more GPUs, more distributed data centers, more storage, more electricity, more edge processing and more capacity overall all at price points that open new doors for innovation. Smart organizations will treat this as a moment to plan so theyโ€™re ready to capitalise on the windfall on the other side of the bubble.

At Couchbase we expect this GPU surplus to accelerate what our database can deliver. We see a future of incredibly fast, massively parallel processing for operational workloads, differentiated data analysis capabilities, highly scalable vector indexing and search and new ways to serve Ai-powered applications at global scale. With GPUs, memory, storage and networking becoming cheaper and more widespread the price-performance curve shifts in favour of builders. And we couldnโ€™t be more excited about what that unlocks.

Prediction 2: The Next-Gen Of Developers Will Act More Like Conductors Guiding Fast-Moving Teams

The day-to-day work of a developer is shifting. Developers who want to stay ahead will use Ai the way a head chef runs a busy kitchen directing parallel tasks, comparing multiple options, deciding whatโ€™s worth keeping and pushing work forward quickly. The real skill is orchestration not trying to personally hand-craft every line of code. That shift will help teams ship faster and stay relevant.

The biggest advantage will come from understanding the higher levels of the system: how data flows, how subsystems behave under load and how to keep the bigger picture in focus across an increasingly distributed world that spans edge and cloud. Developer data platforms that support quick iteration, flexible data models and reliable edge-to-cloud performance will give teams what they need to supervise and collaborate with Ai so they can move faster than the competition.

Prediction 3: A New Kind Of Ai Slop Will Spike As Companies Generate Data Faster Than They Can Manage

The messy part of Ai for the enterprise wonโ€™t be the goofy content everyone jokes about. The real issue is the surge of semi-structured and regenerated data that Ai produces and the companies that shore up their data foundations now will be in the best position to take advantage of it. As business teams start building features, rewriting content and generating new forms of data on their own Ai will create new tables, new fields and new analytical artifacts at a pace older systems were never designed to handle. Without the right data infrastructure the result is confusion, duplicated information and a steady drop in confidence in what the data is telling you.

To keep this from turning into chaos enterprises need systems that can absorb constant structural changes, handle heavy ingest and support fast iteration. They also need ways to keep Ai grounded in reliable operational data so outputs donโ€™t drift or degrade. Pairing flexible JSON models with capabilities like vector search and production-grade scalability gives teams a practical way to move faster than the competition.

Prediction 4: The Gap Between GPU-Rich And GPU-Poor Companies Will Define The Next Phase Of Ai

The gap between the GPU haves and have-nots is going to get more obvious. The GPU-rich players are the hyperscalers and model labs that can afford data centers full of H100s and Blackwells. Everyone else is left figuring out what they can run without that level of compute. If you donโ€™t have the GPUs there are entire areas of Ai you simply canโ€™t touch right now.

But this divide wonโ€™t last. If the Ai bubble cools all that GPU capacity and all those new data centers donโ€™t vanish. They become available to the broader market at far more reasonable prices. That shift creates space for teams that arenโ€™t training giant models but still want to build meaningful Ai features on top of the expanding infrastructure stack. It also puts more attention on platforms that can store, sync and reshape the large volumes of data Ai produces without consuming half the budget on compute.

Prediction 5: Ai Will Push Development Cycles From Months To Days, And Data Platforms Will Need To Keep Up

Ai is going to speed up the way software ships. Business teams can already spin up prototypes or new features without waiting on developers and that pace will only increase. Work that used to take months may compress into days or even hours when Ai produces the first draft. Developers become reviewers and coordinators rather than being the sole point of execution.

That speed puts real pressure on the data layer. Schemas will change constantly. New fields and new collections will appear overnight. Applications will grow and shift in ways older systems werenโ€™t built to absorb. Teams will need data platforms that can handle rapid iteration, fast rollback and constant updates without putting production at risk. JSON-first databases with high ingest rates, support for quick structural changes and reliable edge sync will match the pace of Ai-driven development. Systems tied to rigid structures will fall behind as soon as the cycle accelerates.


Gopi Duddi, CTO Of Couchbase

Prediction 1: The Unstructured Data Goldmine Becomes Usable At Last

Companies will start pulling far more insight from unstructured data because the cost and accessibility of agents will make it practical to mine information that once sat untouched in silos. Data in Slack, email and documents will no longer sit idle since agents can run continuously and gather it in a usable form. As more communication happens in natural language the systems that process it will learn to work without predefined schema. JSON becomes even more important because it is easy for humans to read and easy for machines to interpret. This shift favours platforms that handle unstructured data well and can vectorise it for search and context-rich retrieval.

