Gartner, Inc., a business and technology research and advisory organisation, has ranked AI-enabled discovery of cyber vulnerabilities as the leading emerging risk for organisations worldwide in the second quarter of 2026.
The finding is included in Gartner’s latest Quarterly Emerging Risk Report, where the company surveyed 316 senior executives and risk managers across multiple industries and regions during April and May 2026 for the report.
“The ability of AI to increase the efficiency and accessibility of vulnerability discovery is making it increasingly difficult for traditional risk management approaches to keep pace,” commented Kevin Mercado, Senior Principal Analyst, Research, in the Gartner Risk & Audit Practice.
“Without corresponding improvements in governance, security operations, and remediation capabilities, AI-driven vulnerability discovery may outpace organisational defences, increasing the likelihood of significant cyber incidents and operational disruption.”
Gartner said the development reflects the growing ability of AI technologies to identify security weaknesses at greater speed and scale. While organisations may have confidence in their existing defences, the pace of AI development could shorten the time between a vulnerability being identified and it being exploited.
This could place additional pressure on security and risk teams to improve how quickly they identify, assess and address emerging threats. Gartner noted that organisations may need to reconsider established assumptions around cyber risk as AI-assisted vulnerability discovery becomes more accessible.
The company recommends reassessing the potential impact of cyber risks to reflect increased exposure, reviewing risk appetite to take account of the continuing discovery of vulnerabilities, strengthening controls around third-party suppliers and speeding up cyber response processes. Gartner also points to faster patching and greater use of automated remediation as ways organisations could improve their ability to respond to AI-enabled threats.
Gartner’s report identifies other areas of concern beyond AI-assisted cyber vulnerability discovery. These include the increased use of agentic AI, where autonomous systems can perform tasks with limited direct organisational oversight, as well as risks to information integrity associated with unreliable data and AI-generated material.
Workforce readiness is another area highlighted by Gartner, with organisations continuing to face shortages in skills and preparedness relating to AI technologies. The company also identifies geopolitical shocks as a continuing risk to global energy supply chains.
Gartner said organisations should therefore consider strengthening their AI governance arrangements, addressing skills gaps through workforce planning and adapting wider risk management processes as AI capabilities and associated risks develop.
“AI’s growing capabilities are creating new and complex challenges for cybersecurity, operational resilience and organisational trust,” added Mercado. “To anticipate and counter the risks associated with each, leaders must recognize the impact potential and be prepared for better response.”





