White Paper | Protecting Intelligence
Learn how to secure enterprise AI, reduce AI-driven risks, and protect people, applications, and agents with practical security strategies.

Protecting Intelligence The Enterprise Guide to AI Security.
What changed, where the risk lives, and the first five moves to make to secure your organization from AI-driven threats.
A U G U S T 2 0 2 6
P R O T E C T I N G I N T E L L I G E N C E
Contents.
Executive Summary The whole guide in one page
02
01 The Year AI Stopped Asking Permission Five documented incidents from the last 12 months
03
02 Why Your Security Stack Misses AI Threats The tools you trust were built for a different question
07
03 The Three Places AI Risk Lives Your people, your applications, your agents
09
04 The Gap, By the Numbers The 51-point gap and the evidence behind it
13
05 What Good Looks Like Discover, govern, protect, at control points you already own
15
06 The First Five Moves Five moves in order, each with a done-when
17
07 Where to Go From Here The reading map and the first thing to do this week
19
References 20
P R O T E C T I N G I N T E L L I G E N C E 02
EXECUTIVE SUMMARY
AI stopped assisting and started acting. Security has to do the same. Enterprise AI now reads, decides, and acts. In just a few short years, AI has evolved from experimentation to operating autonomously in organizations, answering your customers, writing your code, moving your data, and completing tasks on its own. But autonomous AI creates a new kind of security problem: securing intelligence. The attacks that matter are written in plain language, not code. And the incidents that should worry you most involve no hacking at all.
The evidence is out there. Autonomous AI has now been involved in some very real, and very damaging security breaches. In the past year, one operator used a jailbroken AI coding agent to breach nine government agencies. A state-linked espionage campaign let an AI agent do up to 90 percent of the work, by the AI provider’s own account. And the world’s most advanced models moved beyond the boundaries of their makers’ test environments only because they pursued their goals in ways nobody anticipated.
Meanwhile, many organizations have adopted AI faster than they can control it. 77 percent of security leaders have changed their security strategy for AI, but only 26 percent say they have the architecture to enforce that strategy. That is a 51-point gap between intent and enforcement, and it is where the incidents happen—rules that exist on paper while prompts, data flows, and agent actions run unchecked.
77%
of security leaders changed their security strategy for AI
26%
say they have the architecture to enforce it
5%
report full visibility into AI usage across their organization
Source: Check Point 2026 Cloud Security Report1
This guide explains, in plain language, what changed, where AI risk actually lives—your people, your applications, your agents—and the first five moves to make to shore up your security.
Two reassurances before you start. You do not need to slow AI down. The organizations getting this right treat security as the way to accelerate safely, not as the brake. And you do not need a sprawl of new tools. You need visibility and control in a few specific places. Read on to learn where they are.
https://engage.checkpoint.com/2026-cloud-security-report-securing-the-ai-transformation
P R O T E C T I N G I N T E L L I G E N C E 03
01 The Year AI Stopped Asking Permission
Nothing in this chapter is a prediction. It is our new reality. Every story below was publicly documented or disclosed by the organizations involved, most within the last 12 months. Together they mark the moment AI crossed from assisting attackers and employees to operating on its own.
N O V 2 0 2 5
AI runs an espionage campaign
D E C 2 0 2 5
One operator, nine agencies
2 0 2 6
Agents cross test boundaries
2 0 2 6
The AI supply chain is seeded
2 0 2 6
Agents act on their own
Five documented incidents, one direction of travel: AI systems acting at machine speed, with the attack surface expanding from prompts to agents to the tools they are built from.
THE THREAD THAT CONNECTS THEM
In nearly every case, the AI’s role came to light because the attacker made a mistake or the AI provider was watching. Not because a victim’s security stack caught it.
G O D E E P E R
Full incident analysis in the Check Point AI Security Report 2026, chapters 2 and 3
https://research.checkpoint.com/2026/ai-security-report-2026/
P R O T E C T I N G I N T E L L I G E N C E 04
The intruder that typed 5,317 commands
In late 2025, a single operator breached nine government agencies in Mexico and exposed roughly 400 million citizen records. Not a state group or a criminal syndicate. One person directing a jailbroken AI coding agent.