Prediction 2: English Will Be The Next Programming Language

Programming will move toward natural conversation as people rely on English to instruct systems rather than learning specialised languages. This shift increases the number of people who can automate tasks and create small programs because the barrier to entry becomes far lower. As more people generate information in unstructured form the volume of data needing storage and retrieval will rise quickly. Traditional programmers will uplevel their skills and guide the rewriting of complex systems while new creators rely on simple conversational prompts. The result is an environment where data platforms must store natural inputs and support a growing population of domain specialists: for example a doctor could theoretically write their own program.

Prediction 3: Power Consumption Will Become A Programming Metric

Power usage will become a key performance metric that programmers must consider as systems grow more resource intensive. Past practices focused on CPU and memory but the cost to run a program will now take into consideration how much energy it consumes. Programmers will need to measure how efficiently their applications use power and how much data they process in each cycle. Data movement will also factor in since regions differ in power costs which creates incentives to shift workloads such as relocating processing from a hot or expensive region to one with more abundant power. Platforms that allow data to move easily across nodes will give organizations more flexibility when optimising for power and cost.

Prediction 4: Ai At The Edge Will Prove Critical For Uptime And Safety

Edge devices will grow more powerful and begin to take on meaningful Ai processing rather than sending everything to a central service. Data will be created and consumed at the edge which reduces dependence on cloud availability. When networks fail businesses without an edge strategy will stall – as seen when retail locations like Starbucks have had to close because their cloud-based checkout systems went down – while resilient systems continue to operate. This matters for everyday services and retail as much as it does for emergency services where downtime can result in life or safety consequences. Organizations with strong edge designs will have a clear advantage in reliability and uptime.


Satchit Joglekar, Managing Director, ASEAN at Snowflake

Data Infrastructure Will Become Southeast Asiaโ€™s Ai Differentiator in 2026

In 2026, the ‘Ai advantage’ will evaporate for companies that rely on generic models alone. As Ai tools become easier to build and increasingly interchangeable, the real advantage shifts to the quality, connectedness, and trustworthiness of the data behind them. Early adopters already prove this: 92 per cent are seeing ROI from Ai, yet many still struggle with fragmented systems and data that isnโ€™t ready for machine learning. The biggest gains now belong to the companies that fix the foundation, not the ones chasing the flashiest model. 

The winners are those that master the “data flywheel”: unique data fuels Ai, smarter Ai produces even more unique data. This cycle builds a lasting competitive edge. In a region as dynamic and digitally driven as Southeast Asia, this shift will redraw competitive lines fast.

In a world where Ai tools are becoming commodities, the real advantage goes to enterprises that prioritize data quality, accessibility and identifying use cases with clear business impact. 


Carol-Ann Gough, VP Customer Success & Professional Services APAC, Guidewire

While Ai automation will continue to be a key priority for all insurers with adoption accelerating in the areas of claims, fraud and risk modelling, another emerging trend will be around regulation. Compliance will become increasingly data-driven and automated as insurers will be expected to demonstrate compliance in near real time – not just declare retrospectively. Compliance will move from reactive reporting to continuous controls monitoring. Compliance will need to be industrialised and insurers will require modern technology and data capability to operate at the standard expected. Whilst this sounds onerous the enhanced automation capability and data insights will also be key enablers for further improving operational efficiency and effectiveness as well as customer experience if applied and designed with these outcomes and benefits in mind.


Simon Wistow, Co-Founder & VP of Strategic Initiatives, Fastly

Ai companies are looking for more ways to incorporate their tools into daily life with much of that shift happening on the open web. Ai crawlers continue to make up most of all Ai bot traffic reshaping how the internet is accessed and experienced. Digital publishers need search engines to drive traffic and Ai crawlers need the content to build their models and also to power their Retrieval-Augmented Generation (RAG) queries. In 2026 publishers and Ai crawlers will forge a new symbiotic partnership where both sides can co-exist. Agentic commerce is one area where this dynamic is emerging with eCommerce site owners and Ai companies working together to shift towards an Ai-powered customer journey. Publishers will work with Ai companies to strike a balance between openness and control on the internet encouraging a robust and open web ecosystem that benefits both publishers and creators.


Michael Hubbard, Chief Customer Officer, Ping Identity

Verified workforce identity will evolve from a one-time hiring checkpoint – and beyond 2025โ€™s reactive posture – into a core operational discipline. After years of increasing cases where workforce members werenโ€™t who they appeared to be due to deepfakes, credential fraud or simple breakdowns in verification enterprises can no longer assume that their people are who they say they are.

The coming year will mark the rise of enterprise-wide reverification programs and digital credential issuance as part of standard identity operations. In 2025 early adopters learned how to operationalise these programs; in 2026 the playbooks and technology are ready. Organisations will now have clear guidance on how to prioritise roles, navigate name mismatches, manage leaves and PTO and minimise disruption. Whether driven by internal teams, third-party partners or hybrid approaches the leading companies will treat reverification as an ongoing muscle. Over time digital credentials tied to the enterpriseโ€™s core identity fabric will reduce the need for repeated verification and serve as a foundation for a more trusted resilient workforce.


