Criminals have moved AI out of testing and into daily use, Flashpoint finds

A new report from threat intelligence company Flashpoint has found that criminals now use artificial intelligence in day-to-day operations, well past the experimental stage.

The 2026 Global Threat Intelligence Report: Midyear Edition covers the first six months of the year. Flashpoint’s analysts worked through 3.9 petabytes of material for it, most of it lifted from illicit forums, encrypted channels and infrastructure tied to attackers. Criminal AI toolkits came up in more than 22 million posts.

Much of the tooling has since disappeared from public view. Criminals are running custom language models with the safety guardrails stripped out, on private infrastructure they control. The uses include target profiling, malware evasion scripts, phishing content and exploit generation. Flashpoint said that makes the activity far harder to spot from outside, leaving defenders with a visibility gap.

Josh Lefkowitz, co-founder and chief executive of Flashpoint, said AI is “compressing the time between opportunity and exploitation.” Tools that once took real expertise to build now take much less of it, he said.