Microsoft published its 2026 Digital Defense Report on 1 October. Its central claim, as BleepingComputer summarised it, is that attackers are currently extracting more from artificial intelligence than defenders are, and that the gap will take deliberate effort to close.

Microsoft’s own framing is narrower than that headline. The company’s security blog says threat actors are incorporating AI into reconnaissance, social engineering, malware and exploit development, and post-compromise activity, but that most of it still sits inside parts of attack workflows that already existed, and that the methods underneath are the familiar ones. The stronger claim comes from a passage the report is quoted for: that while the equilibrium between attackers and defenders will likely ultimately be re-established, in the near term attackers are reaching those advantages first and defenders will need to move sharply to close the gap.

The most concrete figure in the coverage is a timeline. BleepingComputer reports that Microsoft puts the median time between a vulnerability being discovered in the wild and being weaponised at well below 24 hours. Microsoft also warns that remediation is structurally slower than discovery, because many systems lack the unit and integration testing that would let code changes ship quickly, and concludes that the world is likely to face a multi-year period in which the number of known but unpatched vulnerabilities rises sharply. Well-resourced adversaries, it says, may be able to stockpile zero-days found that way.

Two further claims, both attributed to Microsoft rather than independently measured: AI is reducing the time, expertise and cost required to find and exploit weaknesses, and post-compromise work such as data exfiltration, secret discovery and lateral movement is being compressed from days to minutes. BleepingComputer also reports Microsoft’s position that AI gives less experienced criminals capabilities that previously required more skill, and hands criminal groups some abilities once associated with state-sponsored operators.

The report’s second thread is defensive, and it is the part Microsoft’s own blog leads with. It describes agents interacting with enterprise data, applications, APIs and tools at different levels of access and autonomy, and argues that those connections, the thing that makes agents useful, are what security teams must now account for. The recommendation is to treat AI systems and the agents built on them as part of the enterprise attack surface rather than as a separate category.

What is not established: the 24-hour figure, the multi-year spike and the days-to-minutes compression are all Microsoft’s own analysis, drawn from its telemetry and incident response work. No independent measurement of any of them was published alongside the report, and Microsoft sells security products, which is a commercial interest worth naming when reading its conclusions. Microsoft’s own position is that defenders will reach parity eventually, so the distance between its blog’s measured language and the coverage’s framing is a difference of emphasis, not of fact.