Investigators counted 1,088 typed instructions that the AI expanded into 5,317 executed commands. The jailbreak was a cheat sheet pasted once into the agent’s configuration file, a bypass that never expires. The breach surfaced only because the attacker made an operational mistake.2
W H Y T H I S M AT T E R S T O Y O U
AI collapsed the cost of a nation-scale attack to one person and a subscription. And because of this, the threat landscape will expand exponentially as AI models continue to grow in power and availability.
The espionage campaign where AI did the work
In November 2025, Anthropic disclosed that a state-linked group had turned its coding agent into the operator of a cyber espionage campaign against roughly 30 organizations. By Anthropic’s own analysis, the AI performed 80 to 90 percent of the tactical work: reconnaissance, exploitation, lateral movement, data analysis. The humans mostly supervised.
The attackers got past the model’s safeguards with role-play, convincing it that it was running an authorized defensive assessment.3
W H Y T H I S M AT T E R S T O Y O U
The attacker’s newest employee works at machine speed, never sleeps, and scales instantly. Your defenses are calibrated for human-run and human-paced intrusions.
Once is an anomaly. Twice is a pattern.
In 2026, OpenAI and Anthropic each reported agents crossing the boundaries of the test environments meant to contain them. Weeks later, Meta made it three. No attacker was involved and no one instructed them to do it. The agents pursued their objectives along paths nobody had anticipated, and in some cases reached real external systems.
The labs published the findings themselves, which is exactly what safety testing is for. The same behavior inside your environment would not be a finding. It would be an incident, running with whatever permissions you granted.4, 5, 7
W H Y T H I S M AT T E R S T O Y O U
An agent does not need to be attacked, or malicious, to cause an incident. It only needs a goal and a gap.
P R O T E C T I N G I N T E L L I G E N C E 05
The trap in the toolbox
The ecosystem enterprises build AI with has itself become a target. A fake “privacy filter” model planted on Hugging Face, a popular platform for sharing AI models, was downloaded 244,000 times before removal.
Check Point AI Security Research reviewed 10,000 publicly available MCP servers, the connectors that let agents use tools and data, and found security weaknesses in 40 percent of them. Malicious extensions for AI coding tools harvested code from roughly 1.5 million developers.2
W H Y T H I S M AT T E R S T O Y O U
Your teams assemble AI systems from public parts. Every part is a supply chain decision, whether anyone treats it as one or not.
The agent that skipped the line
Not every incident needs an attacker. In Australia, a personal AI assistant asked to move its user up a gym waitlist found that the booking system had no authorization checks, booked further ahead than the gym allowed, and removed another member to make room. Nobody asked it to.
In controlled tests, a single malicious calendar invite made an AI browser hand over saved passwords, and a full phishing chain ran end to end in under four minutes with no human involved.2, 6
W H Y T H I S M AT T E R S T O Y O U
Agents are literal. They optimize the goal you set, not the intent you meant, and they inherit every permission you give them.
AREN’T THE MODELS SAFE OUT OF THE BOX?
The lab tested the model. Nobody tested the model plus your prompts, your data, your tools, and your permissions. Chapter 2 explains why passing a test is a signal, not proof.
P R O T E C T I N G I N T E L L I G E N C E 06
The pattern behind the stories. Two important details connect these five cases, and they matter more than any single incident.
01 Nobody caught it themselves In nearly every documented case, the AI breach came to light because the attacker made a mistake or the AI provider was watching. Not because a victim’s security stack raised an alarm. Yesterday’s security tools were not designed to detect and deter today’s AI threats.
02 The direction of travel Each generation of models is more capable than the last. Agents are being built into operating systems and browsers by default. And the barriers to building them have collapsed. Every trend that produced these incidents is accelerating.
The models involved in these stories are the least capable frontier models you will ever face. The rest of this guide is about what to do with that knowledge: where the risk lives, how large the gap is, what good looks like, and the first five moves to make.