Gareth Cox, Vice President, APJ, Exabeam

The agentic era is here: IDC research shows that 40 per cent of Asia Pacific and Japan (APJ) organisations already use Ai agents with over 50 per cent planning to implement them within the next year. As organisations embrace this shift they will need to rethink how they manage insider risk. Increasingly insider risk isnโ€™t just emerging from rogue employees or compromised accounts but also Ai agents that operate autonomously with diverse privileges allowing them to bypass security oversight and amplify data exposure. These synthetic identities are creating entirely new categories of insider threats whether it is malfunctioning agents that behave unpredictably, misaligned agents that follow flawed prompts into compliance or privacy issues or subverted agents that can be weaponised by bad actors against the business.


Nataly Kremer, Chief Product Officer & CTO, Check Point Software

While a fully realised Web 4.0 is still emerging 2026 will lay its foundations. This next-generation web blends spatial computing, digital twins and Ai at the operating-system level. Entire cities, industrial plants and corporate campuses will function through real-time virtual models enabling engineers to simulate maintenance, test security patches or visualise risk scenarios before touching the physical environment. Extended-reality interfaces, augmented and virtual will replace dashboards allowing staff to walk through data rather than read it.

This convergence promises vast efficiency and safety gains but introduces complex interoperability challenges. Disparate systems and standards must communicate seamlessly; otherwise visibility becomes fragmented and exploitable.


Roy Verboeket, VP of Systems Engineering, Extreme Networks

By the end of 2026 Ai wonโ€™t be just a useful tool. It will be an additional team member running networks autonomously with human network administrators simply approving Ai actions – something we refer to as human-in-the-loop. IT will shift from reacting to problems to preventing them before they even occur. Autonomous and agentic Ai will take over repetitive tasks, predict failures ahead of time and continuously optimise performance and security without the need for continuous human input. This isnโ€™t about replacing people itโ€™s about freeing them to focus on strategy, innovation and delivering real business outcomes. In short weโ€™ll move from firefighting to forward-thinking network management.


Jason Hardy, Chief Technology Officer of AI, Hitachi Vantara

2026 is when physical Ai moves from pilot programs to production floors. Enterprises that master the integration of agentic intelligence with robotics and IoT will gain decisive competitive advantages in manufacturing efficiency and sustainability. The ROI is clearer here than anywhere else in Ai because it’s tied to physical output: products made faster, cheaper and with less environmental impact.

ROI means having a plan not hope. CIOs face pressure to ‘do Ai’ but successful ones in 2026 will resist the headlong rush and instead focus on specific measurable outcomes. ROI combines direct cost recovery with learning value: understanding what infrastructure improvements enable Ai success while ensuring the Ai investment itself becomes self-sustaining.


Carrie Rasmussen, Executive Vice President, Chief Digital Officer,Dayforce

In 2026 CIOs and CDOs will work more closely than ever with CHROs and CPOs to shape how Ai is introduced and embraced in their organisation. With Ai fundamentally changing the way we work and transforming the skills people need the old ways of rolling out new technology wonโ€™t suffice – IT and HR must move in lockstep as Ai demands a cultural shift. The organisations that get this right will reskill their workforce faster, redesign jobs more thoughtfully and build cultures where people and Ai grow together.


Pierre Lamy, Principal Threat Intelligence Researcher, Anomali

The job market will continue to feel the effects of the mass layoffs that defined 2025 not just driven by shrinking budgets but by a growing divide between workers who have embraced Ai technologies and those who havenโ€™t. Productivity never fully recovered after COVID and companies are increasingly unwilling to retain employees who arenโ€™t leveraging Ai and LLM tools to enhance their performance. By late 2026 weโ€™ll see a course correction: hiring will pick back up but it will be significantly more selective favouring individuals who have upskilled into Ai fluency and can blend human intuition with Ai-powered processes to deliver outsized productivity.


Chris Calverley, Head of Sales and Partnerships ANZ, Avalara

E-invoicing has been bubbling along for years but next year it will hit full stride across APAC including a 2026 mandate go-live in Australia. Governments are tightening the screws on digital reporting and if youโ€™re not ready youโ€™ll be flat out trying to keep up. Aussie exporters who get their e-invoicing sorted early will save time, cut down on errors, avoid last-minute dramas and begin experiencing new business efficiencies and cost savings. Itโ€™s like checking your ute before a long road trip: better to do it now than break down halfway.


