Skip to main content
Expanding our AI Security Suite, Powered by Behavioral AILearn More

Oct 6, 2026

Cybersecurity Awareness Month 2026 Is AI Security Month at Abnormal

AI is already inside your enterprise. For AI Security Month at Abnormal, learn how to govern it, secure your agents, and detect AI-driven attacks.

Alyssa Harmon

Key Insights

You can't govern AI you haven't found, so start with an inventory of every sanctioned and unsanctioned tool and agent.

Securing AI breaks into four jobs: govern adoption, secure agents and infrastructure, detect misuse and attacks, and protect identities.

Identity is the common unit: every employee, agent, and service account needs an owner, a scope, and a baseline of normal behavior.

This October, the most urgent security conversation is about the AI operating inside your business, and the identities it brings with it.

Cybersecurity Awareness Month usually asks what employees should do differently: Spot the phish, use a password manager, report the odd message. This year, security leaders have a second question to answer. What is the AI inside your organization doing, and who is accountable for it?

A recent incident involving OpenAI and Hugging Face shows why the question is pressing. AI agents identified and chained multiple weaknesses until they reached third-party production infrastructure. The weaknesses were forgotten permissions, stale keys, and over-privileged identities, the technical debt every organization carries. Together they became an attack path that AI systems can find and act on quickly, as we explained in our analysis of how Abnormal and OpenAI are detecting rogue AI in the cloud.

At Abnormal, Cybersecurity Awareness Month 2026 is AI Security Month, and we're putting AI security at the center of the conversation. Throughout the month, we'll be publishing research, perspectives, and guidance on how security teams can govern the AI their employees use, secure the agents and infrastructure behind it, detect AI-driven attacks, and protect the identities operating across all of it. Stay tuned for weekly AI security thought leadership from Abnormal.

Why the AI Security Conversation Can't Wait

OpenAI has described a "narrowing window to strengthen cyber defenses," warning that AI-enabled attacks will become far more widespread and sophisticated in the coming months. Attackers are already using AI to personalize social engineering at scale and to impersonate trusted people across text, voice, and video. 

Adoption inside the enterprise is moving just as fast. IBM's 2025 Cost of a Data Breach Report found that 13% of organizations had reported a breach of an AI model or application, and 97% of those had no AI access controls in place. Among breached organizations, 63% had no AI governance policy or were still developing one, and organizations with high levels of shadow AI paid an average of $670,000 more per breach. Gartner predicts that by 2028, the average global Fortune 500 enterprise will have more than 150,000 agents in use, up from fewer than 15 in 2025.

Our Upcoming AI Security Content

We're publishing a new set of AI security pieces every week this October. Every piece in this series lives in one place. The AI Security hub collects each new blog as it publishes, along with our latest research, announcements, and guidance, so you can follow the series week by week without hunting for it.

Check back each week, or bookmark the AI Security hub to follow along.

See the Latest in AI Security
One place for all the AI security resources you need

Four Jobs Security Teams Now Have to Do

Securing AI takes more than a single control. It breaks into four jobs, and each depends on knowing what normal looks like.

Govern AI Adoption

You can't govern AI you haven't found. The first job is discovering sanctioned and unsanctioned AI across the organization, scoring the risk each tool carries, and enforcing policy where employees actually use it. A policy that lives in a document and a policy an employee encounters at the moment of use are not the same control, and the second is the one that changes behavior. 

Secure AI Infrastructure and Agents

Many agents outlive the task they were built for and keep the credentials they were given. Securing them starts with an inventory of first- and third-party agents, a map of the identities and access each one has, and a baseline of how each normally behaves. 

The same goes for the cloud infrastructure those agents run in, where stale keys and over-privileged accounts give an agent more room than anyone intended. Developers building with AI coding tools add their own exposure.

Detect Misuse and Emerging Attacks

A rule catches what someone described in advance, and AI-driven attacks and misused tools are not described in advance. Detection has to ask whether an action makes sense for this identity at this moment. 

A finance analyst using a sanctioned AI assistant to download the full customer revenue spreadsheet at 3 am is a higher-risk event than an unsanctioned tool sitting idle. Security engineers also need to be able to query that activity data directly and turn what they find into detections they can test, because hand-built detections are often outdated by the time they ship.

Protect the Identities Operating Across the AI Ecosystem

Every AI tool, integration, and agent creates an identity that requests access, takes action, and produces data. 

That makes identity the common unit across the other three jobs: each employee, service account, OAuth app, and agent needs an owner, a scope, and a baseline of normal behavior. When an agent that has never touched the customer database suddenly starts pulling files from it, tools built for people read that as an account takeover.

This is the approach Abnormal takes: a behavioral model for each identity an organization depends on, human and non-human alike, from employees and vendors to service accounts, OAuth apps, and AI agents.

Why Behavior Is the Common Thread

All four jobs come down to the same question: is this identity acting the way it normally does? Rules and signatures can't answer it for tools and agents that change every week, but a baseline of behavior can.

That's the idea behind Abnormal's work with OpenAI. Abnormal joined OpenAI's Daybreak Cyber Partner Program as an early security partner, and the two companies plan to explore how OpenAI's frontier models and Codex Security can add to Abnormal's Behavioral AI. That includes ways to help security teams monitor agent activity and spot anomalous behavior. 

One example is already in private preview with customers. Abnormal’s AI Cloud Security uses OpenAI models to help detect, investigate, and respond to risky or malicious agent behavior. The foundation stays the same: Abnormal's core detection and response products still run on its proprietary behavioral AI, built on Attune, and the OpenAI models complement it.

What This Means for You

The four jobs above land on different desks. Here is where each role can start.

  • CISOs and security leaders: You are probably the default owner of AI risk. Start with an inventory, and look for one platform view of AI rather than a new console for every use case. Our six-step strategy for CISOs lays out the sequence.

  • SecOps and detection engineering: Agents and AI tools now generate the activity you triage. You'll need to investigate identities that aren't people and turn what you find into detections.

  • Cloud and AI and ML platform owners: The stale keys, over-privileged service accounts, and forgotten permissions in your environment are the paths an agent will find first.

  • Identity teams: Treat agents as identities. Each one inherits access to systems and data, and each needs an owner, a scope, and a baseline.

Whatever your role, the first move is to find out what AI is running and who is responsible for it. The five steps below turn that into a plan you can start this week.

Five Steps to Take for AI Security Before October Ends

These run from easiest to hardest, and none requires new tooling to begin.

  1. List every AI tool employees used in the last 30 days, sanctioned or not. Browser logs, OAuth grants, and expense reports are good places to start.

  2. Assign a named owner to every AI agent in production.

  3. Audit the credentials and permissions each agent has, and retire the ones that outlived their purpose.

  4. Write down what normal looks like for one agent: what it reads, when it runs, and how much it touches.

  5. Decide who gets paged when an agent steps outside that pattern.

Where to Follow AI Security as It Changes

We know how fast AI security is moving, and how hard it is to keep up with the attacks and the news. 

That's why we built the AI Security hub: one page with our latest announcements, research, and guidance, updated as things change. Instead of tracking it all across dozens of tabs, you can check one place for what's new.

Explore AI Security Resources

Protect Against Evolving Email Threats

See how behavioral AI detects attacks that legacy defenses miss.