Por Jim Glade
August 26, 2026
Artificial intelligence is making companies more productive, but it is also changing the nature of the threats they face. An employee might enter confidential information into an AI tool without realizing the consequences, while an attacker could use those same systems to create phishing campaigns, identity theft schemes, or fake content that is harder to detect.
The cost of making a mistake is no small matter either. According to IBM's Cost of a Data Breach 2026 report, a single data breach costs organizations in Latin America an average of $4.65 million. The study also found that nearly 19% of the malicious attacks analyzed were enabled by artificial intelligence.
This scenario is placing new pressure on security teams while simultaneously creating opportunities for startups that develop tools to detect vulnerabilities, protect data, and control corporate use of AI.
According to Fabio Brodbeck, co-founder and CGO of OSTEC, a Brazilian cybersecurity firm, one of the least visible threats is occurring within companies themselves.

"People lack the training to use AI correctly," explained Brodbeck in an interview with Contxto during the Startup Summit 2026 in Florianópolis.
The problem arises when employees use public models for everyday tasks. An employee might upload a Word document, an Excel spreadsheet, or internal information to request a summary or identify conclusions without realizing they're sharing corporate data with an external tool.
"They often upload company information—things that are confidential or critical to the company," he noted.
The other side of the problem lies with those who deliberately use AI to launch attacks. Brodbeck cites phishing as an example: fraudulent emails that used to be easily spotted due to spelling errors or unprofessional designs are becoming increasingly convincing.
"Today, even with ChatGPT, if you ask it to write perfect HTML—like an email from a bank to be sent to employees at Company X—it will generate a flawless document that can be sent, and people will believe it's real," he says.
The threat also extends to phone calls and audiovisual communications. According to Brodbeck, voice cloning and other AI-generated content are adding new tools to social engineering attacks.
The emergence of these threats is occurring as the cybersecurity market is once again attracting capital. According to Crunchbase, cybersecurity startups raised US$11.6 billion in venture capital in 2025, an increase compared to 2024. Artificial intelligence was also one of the main drivers of new investments, both for companies that use AI to defend systems and for those focused on protecting the AI models and agents themselves.
In Latin America, the market is still small compared to the United States, but activity is beginning to diversify. Uruguay's Strike, for example, raised US$13.5 million in a Series A round in 2025 to expand its penetration testing platform. Argentina's Whalemate secured $1 million to develop training tools against phishing and other threats.
Brazil is also producing companies focused on corporate risk. Tenchi Security raised US$35 million in 2024 to develop third-party cyber risk management tools—an issue that has gained prominence as companies rely on increasingly extensive chains of technology providers.
The market is thus responding to a shift in the perception of risk: after a data breach, the cost isn't limited to restoring systems or replacing infrastructure. It can also affect relationships with customers, suppliers, and business partners.
"The costs of an attack, the costs of a data breach, are irreparable. Because they aren't necessarily the direct costs of the incident—it's the indirect costs that are the worst: it's the company's reputation, it's the damage done to customers, and it's the damage done to the market," said Brodbeck.
The solution, however, isn't just about buying new tools. For Brodbeck, companies need to work on three fronts: culture, processes, and technology.
"That's what every company needs—it's not an option; it's a must," he said.
Employee education takes on special importance as companies adopt AI tools without necessarily having clear policies on what information can be shared with them.
The shift is also affecting budgets. 64% of Latin American organizations surveyed by IBM stated that they plan to increase their investment in security after suffering a data breach, with areas such as AI security and governance among their priorities.
For industry leaders, this opens up an opportunity that goes beyond traditional security. Companies now need to know what information a model can use, what permissions an AI agent has, what systems it can access, and how to detect when a seemingly legitimate interaction is part of an attack.
Brodbeck summarizes the shift from a business perspective: cybersecurity should no longer come into play after an incident, but before.
"Investing in security is a must for companies so they don't have to incur other costs," he affirmed.
As AI adoption continues to accelerate in Latin America, this tension between productivity and risk will likely become one of the new markets for tech entrepreneurs in the region.