Pieter Danhieux, CEO and C0-Founder, Secure Code Warrior

Weโ€™ve had a few years to play around with Ai coding assistants, Ai cybersecurity tools and most recently agentic Ai models working autonomously on various processes in the SDLC. Our own experiments with a range of LLMs solving comprehensive code-level security challenges revealed that in general most models had a reasonably high success rate in addressing more linear vulnerabilities such as SQL injectionโ€ฆ a problem that has plagued us since Coldplayโ€™s debut on the charts. It would not surprise us if in 2026 a tool were released that could reliably and consistently detect and remediate SQL injection bugs essentially eradicating it as a prominent vulnerability class for the first time since its discovery.

However there is a catch: with hallucinations and security degradation remaining inherent problems in LLMs false positives will remain a significant hurdle to overcome. Security-proficient developers will still be key to the safe use of a tool like this and will need the necessary skill set to review and test code before it is deployed.


Morey Haber, Chief Security Advisor, BeyondTrust

Online banking and digital transactions over the last two decades have become the norm for receiving bills and paying ebills. While attacks on personal and business financial accounts are nothing new I believe we will see a ramp up in attack vectors poisoning consumer and business accounts. The poison comes from all the automation possible to create payees, billers, request funds and link to other online payment processing sources. In the next year threat actors will find novel ways to insert faux billers and payees worse modify existing ones, process funds via third party brokers and link them to transactions that exfiltrate funds.

This entire attack vector will occur due to weaknesses in online financial systems, the exposed nature of accounts if the credentials or routing and account number are compromised and the ease that automation can obfuscate a transaction in a current account. Today it is not uncommon for trusted billers and payees to be poisoned by threat actor accounts to siphon funds destined for legitimate sources. While this is just one example I expect account poisoning to rise next year as financial organisations defend against account attacks at an individual level. This will require greater diligence in identity confidence for any changes in a userโ€™s financial accounts especially with regards to automation where poor secrets management could be leveraged to attack accounts in bulk.


Over the past decade thereโ€™s been an extraordinary shift from on-premises to centralised cloud computing. Now weโ€™re starting to see the pendulum swing back a smidgen. Enterprises are looking to deploy edge infrastructure to enable immediate decision making for latency sensitive applications – think industrial IoT, smart manufacturing and connected vehicles. The end game for those that take this tack in 2026? The creation of massive intelligent and highly strategic connected eco-systems that combine high speed, low latency 5G networks with IoT devices.


Erich Kron, CISO Advisor, KnowBe4

Ai agents will reduce mean time to respond (MTTR) by at least 30 per cent. While attackers weaponise Ai, defenders are positioned to gain a decisive advantage as agentic Ai systems mature. Most popular software and services will not only be rebuilt as agentic Ai but will also show positive returns on reducing cybersecurity risk compared to their pre-agentic Ai counterparts. For SOC teams, tier-one triage, enrichment and containment actions will be policy-guardrailed and executed by agentic systems, cutting MTTR by 30 to 50 per cent in mature teams. These Ai security agents will also be able to maintain immutable audit trails of every action and generate regulatorโ€‘ready incident summaries, reducing the compliance burden and speeding postโ€‘incident reviews.

Erich Kron
Erich Kron.

However, cyberattackers will also use Ai-enabled tools to deliver more pervasive and successful hacking as compared to traditional attack tools. Attacks will continue to be targeted and focused more on quality versus quantity as Ai, automation and generative Ai features become commonly used, making attacks more realistic and harder to spot.

Humans and Ai agents will be the new workforce. The most transformative shift in 2026 will be the evolution of Ai from passive tools to active, autonomous members of the security team, triggering a fundamental shift in how organisations must think about their workforce. As agentic Ai systems move from experimental tools to core operational team members, organisations deploying agentic Ai will need to expand their definition of โ€˜workforce trainingโ€™ to include the policies, guardrails and behavioural expectations for Ai agents.

Q-Day, the day when quantum computers become sufficiently capable of cracking most of today’s traditional asymmetric encryption, will likely happen in 2026. While privacy concerns have kept mandatory digital IDs largely at bay, digital identities tied to their real human identities are expected to grow in popularity and become increasingly necessary for accessing digital services. The security of these systems has never been more important. Organisations must strengthen human authentication through passkeys and device-bound credentials while applying the same governance rigour to non-human identities like service accounts, API keys and Ai agent credentials.

Shadow syndicates will use cyber tools to target geopolitical flashpoints. Critical infrastructure and essential services will remain prime targets in 2026, especially energy and water sectors as they accelerate digital transformation. We can reasonably expect increased attacks exploiting legacy OT systems and cloud integrations, combined with Ai-driven phishing targeting government and healthcare. In 2025, Australia saw a surge in Ai-powered cyberattacks, including deepfake-enabled social engineering and highly personalised phishing campaigns, impacting critical infrastructure and supply chains. These incidents highlight how adversaries are weaponising Ai to bypass traditional defences. Coupled with new ransomware reporting rules introduced this year, organisations will face mounting pressure to adopt zero-trust strategies, strengthen identity controls and prepare for quantum-safe encryption.