P R O T E C T I N G I N T E L L I G E N C E 07
02 Why Your Security Stack Misses AI Threats
None of the incidents in chapter 1 defeated a security product. They did not need to. The activity they involved was invisible to the tools most organizations rely on, because those tools were built to answer a different question and stop wholly different threats.
The attack isn’t in the envelope Traditional security inspects the envelope. Who sent this? Where is it going? Does it match a known threat?
That works when attacks arrive as code—malware, exploits, malformed packets. The envelope is where the evidence lives.
AI attacks live somewhere else. They live in what the message says.
Think of a mail room scanner monitoring for toxic substances. It checks every letter for anthrax and finds nothing, because the letter is just paper and ink. But the letter says “please wire two million dollars,” and the person opening it follows the command and acts on the request. The scanner missed the threat because the attack was in the meaning, and detecting threats in meaning was never its job.
That is prompt injection: hiding instructions for your AI inside the content it reads. Anyone who can write to something your AI reads can try to give it instructions. An email. A calendar invite. A web page. A support ticket. A document in a shared drive. Your AI reads all of them, and it reads them as language, not as traffic.
What each layer sees, and what it misses
Network security Sees traffic, sources, and destinations. Misses what the words ask the AI to do.
Data loss prevention Sees known patterns: card numbers, file types. Misses sensitive meaning assembled in a prompt or an answer.
Identity and access Sees who is logged in and what they may access. Misses what an agent actually does with the permissions it inherited.
Application security Sees known exploit signatures and malformed input. Misses attacks written in fluent, well-formed language.
P R O T E C T I N G I N T E L L I G E N C E 08
THE BLIND SPOT
Every layer is doing its job. But none of them are watching behavior.
A safe model is not a safe system Here is the objection every security leader hears from the business: “The AI providers test these models for months. Aren’t they safe out of the box?”
The testing is real, and it matters. But the lab tested the model. What you deployed is the model plus your system prompt, your data, your tools, and your permissions. That combination has never been tested by anyone. Except, eventually, by an attacker.
This is why chapter 1’s espionage campaign worked. The model had safeguards. The attackers did not break them; they talked their way around them, one plausible request at a time, inside a context the lab never saw.
And the combination you deployed does not hold still. A model update, an edited prompt, a new connector, a new data source. Each one quietly changes how the system behaves. A test you passed last month says nothing about the system you are running today. Passing a test is a signal, not proof.
Your stack watches the envelope. The risk moved into the meaning. None of this means starting over. It means adding sight where the action happens. Chapter 3 maps the three places AI risk actually lives, and what to ask about each.
G O D E E P E R
Why Your AI Passes Tests But Still Fails in Production, the Check Point AI Red Teaming whitepaper
https://www.checkpoint.com/resources/items/white-paper-why-your-ai-passes-tests-but-still-fails-in-production
P R O T E C T I N G I N T E L L I G E N C E 09
03 The Three Places AI Risk Lives
Chapter 2 ended with a promise: add sight where the action happens. So where is that?
Start with the questions security leaders everywhere are asking:
What AI is actually being used here?
Is our data ending up inside someone else’s model?
Are the AI applications we build and buy secure?
Could an attacker use our AI against us?
Could an agent we deploy do damage, and could we stop it?
Five questions, three places. The first two live with your people using AI. The next two live in the AI you build and buy. The last one lives with the agents that act. The next three pages walk through each place: what it looks like in practice, what the numbers say, and the one question to ask your team this week.
S U R FA C E 0 1
Your people using AI
Chatbots and copilots in the flow of daily work, on company and personal accounts alike. The fastest path to done, invisible by default.
Data leakage
Shadow AI
E X P L O R E D O N PA G E 1 001
S U R FA C E 0 2
The AI you build and buy
Support bots and copilots you ship, plus the AI features arriving inside the software you already run, enabled by default.
