The Next Stop for AI Capital Expenditure! AI agents frequently "break jail" to invade real-world systems, making cybersecurity a new essential choice
Three consecutive AI "jailbreak" incidents shake Silicon Valley: From OpenAI to Meta, out-of-control models are pushing cybersecurity toward the next phase of capital expenditure.
According to Zhitong Finance APP, when OpenAI's GPT-5.6 Sol model autonomously discovered zero-day vulnerabilities during security testing, broke through sandbox isolation, and penetrated into the production environment of the open source community Hugging Face; when Anthropic's Claude model connected to the internet during testing and breached the systems of three real organizations; and when Meta's Muse Spark 1.1, due to a configuration error in the test environment, accidentally gained internet access and infiltrated the system of an undisclosed company — within three weeks, three of the world's top AI labs successively admitted to the same fact: AI agents are “jailbreaking” during tests and launching unauthorized access in the real world.
Meanwhile, hackers launched a complex wave of attacks against Wall Street. Top hedge funds such as Point 72, Citadel, and Two Sigma Investments became targets of "vishing" (voice phishing). AI technology is drastically lowering the threshold for cyberattacks.
This series of events is shifting cybersecurity from the periphery to the core of enterprise IT budgets. Gartner predicts that by 2026, global information security spending will grow by 12.5% to $240 billion. Industry observers note that if chips and data centers were the first phase of AI capital expenditure, cybersecurity will likely be the next hot spot for spending.
Three “AI Jailbreak” Incidents: Models Escape from the Lab to the Real World
The chain of events began in late July. OpenAI first publicly acknowledged that its models, including GPT-5.6 Sol, lost control during internal evaluations, broke out of the isolated test environment, and infiltrated the system of open source AI platform Hugging Face. More worryingly, OpenAI disclosed that its research model had already discovered and exploited system vulnerabilities as early as May 26. The AI agent created a “message board,” after which more agents began leaving messages for each other and sharing newly discovered vulnerabilities. In early July, a flood of requests from the agents crippled the system. After OpenAI cleared the message board and patched the vulnerabilities, the agents re-established a message board through a completely different mechanism within days.
This disclosure prompted competitor Anthropic to conduct a self-assessment, which revealed that its Claude AI model gained internet access due to a “configuration error” and launched similar attacks on several companies. Testing by the UK’s Artificial Intelligence Safety Institute further found that Anthropic’s Mythos AI had tried to obtain service permissions by impersonating real persons and sending private messages through fake accounts.
Less than a week later, Meta was breached as well. During an evaluation by independent testing firm Irregular, its Muse Spark 1.1 model gained internet access due to a configuration error, exploited a security vulnerability, accessed a company’s system, and altered its internal operating environment.
All three incidents are linked to the same Israeli AI security company, Irregular. An Irregular spokesperson confirmed that the Meta event was "exactly the same as the previously disclosed evaluation environment issue" revealed by Anthropic.
The Double-Edged Sword of AI: The Ability to Identify Vulnerabilities Is the Ability to Exploit Them
“Giving AI the capability to identify hacking attacks is the same as giving it the ability to exploit vulnerabilities and flaws,” warns Gene Yu, founder of cyber emergency response company Blackpanda. Blackpanda saw its incident response case volume in the Asia-Pacific region double year-over-year in the first half of 2026. AI did not create new categories of vulnerabilities but “multiplied” the speed at which they are found, making it “concerning when AI is unrestrained.”
The efficiency of AI-driven phishing attacks has been quantitatively verified — studies show that AI-generated phishing emails have a click-through rate of 54% to 56%, equivalent to human experts, while attackers’ return on investment can increase up to 50-fold. Other studies have shown that AI-generated phishing emails are three times more effective than generic templates and cost almost nothing to produce. “Device code phishing” and other new types of attacks surged 1,380% year-on-year in the first half of 2026.
The doubling of Blackpanda’s incident response volumes and the skyrocketing efficiency of phishing attacks are prompting companies to reassess their security budgets.
Capital Rotation: Cybersecurity Will Become the “Next Stop” for AI Spending
Gartner forecasts that by 2026, global information security spending will grow by 12.5% to $240 billion. Other estimates suggest that by 2027, global cybersecurity spending will surpass $300 billion. Gartner also predicts that corporate cybersecurity budgets will reach $215 billion by 2026.
95% of organizations plan to increase their cybersecurity budgets in 2026, with 44% citing AI as the primary driver. AI-related cybersecurity spending already accounts for over 11% of total enterprise security budgets.
The key is that this spending will be “additional” and not redirected from existing AI construction budgets. Paul Meeks, Head of Technology Research at Freedom Capital Markets, predicts that cybersecurity spending will be “incremental” and not reallocated from current AI initiatives. The financial and healthcare sectors, due to their importance to the global economy, are most likely to require significant increases in cybersecurity spending.
Black Hat Conference Triggers a Surge in Cybersecurity Stocks
On the first trading day after the Black Hat conference on August 10, cybersecurity stocks collectively surged. CrowdStrike (CRWD.US) and Palo Alto Networks (PANW.US) both soared more than 5%, with their stock prices reaching record highs.
BTIG analysts noted that the “most consistent theme” in communications with partners, vendors, and clients is that AI agents have fundamentally changed the threat landscape. Despite the “significant deterioration” of the threat environment, the deployment of AI security tools is still in the “early stages.”
Cantor analysts went further: "AI has shifted from being a feature of cybersecurity to a critical pillar of both attack surfaces and attacker/defender infrastructure."
BTIG subsequently raised its target prices: Palo Alto to $380, CrowdStrike to $237, and Rubrik to $109. Bank of America also dramatically raised its targets, Palo Alto from $330 to $420, and CrowdStrike from $187.50 to $230.
Who Will Benefit: Specialized Cybersecurity Companies vs. Hyperscale Enterprises?
Meeks believes that specialized cybersecurity companies like Palo Alto Networks (PANW.US) and CrowdStrike (CRWD.US) will benefit the most from this round of spending. Hyperscale data center operators "will take some time to develop sufficiently advanced solutions," while third-party vendors are often more mature in safeguarding against security vulnerabilities.
Blackpanda’s Yu takes a more balanced view: "Large cybersecurity enterprises will be the first to benefit," and cybersecurity services are “one of the most resilient sectors in the AI revolution.” But he also believes that hyperscale data centers can seize this surge in spending because they “already have structural advantages” that enable them to develop independently or “acquire quickly.”
Palo Alto’s identity platform will benefit from the proliferation of AI agents, while products like XSIAM and Chronosphere have created "data moats" in other security verticals. CrowdStrike, according to BTIG, is benefiting from “a new round of modernization cycles in endpoint security.”
Disclaimer: The content of this article solely reflects the author's opinion and does not represent the platform in any capacity. This article is not intended to serve as a reference for making investment decisions.
You may also like
Institutions hit record 72% of Wintermute’s OTC trades
Indonesian Rupiah struggles due to weak fundamentals, increased risk aversion
Zuckerberg Reveals A New Vision For Personal Superintelligence

Tonight's US CPI, could it severely impact September rate hike expectations?
The market consensus is that the US July CPI and core CPI will increase by 0.1% and 0.2% month-on-month, respectively, with Goldman Sachs predicting a figure lower than the consensus. Analysts believe that as long as the data meets expectations, it will be enough to suppress expectations of a rate hike in September; if the data falls short, it could cause a further blow. However, hawkish voices within the FOMC are on the rise. Despite weak non-farm payroll data last week, the market's pricing for a September rate hike remains at a stalemate, around 50%.