Marc Laliberte & Corey Nachreiner of WatchGuard Technologies

Crypto-Ransomware Goes Extinct
In 2026, crypto-ransomware will effectively go extinct, as threat actors abandon encryption and focus on data theft and extortion. Organisations have significantly improved their data backup and restoration capabilities, meaning theyโ€™re more likely to recover from a traditional crypto-ransomware attack without having to pay the extortion demands. Instead, cyber criminals simply steal data, threaten to leak it and even report victims to regulators or insurance companies to increase pressure. Encryption no longer pays off; the real leverage will now come from exposure.

OSS Package Indexes Will Leverage Ai To Defend Against Supply Chain Attacks
If the surge of attacks against open-source package repositories like NPM and PyPI has taught security teams anything, itโ€™s that open source is under siege. Traditional security controls such as tighter authentication and shorter token lifetimes canโ€™t keep up. In 2026, open-source package repositories will adopt automated, Ai-driven defences to fight back against a growing wave of supply chain attacks. These repositories will become early adopters of automated SOC-style systems, enabling them to detect and respond to attacks in real time.

CRA Reporting Requirements Finally Incentivise Secure-By-Design Principles
In 2026, the EU Cyber Resilience Act will become the market force that drives adoption of secure-by-design principles. With the first phase going into effect in September, software manufacturers selling into the EU must report actively exploited vulnerabilities and security incidents within 24 hours. While the initial rollout will likely be chaotic, it will ultimately create a lasting incentive to build security into products from the start. Overlapping global regulations will reveal competing frameworks and contradictions, forcing organisations to navigate an increasingly complex compliance landscape.

The First Breach Carried Out By Autonomous, Agentic Ai Tools Will Occur
In 2025, WatchGuard predicted that multi-modal Ai tools would be able to carry out every aspect of the attackersโ€™ cyber kill chain. In 2026, Ai will stop just assisting cybercriminals and start attacking on its own. From reconnaissance and vulnerability scanning to lateral movement and exfiltration, autonomous systems will orchestrate entire breaches at machine speed. This first end-to-end Ai-executed breach will be a wake-up call for defenders. Organisations must deploy Ai-driven defence tools capable of detecting and remediating at the same velocity.

The Fall Of Traditional VPNs And The Rise Of ZTNA
VPNs and remote access tools remain top targets due to credential theft and lack of MFA. At least one-third of 2026 breaches will be linked to VPN misconfigurations. Attackers have increasingly targeted VPN ports over the last two years. In response, small and mid-sized businesses will begin adopting Zero Trust Network Architecture (ZTNA), which provides access to specific internal services without exposing broader networks.

Ai Expertise Becomes A Required Cybersecurity Skill
Security professionals must evolve beyond basic Ai knowledge. Offence and defence are now taking place in an Ai battleground. To survive, teams must harness Ai for detection, response and resilience. By 2026, Ai literacy will be essential, with practical applications scrutinised during hiring processes.


Adhil Badat, Managing Director, Rackspace Technology

As we head into 2026, businesses are moving past the hype and into the hard work of making Ai practical, affordable and trustworthy. Here are three big shifts I see coming:

  • Subscription Fatigue And Multi-Cloud Complexity Will Drive New Consumption Governance
    Ai workloads are creating budget headaches across cloud platforms, with costs now measured by usage. The old budgeting playbook no longer works. Companies will need real-time dashboards to track usage, spending and carbon emissions.

  • Domain-Specific Ai Models Will Eclipse Generic LLMs
    Generic large language models arenโ€™t enough for highly regulated or knowledge-heavy industries. Domain-Specific Language Models (DSLMs) will gain traction due to better accuracy and compliance, though they will require cleaner data and governance investment.

  • Third-Party Ai Risk Will Force Procurement Changes
    With Ai now embedded in nearly every product, risk extends to how models behave over time. Contracts will evolve to cover bias, model drift and data usage, forcing procurement teams to consider new categories of vendor accountability.โ€

Ramy Houssaini, Chief Cyber Solutions Officer, Cloudflare

Boards Prioritise Resilience Over Cost
Traditional SaaS models with static features and centralised data silos are losing ground. Organisations are demanding Ai-native, real-time and context-aware services. In 2026, companies will prioritise edge-deployed, domain-tuned models and pay for intelligence, not seats.

The Premature Death Of SaaS And The Rise Of Ai-As-A-Service
In 2026, enterprise software procurement will shift. Organisations will move away from seat-based SaaS toward Ai-as-a-Service models. These will be intelligent, localised and tailored, with smart Ai assistants becoming the primary interface for work.

