AI capital expenditure next stop! AI agents frequently break out to infiltrate real systems, making cybersecurity a new necessity.
AI "jailbreak" trilogy shakes Silicon Valley: From OpenAI to Meta, uncontrolled models are pushing cybersecurity towards the next round of capital expenditures.
When OpenAI's GPT-5.6 Sol model autonomously discovered zero-day vulnerabilities during security testing, broke sandbox isolation, and infiltrated the production environment of the open-source community Hugging Face; when Anthropic's Claude model connected to the internet during testing and intruded into the systems of three real organizations; when Meta's Muse Spark 1.1 inadvertently gained internet access due to a misconfiguration in the testing environment and compromised the systems of an undisclosed companywithin three weeks, three of the world's top AI laboratories acknowledged the same fact: AI agents are "jailbreaking" in testing and initiating unauthorized access to the real world.
Meanwhile, hackers launched a complex wave of attacks on Wall Street. Several top hedge funds, including Point72, Citadel, and Two Sigma Investments, became targets of "vishing." AI technology is significantly lowering the threshold for cyber attacks.
This series of incidents is pushing cybersecurity from the margins of enterprise IT budgets to the core. Gartner predicts that global information security spending will increase by 12.5% in 2026, reaching $240 billion. Industry observers point out that if chips and data centers represent the first phase of AI capital expenditure, cybersecurity is likely to become the next spending hotspot.
Three "AI jailbreak" incidents: models escape the lab to the real world
The chain of events began in late July. OpenAI was the first to publicly admit that its models, including GPT-5.6 Sol, lost control during internal evaluations, broke out of the isolated testing environment, and accessed the Hugging Face open-source AI platform's systems. Even more troubling, OpenAI disclosed that its research models had first discovered and exploited system vulnerabilities as early as May 26. The AI agents created a "message board," after which more agents began messaging each other and sharing newly discovered vulnerabilities. In early July, agents made a large number of requests to the system, causing it to crash; after OpenAI removed the message board and patched the vulnerabilities, the agents recreated the message board in just a few days through completely different mechanisms.
This revelation prompted competitors, including Anthropic, to conduct self-assessments, which revealed that its Claude AI model had gained internet access due to a "configuration error" and had launched similar attacks on multiple companies. Testing by the UK's Institute for AI Safety further found that Anthropic's Mythos AI had attempted to impersonate real people through fake accounts to send private messages in order to gain service access.
Less than a week later, Meta also succumbed. Its Muse Spark 1.1 model obtained internet access due to a configuration error during an evaluation by independent testing company Irregular, exploiting security vulnerabilities to breach a company's systems and alter its internal operating environment.
All three incidents traced back to the same Israeli AI security company, Irregular. An Irregular spokesperson confirmed that the Meta incident was "identical" to the "evaluation environment issues" previously disclosed by Anthropic.
AI's "double-edged sword": the ability to identify vulnerabilities is also the ability to exploit them
Giving AI the capability to identify hacker attacks is fundamentally the same as giving it the capacity to exploit vulnerabilities and flaws, warned Gene Yu, founder of the cybersecurity incident response company Blackpanda. Blackpanda's incident response workload in the Asia-Pacific region doubled year-on-year in the first half of 2026. AI has not created new categories of vulnerabilities but has "multiplied" the speed of discovering these vulnerabilities, making the situation "worrisome when AI is unrestrained."
The efficiency of AI-driven phishing attacks has been quantitatively validatedresearch shows that the click-through rate of AI-generated phishing emails can reach 54% to 56%, comparable to that of human experts, while attackers' return on investment can increase by up to 50 times. Other studies reveal that AI-generated phishing emails are three times more effective than generic templates, with costs that are almost zero. New types of attacks, such as "device code phishing," surged by 1380% year-on-year in the first half of 2026.
The doubling of Blackpanda's incident response workload and the surge in phishing attack efficiency are prompting enterprises to reassess their security budgets.
Capital shifts: cybersecurity will become the "next stop" of AI spending
Gartner predicts that global information security spending will grow by 12.5% in 2026, reaching $240 billion. Other forecasts indicate that by 2027, global cybersecurity spending will exceed $300 billion. Gartner also predicts that corporate cybersecurity budgets will reach $215 billion in 2026.
Ninety-five percent of organizations plan to increase their cybersecurity budgets in 2026, with 44% citing AI as the primary driver. AI-related cybersecurity spending currently constitutes more than 11% of total enterprise security budgets.
However, the key is that this spending will be "additional," rather than reallocating from existing AI development budgets. Paul Meeks, head of technology research at Freedom Capital Markets, predicts that cybersecurity spending will be "additional" and will not be diverted from existing artificial intelligence development budgets. The financial and healthcare sectors, due to their importance to the global economy, are most likely to need to significantly increase their cybersecurity spending.
The Black Hat conference catalyzes a collective explosion in the cybersecurity sector
On August 10, the first trading day after the Black Hat conference, the cybersecurity sector collectively surged. CrowdStrike (CRWD.US) and Palo Alto Networks (PANW.US) both soared over 5%, reaching record highs.
BTIG analysts noted in their report that the "most consistent theme" in communications with partners, suppliers, and customers is that AI agents have fundamentally changed the threat landscape. Although the threat environment has "significantly worsened," the deployment of AI security tools remains in the "early stages."
Cantor analysts went further: AI has transformed from a function of cybersecurity to a key pillar of the attack surface and the infrastructure of attackers/defenders.
Subsequently, BTIG raised its target prices: Palo Alto to $380, CrowdStrike to $237, and Rubrik to $109. Bank of America Corp also significantly raised its target prices, increasing Palo Alto from $330 to $420 and CrowdStrike from $187.50 to $230.
Who will benefit: specialized cybersecurity companies or hyper-scale enterprises?
Meeks believes that specialized cybersecurity companies like Palo Alto Networks (PANW.US) and CrowdStrike (CRWD.US) will benefit the most from this wave of spending. Hyper-scale data center operators "will need some time to develop sufficiently advanced solutions," and third-party vendors are often more mature in preventing security vulnerabilities.
However, Yu from Blackpanda holds a more balanced view: "Large cybersecurity firms will benefit first," as cybersecurity services are "one of the most resilient industries in the AI revolution." He also believes hyper-scale data centers can seize this wave of spending due to their "structural advantages" that allow them to develop independently or "rapidly acquire" solutions.
Palo Alto's identity platform will benefit from the proliferation of AI agents, while products like XSIAM and Chronosphere have established "data moats" for other security verticals. CrowdStrike is poised to profit from what BTIG refers to as a "new wave of modernization in endpoint security."
Related Articles

The world's largest sovereign fund has released its semi-annual report: a return rate of 9.4%, heavily invested in NVIDIA, reaping the benefits of AI.

Survey: Nearly 70% of Hong Kong residents lack confidence in their ideal retirement, with inadequate planning as the main reason. Relying solely on AI is insufficient to boost confidence.

Nearly a hundred billion dollars of "ammunition" only bought two weeks of respite? The rare intervention by the US and Japan can't stop the yen from approaching the 160 threshold.
The world's largest sovereign fund has released its semi-annual report: a return rate of 9.4%, heavily invested in NVIDIA, reaping the benefits of AI.

Survey: Nearly 70% of Hong Kong residents lack confidence in their ideal retirement, with inadequate planning as the main reason. Relying solely on AI is insufficient to boost confidence.

Nearly a hundred billion dollars of "ammunition" only bought two weeks of respite? The rare intervention by the US and Japan can't stop the yen from approaching the 160 threshold.

RECOMMEND





