The 2026 Horizon: AI, Supply Chains, Edge, and Identity
Integrate the newest evidence into operations without mistaking novelty for strategic change.
In this lesson, you will learn to:
- Produce a horizon assessment that separates observed change, extrapolation, uncertainty, and operational implication.
The 2026 Horizon: AI, Supply Chains, Edge, and Identity
This lesson updates the course through September 2026 using current frontline reporting, then converts trends into requirements, controls, exercises, and watch indicators.
Track acceleration and persistent fundamentals
Current evidence shows AI moving from occasional assistance toward scaled workflow integration. In May 2026, Google Threat Intelligence reported AI-assisted vulnerability discovery and exploitation activity and described broader operational augmentation. By September 2026, its reporting emphasized progression toward greater autonomy while still showing human-directed objectives and infrastructure. Treat these first-party findings as observations from one provider’s visibility, not a complete census.
The strategic implications are compressed discovery and decision cycles, cheaper multilingual influence, faster variation, and pressure on patch, validation, and intelligence workflows. Defenders also gain code review, triage, correlation, and simulation capacity. Require provenance, sandboxing, human release gates, evaluation against deception, protected data, and logs for consequential AI use.
Other fundamentals persist. M-Trends 2026 reported exploitation as the leading initial vector in its investigated intrusions, increased voice phishing, edge and native-function evasion, and very long dwell time for espionage and DPRK IT-worker cases. CISA’s 2025 Salt Typhoon advisory centers on routers and trusted network relationships. Identity, unmonitored infrastructure, and long-term access remain strategic terrain.
Watch supply chains and strategic technology
Cyberwarfare planning must track software supply-chain compromise because one trusted path can reach many targets. Google’s July 2026 guidance notes growth in attacks on open-source repositories after SolarWinds and 3CX. Map source, build, package, signing, distribution, identity, maintainer, dependency, and update trust. Maintain reproducible builds where practical, protected signing, dependency inventory, provenance, rapid revocation, and detection after trusted updates.
AI systems are also targets: model weights, research, data, prompts, agents, tools, and cloud capacity carry military and economic value. Google reported PRC-nexus targeting of AI research in 2026. Add AI assets to counterintelligence and supply-chain models rather than isolating them in an innovation program.
Maintain a horizon register with claim, source, observation period, confidence, potential mission impact, leading indicators, collection owner, and decision trigger. Avoid predicting that one technology “changes warfare” without a causal mechanism. Ask which constraint it relaxes, which dependency it creates, how an adversary adapts, and how evidence would show the change.
Resources
- GTIG AI Threat Tracker, May 2026 — Current first-party reporting on AI-assisted vulnerability work, exploitation, and scaled adversarial workflows.
- GTIG From Prompting to Autonomy, September 2026 — The newest researched source in the course, covering evolving adversarial AI use and targeting of AI research and infrastructure.
- M-Trends 2026 — Investigation-based 2025 metrics and observations for operational prioritization in 2026.
- 2026 Supply-Chain Compromise Guidance — Current guidance connecting SolarWinds, 3CX, and 2025–2026 open-source repository campaigns to defensive design.
- ENISA Threat Landscape 2025 — EU-focused analysis of 4,875 incidents from July 2024 through June 2025, revised in January 2026.