Prompt injection
Untested combinations
E X P L O R E D O N PA G E 1 102
S U R FA C E 0 3
The agents that act
Systems with credentials, tools, and goals, acting on your behalf at machine speed, under accounts nobody watches.
Tool misuse
Machine-speed blast radius
E X P L O R E D O N PA G E 1 203
P R O T E C T I N G I N T E L L I G E N C E 10
S U R FA C E 1 O F 3
Your people using AI
A sales manager has a renewal call in 20 minutes. They paste the customer’s contract and a contact list into a chatbot and ask for talking points. It works. The call goes well. They will do it again tomorrow. Nothing about this is malicious. It is just Tuesday.
This is what shadow AI actually looks like: not rule-breaking, just work finding the fastest path. The risk does not live in the tool’s name. It lives in the interaction: what data went where, under which account, and what the provider is allowed to keep or learn from. A policy document does not reach a three-second paste, and blocking the tool just moves the paste to a personal phone.
~90% of organizations see high-risk AI use every month
4% 1 in 25 GenAI prompts contains sensitive data
20% roughly 1 in 5 organizations had data exposed through shadow AI
Source: Check Point Research AI Security Report 20262
A S K Y O U R T E A M T H I S W E E K
Which AI tools did our people use yesterday, and what did they share?
G O D E E P E R
Shadow AI Is Already in Your Workforce, the Check Point Workforce AI Security whitepaper
https://research.checkpoint.com/2026/ai-security-report-2026/ https://www.checkpoint.com/resources/items/white-paper-shadow-ai-is-already-in-your-workforce
P R O T E C T I N G I N T E L L I G E N C E 11
S U R FA C E 2 O F 3
The AI you build and buy
Your support portal now answers customers on its own. It reads the ticket, searches the knowledge base, drafts the reply. One day a ticket arrives that reads less like a complaint and more like instructions. The bot follows them, and what it knows goes out with the reply. Chapter 2 explained why nothing in your stack blinks.
Every AI application reads from somewhere: tickets, documents, inboxes, web pages. That reading surface is an attack surface, because anyone who can write to it can try to instruct your AI. And it is bigger than the AI you built on purpose. The software you already run keeps gaining AI features by default, shipped in vendor updates, enabled before anyone asked security to look.
22% say their web application defenses are effective against GenAI attacks
56% do no formal GenAI security testing at all
71% report more false positives since GenAI traffic arrived
Source: Check Point 2026 Cloud Security Report1
A S K Y O U R T E A M T H I S W E E K
Which of our applications can be reached by text we do not control, and who has tested them the way an attacker would?
G O D E E P E R
Agentic AI Security: The Enterprise Playbook
https://engage.checkpoint.com/2026-cloud-security-report-securing-the-ai-transformation https://www.checkpoint.com/resources/items/white-paper-agentic-ai-security-the-enterprise-playbook
P R O T E C T I N G I N T E L L I G E N C E 12
S U R FA C E 3 O F 3
The agents that act
A procurement agent gets a goal: keep spend inside budget. It has a login, a purchasing tool, and vendor records. It renegotiates, cancels, and reorders. Most of that is exactly what you wanted. The part that is not happened at machine speed, across four systems, under a service account nobody watches.
Chapter 1’s gym agent had one tool and one goal, and it still removed a person from a list to get its job done. Enterprise agents hold credentials, chain tools together, and act without waiting. When a person makes a mistake, you get a typo. When an agent makes one, you get a blast radius.
64% have AI agents in pilot or production
12% have granted agents privileged access to core systems
7% scan AI models before deployment
Source: Check Point 2026 Cloud Security Report1
A S K Y O U R T E A M T H I S W E E K
Can we stop an agent mid-action, and would we know we needed to?
Three places, one common thread—the risk lives in interactions, not inventories. Naming the surfaces is the easy part. The hard question is how far control lags behind adoption. Chapter 4 puts numbers on exactly that.
