AI Is Slashing the Cost of Hacking, and Enterprise Software Security Can't Keep Up
As AI agents proliferate across codebases, cloud infrastructure, and financial workflows, identity management may become the real control layer for enterprise AI.

AI Is Slashing the Cost of Hacking, and Enterprise Software Security Can't Keep Up
According to a PYMNTS report dated October 1, 2026, AI is dramatically lowering the cost of launching sophisticated cyberattacks. Researchers are using automated tools for reconnaissance, code analysis, and vulnerability testing, giving individuals capabilities that previously required a professional security team. At the same time, enterprises are connecting AI agents to codebases, cloud infrastructure, corporate databases, and even financial workflows. Each connection creates a software identity with credentials and permissions—and if those credentials leak or permissions are excessive, the potential financial risk is significantly amplified. The report cites a case in which a 16-year-old security researcher used a self-built AI-assisted tool to investigate Microsoft's internal systems. The article notes that identity management may become the true control layer for enterprise AI, and that competitive advantage will no longer depend solely on the quality of models, but increasingly on the ability to securely govern what thousands of software identities can see, access, and do.
Source: https://www.pymnts.com/news/artificial-intelligence/2026/hacking-is-getting-cheaper-faster-than-enterprises-can-make-software-safer/
Provenance & status
- Byline
- OceanAlt Editorial
- First published
- 2026-10-02
- Last updated
- 2026-10-02
- Content type
- Newsflash
- Source material
- View original ↗
Related reading

NVIDIA Open-Sources Agent Security Platform: Another Piece in the Agent Security Infrastructure, from Testing to Deployment

Robinhood Lets AI Agents Trade Without Per-Order Approval — and Clients Bear the Losses

OpenAI Agent Crosses the Line into Australian Government Website: First Confirmed AI Agent Intrusion
Paste a payee address before you pay and see whether it's on a sanctions list, through a mixer, or tagged for fraud.
This judgement can sit inside your own product
One line of code; it touches neither your CSS nor your JS. The same pre-settlement judgement can appear in your articles, on your wallet's confirmation screen, or as an endpoint your agent calls before it pays.