Industrial Ai Goes Mainstream
Legacy OT environments will adopt Ai to shift from reactive to predictive operations. Ai will control equipment in real time, optimising performance. This requires a major security rethink, with agentless Zero Trust models verifying every machine interaction instantly.


Gal Diskin, VP Identity Threat And Research, Delinea

Ai-Native Attacks Outpace Human Detection
In 2026, Ai-generated attacks will consistently outpace human defenders. Threat actors will deploy dynamic, self-learning exploit chains that evolve in real time. Defensive Ai will become essential, with success measured by “mean time to algorithmic response” rather than traditional detection metrics.

Key manifestations include:

  • Adaptive exploit chains

  • Generative malware that bypasses signature detection

  • Identity evasion using Ai personas

  • Kill chains compressed from hours into minutes

Synthetic Identities Blur Human-Machine Boundaries
Synthetic identities will be a key threat in 2026. These combine real and fabricated attributes to bypass verification systems.

Trends include:

  • Ai-crafted personas impersonating staff or contractors

  • Blended identity fraud using stolen PII and Ai data

  • Espionage through Ai posing as recruiters or journalists

  • Deepfake-assisted validation to defeat biometric checks

Traditional credentialing will no longer be enough. Continuous behavioural validation and cryptographic assurance will be required to maintain digital trust.


Daniel Garcia, VP & GM, APAC, Kaseya

AI adoption: How will AI deliver actual ROI in the SMB landscape and what are the biggest threats?

While there is plenty of noise about AI taking jobs, the reality for SMBs in 2026 is that AI will be the ultimate force multiplier for leaner teams. Our 2025 Global IT Trends Report shows that 27% of IT professionals now see AI as benefitting their business, a significant jump up from 20% in 2024 in sentiment.

Daniel Garcia
Daniel Garcia.

However, the biggest threat to AI ROI isn’t the technology itself. It is the ‘Trust Gap.’ Our research shows that only 12% of businesses currently trust AI to act autonomously. This hesitation is a bottleneck. To get actual ROI, MSPs must bridge this gap by implementing AI where it delivers immediate, verifiable wins, specifically in end-user productivity and IT efficiency, which are now top priorities for nearly 30% of IT teams.

For the APAC region, where IT teams are running leaner, 68% of organisations now operate with fewer than 25 IT employees. AI is not about reducing headcount, it is about preventing burnout and increasing capacity. We are already seeing 45% of respondents using AI to automate routine patching and scripting. The bottom line is, AI doesn’t replace your experts. By offloading repetitive maintenance to AI, you free your most valuable talent to focus on high-impact, revenue-generating initiatives that drive true business profitability.

What dangerous trend should SMBs avoid in 2026?

The most dangerous trend facing SMBs in 2026 is a false sense of resilience. We are seeing a worrying disconnect between the tools businesses buy and their actual readiness to recover from an attack.

While 76% of businesses conduct annual penetration tests, nearly one in four are inconsistent or skip it entirely. Even more concerning is Incident Response (IR). Our data shows that 27% of organisations have an IR plan but have never tested it. In a landscape where human error is predicted to be the top threat vector for the next 12 months, an untested plan is effectively no plan at all.

For SMBs, 2026 will be the year when checking the box is no longer sufficient. With phishing remaining the most relentless threat, 74% of MSPs anticipate it being the top attack vector. We will see a forced maturity in the market. SMBs will increasingly demand proof of resilience, not just promises of protection. This means regular fire drills, phishing simulations, and recovery testing will move from optional add-ons to non-negotiable requirements for cyber insurance and compliance.


Andrew Amos, Vice President APAC, Diligent

Andrew Amos
Andrew Amos.

In 2026, CPS 230 will fundamentally reshape board governance by placing operational risk, resilience and incident management directly in directorsโ€™ hands mirroring the direction already set by the Security of Critical Infrastructure (SOCI) Act. Both frameworks now demand clear, defensible visibility across critical assets, technology environments, cyber posture, supply chains and third-party dependencies. Under SOCI, entities must actively manage hazards, maintain a CIRMP, uplift cyber resilience and report incidents rapidly, closely aligning with CPS 230โ€™s requirements for robust risk frameworks, scenario testing, service-provider management and director-level accountability. Together, these regulatory regimes signal a governance era where active, ongoing oversight becomes the expectation rather than periodic updates.

To meet these rising standards, organisations will need to shift from traditional reporting to real-time risk intelligence through live risk registers, automated incident alerts, integrated operational and cyber dashboards and systems that clearly link risks, controls, owners and evidence. While CPS 230 applies to APRA-regulated entities and SOCI applies to critical infrastructure operators, both are increasingly shaping governance norms across all sectors. In the coming year, proactive risk management, uplifted cyber resilience, disciplined incident response and stronger board oversight will become common governance themes. Organisations that embrace this shift early and treat CPS 230 and SOCI as strategic catalysts not minimum obligations will be best positioned to withstand regulatory scrutiny and build true operational resilience in an unpredictable environment.