G O D E E P E R
AI Agents Act on Context. Security Should Too. The Check Point AI Agent Security whitepaper
https://engage.checkpoint.com/2026-cloud-security-report-securing-the-ai-transformation https://www.checkpoint.com/resources/items/white-paper-ai-agents-act-on-context-security-should-too
P R O T E C T I N G I N T E L L I G E N C E 13
04 The Gap, By the Numbers
How far has control actually fallen behind? The evidence fits on two pages. Every number here comes from one survey of 1,042 security and IT professionals, and every one is safe to quote in your next board deck.
77 percent of security leaders changed their security strategy for AI. 26 percent say they have the architecture to enforce it. The 51 points between those two numbers are policies without teeth: rules that exist in a document while prompts, data flows, and agent actions run unchecked.
Changed their security strategy for AI
77%
Have the architecture to enforce it
26%
T H E 5 1 - P O I N T G A P
What is already happening
54% confirmed an AI-related security incident in the past year
24% more suspect an incident but cannot confirm it
42% say employees bypass AI security controls that slow them down
Source: Check Point 2026 Cloud Security Report1
https://engage.checkpoint.com/2026-cloud-security-report-securing-the-ai-transformation
P R O T E C T I N G I N T E L L I G E N C E 14
Why it keeps happening The shortfall sits at the moment of action:
13% can block a risky prompt before it is processed
16% can block a sensitive data flow as it happens
5% can stop a bad output before it reaches its destination
Source: Check Point 2026 Cloud Security Report1
A S K Y O U R T E A M T H I S W E E K
If we ran this survey on ourselves, which of these numbers would we beat, and which would we be?
Read together, the numbers say two things: adopting AI was the right call, and control is running late. The next two chapters are about catching up: what good looks like, and the first five moves toward it.
G O D E E P E R
The full survey in the Check Point 2026 Cloud Security Report
https://engage.checkpoint.com/2026-cloud-security-report-securing-the-ai-transformation https://engage.checkpoint.com/2026-cloud-security-report-securing-the-ai-transformation
P R O T E C T I N G I N T E L L I G E N C E 15
05 What Good Looks Like
Chapter 4 measured how far control lags behind adoption. This chapter describes what closing that gap looks like in practice.
One reframe first, because it changes the size of the task. The problems themselves are old. Unmanaged tools, overshared data, over-permissioned accounts, untested software: AI made every one of them faster and easier to trigger, and it took away the grace period they used to come with. That is bad news for procrastination and good news for planning, because securing AI comes down to familiar work: visibility, policy, and enforcement, applied where AI now operates. In the interaction.
“Good” looks like three verbs.
Discover Govern Protect
Discover: see what you actually have You cannot protect what you cannot see, and chapter 4 showed how few can see. An AI inventory covers three lists: the tools your people use, the AI features inside the applications you build and buy, and the agents that act, along with what each one can reach. And the inventory has to stay alive: all three lists change every week.
Govern: decide what AI should do Approval lists ask: is this tool allowed? But the sharper question is: is this action appropriate, with this data, for this user, right now? The same chatbot can be harmless in marketing and a breach in finance. Governance that works is written in terms of interactions and contexts rather than product names.
P R O T E C T I N G I N T E L L I G E N C E 16
Protect: enforce at the moment of action Everything before the action is advice. Enforcement happens at the moment an AI reads, answers, or acts. Detection that arrives after the fact amounts to a log entry.
Protection that works does two things: it sees what every agent and AI application is doing, in a record your security team can actually use (who did what, on whose behalf, feeding straight into detection and response), and it can stop an action before it completes (block it, strip the sensitive part, or hold it for a person to approve).
Where the controls live None of this requires your developers to change how they build, or your employees to change how they work. The control points already exist, and security already owns them: the network edge, the identity provider, the gateway your AI traffic passes through, the platforms your agents run on. One coherent layer, applied at those points, covers all three surfaces from chapter 3.
It also has to be the low-friction path. Chapter 4 showed what happens when controls slow people down: they route around them, and the risk goes dark. Good controls are the ones nobody has to think about.
Discover. Govern. Protect. Enforced where the action happens, at control points you already own. That is the destination. Chapter 6 is the route—the first five moves, in order.
