1. [para. 1][para. 2][para. 3] At the Asia New Vision Forum 2026 in Singapore, cybersecurity industry leaders warned that AI is rapidly escalating threats by empowering autonomous hacking agents and expanding risks into physical technologies like robots and smart cars. They stressed that rapid AI adoption is outpacing corporate defense capabilities, shifting the security landscape from simple data breaches to systemic supply chain vulnerabilities and potential physical harm.
2. [para. 5][para. 6][para. 7] Gaurav Keerthi, CEO of StrongKeep Cybersecurity, said autonomous AI agents have emerged as a fourth category of cyber attackers, joining state-sponsored hackers, criminal groups, and ideologically driven attackers; these agents operate without human motives and solely execute programmed objectives. AI also boosts hacker productivity by enabling malicious code creation and more deceptive phishing emails, allowing attackers to target small and midsize enterprises at lower cost. Keerthi further warned of internal corporate risks from generative AI and ambient programming, where employees lacking technical and security expertise develop software that may inadvertently create viruses, bypass security protocols, or leak corporate data to uncontrolled external environments.
3. [para. 9][para. 10][para. 11][para. 12] Gene Yu, CEO of Blackpanda, reported a more than 100% year-on-year increase in security incident responses this year, though most breaches still stem from inadequate basic security measures. Small businesses and supply chain service providers are increasingly the weak points for larger institutions; attackers may bypass a big bank’s defenses by targeting smaller law firms, accounting firms, or marketing vendors that hold client data, with companies under 200 employees representing about 98% of global enterprises yet lacking adequate protection. Yu noted that management’s biggest mistake during a cyberattack is abandoning established contingency plans for emotional decisions—rushing to wipe systems or recover backups without thorough investigation can destroy evidence and worsen risks. Keerthi added that attackers currently hold a short-term advantage because they can rapidly test new technologies without regulatory constraints, while companies typically spend months on due diligence, procurement, and integration before deploying defenses.
4. [para. 14][para. 15][para. 16][para. 17][para. 18] On governance and prevention, Keerthi said cybersecurity should be treated as a public product, requiring improved foundational protection across all enterprises. He argued against fragmenting global technology infrastructure, explaining that shared infrastructure discourages attacks because all parties depend on it, whereas dividing the world into distinct systems alters incentives and increases conflict likelihood. Yu suggested that as AI, drones, and physical robots develop, a new balance similar to the Cold War concept of mutually assured destruction could emerge, with the high costs of large-scale drone warfare acting as a technological deterrent. Keerthi advised companies to assume not all attacks can be blocked and instead focus on resilience, noting that stock prices of listed companies hit by cyberattacks typically recover in about 40 days and can even exceed pre-attack levels if the crisis is managed well. Companies must regularly test backup systems rather than only documenting disaster recovery plans—if a backup is supposed to activate in 30 seconds, it should be tested immediately.
5. [para. 20][para. 21][para. 22] Regarding future technologies, Yu warned that integrating physical AI products such as humanoid robots and autonomous vehicles into public spaces means cyberattacks could escalate from data loss to physical injury; a hacked household robot could bring risk into a family’s most private living space. Keerthi called for clearer technological liability frameworks, noting that if a Windows computer crashes during surgery and causes a patient’s death without Microsoft facing liability, the tech sector remains largely excluded from accountability systems. Tech companies cannot simply blame AI-driven accidents on rogue agents, as their systems are equally capable of committing criminal acts; if an autonomous vehicle speeds or blocks an ambulance, laws must clearly define penalties and whether the operating company could lose its license, which would fundamentally change how products are designed.
AI generated, for reference only