The next wave of business email compromise may not target people at all. According to Dark Reading, attackers are increasingly focusing on AI agents—software that can act on behalf of users—as these agents gain more authority over business systems. The report argues that AI agents are vulnerable to the same kind of manipulation that makes BEC attacks effective against human employees.

Instead of tricking a person into approving a payment or sharing credentials, attackers can craft prompts, emails, or other inputs that lead an AI agent to take harmful actions. Because agents are granted trust and access to perform tasks, a successful social engineering attempt can have direct, automated consequences.

The article suggests that organizations need to treat AI agents as potential victims of social engineering, not just as tools. That means applying security controls similar to those used for human users—such as verification steps, monitoring, and limits on what agents can do autonomously. With AI agents becoming more common in business workflows, the report frames this as a growing risk heading into 2026.