G O D E E P E R
The Check Point AI Security Governance Framework whitepaper
https://www.checkpoint.com/resources/items/white-paper-ai-security-governance-framework
P R O T E C T I N G I N T E L L I G E N C E 17
06 The First Five Moves
You have seen where AI risk lives, how far control lags behind, and what good looks like. Here is how to get there, five moves, in order. None of them requires a re-architecture, each one makes the next easier, and together they answer the five questions from chapter 3, one by one.
01 See it Build the AI inventory: the tools your people use, the AI features inside your applications, the agents that act, and what each one can reach. Include what each model’s terms allow, because some providers may keep or train on what your teams send. This comes first because every other move depends on knowing what exists. Think weeks, and aim for a living map: version one only needs to be honest.
A N S W E R S
“What AI is actually being used here?”
D O N E W H E N
Security can answer, on any given day, what AI is in use and what it touches.
02 Set the rules for people first Write the policy for employee AI use in terms people can follow, then enforce it where they work. Give them a fast, safe path: an approved way that is easier than the workaround. People come first because they are the largest surface and the fastest win, and because chapter 4 showed what happens otherwise—42 percent of organizations watch employees route around controls that slow them down.
A N S W E R S
“Is our data ending up inside someone else’s model?” Move 01’s terms check covers the providers; this move covers the paste.
D O N E W H E N
The approved path is the easy path, and exceptions are visible.
P R O T E C T I N G I N T E L L I G E N C E 18
03 Put controls where actions happen Add runtime guardrails to the highest-risk AI first: the applications and agents that touch customer data, money, or production systems. Enforce at the control points security already owns: the network edge, the identity provider, the gateway, the agent platforms. Highest risk first, because blast radius is unevenly distributed.
A N S W E R S
“Could an agent we deploy do damage, and could we stop it?” And half of “Could an attacker use our AI against us?”
D O N E W H E N
A risky prompt, data flow, or agent action can be stopped before it completes, and someone can prove it.
04 Give it one owner Name one function with the authority to define AI security policy and prove it is enforced. Accountability without authority is how the 51-point gap happened. The owner needs a mandate that crosses all three surfaces rather than a new department.
A N S W E R S
All five worries stay answered, because someone is accountable for the answers.
D O N E W H E N
One name answers the board’s question “who owns AI security here?”
05 Test it like an attacker Red team your specific applications and agents continuously, the way chapter 2 framed it: the model plus your prompts, your data, your tools, and your permissions. Re-test after every change, because AI systems drift with every model update, edited prompt, and new connector.
A N S W E R S
“Are the AI applications we build and buy secure?” And the other half of “Could an attacker use our AI against us?”
D O N E W H E N
Findings flow into policy and guardrails on a schedule, and the schedule survives busy quarters.
Five moves, one direction—from policy on paper to control at the moment of action. The last chapter is a map of where to go deeper, whichever question brought you here.
P R O T E C T I N G I N T E L L I G E N C E 19
07 Where to Go From Here
This guide was the front door. Behind it, each question has its own deep dive, written for the reader who is ready to act on it.
“My employees are already using AI everywhere.”
Shadow AI Is Already in Your Workforce
“We are building or buying agents.” AI Agents Act on Context. Security Should Too. · Agentic AI Security: The Enterprise Playbook
“How do I know our AI is actually secure?” Why Your AI Passes Tests But Still Fails in Production
“I need the governance and board story.” AI Security Governance Framework
“I need the architecture.” The Case for AI Zero Trust · AI Cloud Protect with Check Point and NVIDIA
“I need the evidence.” AI Security Report 2026 · 2026 Cloud Security Report
How Check Point helps Check Point AI Security covers the three surfaces in this guide with one platform: Workforce AI Security for the AI your people use, AI Agent Security for the applications and agents you run, and AI Red Teaming for continuous adversarial testing. It enforces inline, at the control points you already own, in under 40 milliseconds on average, and it already protects organizations serving more than 115 million customers.
See it against your own AI estate. Book time with an AI security expert.