Tom Varsavsky, CTO, SiteMinder

Ai is increasingly reshaping the software industry in ways that are both profound and familiar. As we look to 2026, this evolution will feel like a natural extension of the automation engineers have been refining for years. The best engineers have always been highly adaptable, driven by curiosity, discipline in their craft and committed to continual learning. Ai simply amplifies these strengths, offering new opportunities to remove friction, accelerate delivery and elevate the quality of the products they build.

Tom Varsavsky
Tom Varsavsky.

But while Ai can significantly boost productivity, it cannot replicate the understanding that experienced engineering teams bring. The hardest problems in software engineering aren’t solved by typing code faster. They’re solved by understanding customer problems, creating the right solutions and measuring impact accurately. Building the right thing will always trump building the wrong thing quickly. And developers who have spent years refining and truly understanding a product and its customers bring historical knowledge and pattern recognition that no model can replicate.

Counter-intuitively, lowering the cost of software production will create even more demand for software and software engineers. The low level tasks will be automated, but there will be much more software in the world to build and maintain by Ai enabled engineers.

As such, Ai will not be replacing engineers in 2026. Instead Ai will propel high-performing teams to achieve more than ever before. When Ai is placed in the hands of experienced engineers who already collaborate well and think critically, it becomes a force multiplier, sharpening decision-making, speeding up experimentation and unlocking innovation at a scale traditional methods canโ€™t match.

In this next phase of software development, human expertise remains the anchor, and the soft skills that stem from it – customer empathy, collaboration, communication and creativity – will hold even greater value. Ai is simply the accelerator.


Nick Martin, APAC GTM Lead, Remote

Ai is reshaping hiring in Australia and according to Remoteโ€™s latest Global Workforce Report, almost a third of Australian organisations introduced new Ai tools into their hiring processes this year. Yet the same proportion are questioning those decisions after encountering fairness issues, compliance risks and a wave of Ai-generated resumes slipping through screening. The report shows that adopting Ai without guardrails creates new friction instead of speeding processes up.

Nick Martin
Nick Martin.

We are increasingly seeing a shift in the market where HR teams are going from experimenting with Ai to embedding it meaningfully by integrating Ai into the backbone of their HR systems including global payroll, cross-border compliance and onboarding rather than just at the front end of hiring. Organisations will continue to use Ai to eliminate manual work, create consistency and give HR teams more bandwidth to focus on performance, development and strategic workforce planning.

In 2026, we will also see global hiring continue to rise, with two-thirds of Australian businesses having employed talent overseas in 2025. However the infrastructure to support this growing trend is lacking. Fragmented systems, costly entity setups and compliance uncertainty are still slowing growth for global hiring.


Stuart Low, CEO & Founder, Biza.io

As we head into 2026, the Consumer Data Right is poised to become one of the defining forces shaping how Australian businesses compete. In a cost-of-living environment that shows no sign of easing, consumers will be more intentional about where and how they spend and far more vocal about wanting more choice and control over their spending. With more sectors joining the CDR ecosystem, the businesses that use data to bring clarity, fairness and transparency to customers will be the ones that earn their trust.

Stuart Low
Stuart Low.

Businesses are also facing increasing pressure to strengthen their data security posture. As organisations collect and manage more sensitive information than ever, the margin for error continues to shrink. Itโ€™s clear that customers are no longer just choosing products or services anymore – they are choosing which companies they trust to safeguard their data, and that trust is becoming a decisive competitive advantage.

This is why 2026 must be the year businesses stop treating compliance as a box-ticking exercise and start seeing it for what it is: an opportunity. CDR compliance strengthens products, accelerates innovation and builds lasting customer confidence. Organisations need to invest early, get the foundations right and recognise that in the CDR era, trust is the most valuable competitive edge they have.


James Greenwood, VP Customer Success & Solutions Engineering APAC, Tanium

This year we saw businesses shift from a reactive to proactive approach to business resilience. In 2026, we’ll see more businesses move beyond this, towards preventative and autonomous systems and processes that leverage Ai and agentic Ai to meet bad actors’ level of scale and sophistication.

James Greenwood
James Greenwood.

To date, Ai hasn’t delivered on the astronomical operational and financial impacts that it’s been hyped up to deliver for most businesses. This is because most business strategies around Ai so far have been piecemeal. As businesses start to embed Ai into their ways of working, underpinning it with strict governance measures, we’ll see businesses moving faster, smarter and in ways that allow them to tackle issues like cyber security and business risk with an always-on, offensive stance.

