Check Point Research's AI Security Report 2026 documents a fundamental shift: AI has moved from a development aid to an active operator in cyberattacks. Key findings include AI-built deployment-ready malware (e.g., an 88,000-line C2 framework built in under a week), a maturing criminal AI tooling market with phishing-as-a-service kits embedding jailbroken LLMs, and voice/face/video deepfakes enabling multi-channel social engineering. Indirect prompt injection detections rose roughly fivefold between March and May 2026, approaching 1% of observed prompts. Enterprise GenAI data leakage is growing, with high-risk prompts doubling from 2% to 4% year-over-year, and Business Services recording the highest rate at nearly 6% of AI interactions carrying significant data exposure risk. Attackers now exploit agentic AI architectures via planted configuration files rather than single-prompt jailbreaks.