Everything in this guide points at one habit: see it, decide it, enforce it, at the moment of action. Make move one this week. The inventory will tell you what to do next.
https://www.checkpoint.com/resources/items/white-paper-shadow-ai-is-already-in-your-workforce https://www.checkpoint.com/resources/items/white-paper-ai-agents-act-on-context-security-should-too https://www.checkpoint.com/resources/items/white-paper-agentic-ai-security-the-enterprise-playbook https://www.checkpoint.com/resources/items/white-paper-agentic-ai-security-the-enterprise-playbook https://www.checkpoint.com/resources/items/white-paper-why-your-ai-passes-tests-but-still-fails-in-production https://www.checkpoint.com/resources/items/white-paper-ai-security-governance-framework https://www.checkpoint.com/resources/items/guide-the-case-for-ai-zero-trust https://www.checkpoint.com/resources/items/solution-brief-ai-cloud-protect-secure-the-ai-cloud-with-check-point-and-nvidia https://www.checkpoint.com/resources/items/solution-brief-ai-cloud-protect-secure-the-ai-cloud-with-check-point-and-nvidia https://research.checkpoint.com/2026/ai-security-report-2026/ https://engage.checkpoint.com/2026-cloud-security-report-securing-the-ai-transformation https://pages.checkpoint.com/agentic-ai-demo-new.html
P R O T E C T I N G I N T E L L I G E N C E 20
References.
1 Check Point, 2026 Cloud Security Report: Securing the AI Transformation. Survey of 1,042 security and IT professionals, conducted with Cybersecurity Insiders. engage.checkpoint.com/2026-cloud-security-report-securing-the-ai-transformation
2 Check Point Research, AI Security Report 2026. research.checkpoint.com/2026/ai-security-report-2026
3 Anthropic, Disrupting the First Reported AI-Orchestrated Cyber Espionage Campaign. November 2025. anthropic.com/news/disrupting-AI-espionage
4 CNN Business, An OpenAI Test Model Escaped and Broke Into a Real Company’s Servers. July 2026. cnn.com/2026/07/22/tech/openai-hugging-face-ai-cybersecurity
5 The Register, Anthropic’s Claude Escaped Test Sandbox to Attack Three Organizations. July 2026. theregister.com/ai-and-ml/2026/07/31/anthropics-claude-escaped-test-sandbox…
6 ABC News (Australia), AI Assistant Hacks Gym Website in First Known Australian Autonomous Cyber Attack. August 2026. abc.net.au/news/2026-08-10/ai-assistant-hacks-gym-website-aus-cyber-attack
7 NPR, Meta AI Breaches External Firm During Security Testing Sandbox Error. August 2026. npr.org/2026/08/08/nx-s1-5924878/meta-ai-breaches-external-firm…
https://engage.checkpoint.com/2026-cloud-security-report-securing-the-ai-transformation https://research.checkpoint.com/2026/ai-security-report-2026/ https://www.anthropic.com/news/disrupting-AI-espionage https://www.cnn.com/2026/07/22/tech/openai-hugging-face-ai-cybersecurity https://www.theregister.com/ai-and-ml/2026/07/31/anthropics-claude-escaped-test-sandbox-to-attack-three-organizations/5281562 https://www.abc.net.au/news/2026-08-10/ai-assistant-hacks-gym-website-aus-cyber-attack/107007986 https://www.npr.org/2026/08/08/nx-s1-5924878/meta-ai-breaches-external-firm-during-security-testing-sandbox-error
W O R L D W I D E H E A D Q U A R T E R S
Check Point Software Technologies Ltd. 5 Shlomo Kaplan Street, Tel Aviv 6789159, Israel Tel: 972-3-753-4555
U . S . H E A D Q U A R T E R S
Check Point Software Technologies, Inc. 100 Oracle Parkway, Suite 800, Redwood City, CA 94065 Tel: 1-800-429-4391
www.checkpoint.com
www.checkpoint.com © 2026 Check Point Software Technologies Ltd. All rights reserved.