The International AI Safety Report 2026, published by the UK's AI Security Institute and supported by more than 30 nations and international organizations, delivers an unequivocal assessment: general-purpose AI systems are already causing real-world harm, and advances in AI capabilities may pose further risks that have not yet materialized.
AI-Assisted Cyberattacks: From Research to Operations
The report's cybersecurity findings are particularly stark. It documents that criminal groups and state-sponsored attackers are actively using general-purpose AI systems across multiple stages of the cyberattack chain, from reconnaissance and vulnerability discovery to attack development and execution. Pre-packaged AI tools and AI-generated ransomware are now available in underground marketplaces, lowering the barrier for entry-level threat actors.
The evidence is strongest for AI-assisted vulnerability discovery: researchers found that AI systems now provide meaningful assistance in finding software vulnerabilities — weaknesses that can be exploited to compromise computer systems. This finding aligns with the broader trend of AI being used not to create fundamentally new attack vectors but to dramatically accelerate and scale existing ones.
Deepfakes, Biological Risks, and Malfunctions
Beyond cybersecurity, the report identifies increasing concerns around AI-enabled deepfakes for fraud and political manipulation, the potential misuse of AI in biological and chemical weapons development, and risks from AI malfunctions including hallucinations, flawed code generation, and misleading medical advice. The authors note that researching AI's impact on biological and chemical risks is itself challenging, as studies could inadvertently violate national security laws or treaties like the Biological Weapons Convention.
A Multinational Call for Action
This second edition of the International AI Safety Report represents the most authoritative multinational assessment of AI risks to date. Its conclusions reinforce that AI security is not a future concern — general-purpose AI systems are actively being exploited in ways that cause tangible harm to individuals and organizations. The report calls for coordinated international action on AI governance, security testing standards, and transparency requirements for AI system capabilities and limitations.
For CISOs and security teams, the report validates the need to integrate AI-specific threat models into existing security frameworks, establish AI security testing as part of procurement and deployment processes, and monitor underground marketplaces for pre-packaged AI attack tools targeting their industries.