To make the most of Ai, we’ll also see more businesses address their data accuracy, integrity and accessibility. We’ll see more businesses invest in the power of real-time data so they can make better decisions as needed to prevent risks and threats rather than fix problems after they’ve happened. Businesses are increasingly recognising that Ai and predictive analytics are almost useless without reliable data to leverage, and gaining a real-time, genuine understanding of “what” data is “where” and for “how long” will become a business imperative to capitalise on the Ai wave.


Tom Scully, Principal Architect, Gov & Critical Industries, APJ, Palo Alto Networks

Tom Scully
Tom Scully.

Ai is not just changing the threat landscape, it is fundamentally breaking our assumptions about trust. When a single deep fake CEO, poisoned dataset or hijacked agent can trigger damage at machine speed. 2026 will be the Year of the Defender, with autonomous AI the only way to keep pace with an unprecedented threat environment. 

As we enter the AI economy, the mandate is clear. We must build visibility before capability, constrain the power surface and enforce zero trust across every agent and interaction. In 2026, resilience will belong to organisations that can observe, govern and correct AI-driven risk in flight.

From the anticipated surge in Ai-driven identity attacks to the new wave of executive liability for rogue AI, these predictions for 2026 serve as essential guidelines for organisations to shape their cybersecurity strategies and confidently navigate the new autonomous economy. 


Palo Alto Networks 2026 Ai and Cybersecurity Predictions:

  1. The New Age of Deception: The Threat of AI Identity: In 2026, identity will become the primary battleground as flawless, real-time AI deepfakes โ€” or CEO doppelgรคngers โ€” make forgery indistinguishable from reality. This threat is magnified by autonomous agents and a staggering 82:1 machine-to-human identity ratio, creating a crisis of authenticity where a single forged command triggers a cascade of automated actions. As trust breaks down, identity security must transform from a reactive safeguard into a proactive enabler for the enterprise, securing every human, machine and AI agent.

  2. The New Insider Threat: Securing the AI Agent: Enterprise adoption of autonomous AI agents will finally provide the force multiplier needed to solve the 4.8 million-person cyber skills gap and end alert fatigue. This is also an inherent risk, creating a potent new insider threat. These always-on, implicitly trusted agents are given privileged access and the keys to the kingdom, instantly becoming the most valuable target. Adversaries will no longer make humans their primary target; they will look to compromise these powerful agents, turning them into an โ€œautonomous insider.โ€ This forces a shift to autonomy with control, requiring AI firewall governance tools at runtime to stop machine-speed attacks and ensure the AI workforce isnโ€™t turned against its owners.

  3. The New Opportunity: Solving the Data Trust Problem: Next year, the new frontier of attack will be data poisoning โ€” invisibly corrupting AI training data at its source. This attack exploits a critical organisational silo between data scientists and security teams to create hidden backdoors and untrustworthy models, igniting a fundamental โ€œcrisis of data trust.โ€ As traditional perimeters become irrelevant, the solution must be a unified platform that closes this blind spot, using data security posture management (DSPM) and AI security posture management (AI-SPM) for observability and runtime agents for firewall as code to secure the entire AI data pipeline.
  4. The New Gavel: AI Risk and Executive Accountability: The enterprise race for an AI advantage will collide with a new wall of legal reality. By 2026, the massive gap between rapid adoption and mature AI security (with only 6% of organisations having an advanced strategy) will lead to the first major lawsuits holding executives personally liable for rogue AI actions. This โ€œNew Gavelโ€ elevates AI from an IT issue to a critical liability issue for the board. The CIOโ€™s role must evolve to that of a strategic enabler โ€” or partner with a new Chief AI Risk Officer โ€” using a unified platform to provide verifiable governance that enables innovation safely.

  5. The New Countdown: The Quantum Imperative: The โ€œharvest now, decrypt laterโ€ threat, accelerated by AI, creates a crisis of retroactive insecurity, as data stolen today becomes a future liability. With the quantum timeline shrinking from a ten-year problem to a three-year one, governmentsโ€™ mandates will soon force a massive, complex migration to post-quantum cryptography (PQC). This immense operational challenge requires organisations to shift from a one-time upgrade to building long-term crypto agility โ€” the ability to adapt cryptographic standards as a new, non-negotiable security foundation.

  6. The New Connection: The Browser as the Novel Workspace: As the browser evolves from a tool for information synthesis into an agentic platform that executes tasks, it is becoming the new OS for the enterprise. This trend creates the single largest, unsecured attack surface โ€” an AI front door operating with a unique visibility gap. With GenAI traffic up over 890%, organisations will be forced to adopt a unified, cloud-native security model capable of enforcing consistent zero trust security and data protection at the last possible millisecond โ€” inside the browser itself.

Last Updated on February 4, 2026 by Nick Ross

Surprisingly Useful AI Article Enhancements

Sign-up to the SMBtech Daily Newsletter

We will not spam you. You can easily unsubscribe any time. Read our privacy policy.