Russia's largest bank is betting on artificial intelligence in the fight against digital fraud. At the Offzone 2026 conference, Sber's team presented an ambitious development—a system of multimodal AI agents designed to automatically detect phishing resources. This is not just another antivirus plugin, but a full-fledged intelligent ecosystem that changes the rules of the game in cybersecurity.
How the "hunt" for fakes works
At the core of the technology lies a comprehensive analysis of a web resource across multiple vectors simultaneously: text, program code, infrastructure, and visual design. The collected data passes through a multi-stage verification system. The architecture resembles an adversarial process: some agents generate arguments in favor of the site being a threat, while others refute them. A separate module makes the final decision, weighing the entire body of evidence.
The scale of the problem explains such interest in automation. Based on industry statistics, my estimates suggest that more than 11,000 phishing domains are registered worldwide every day, with a significant portion living only a few hours. The proliferation of generative AI has made creating fake pages cheaper and faster to the extreme, making manual moderation a losing strategy by definition.
At this stage, the system is undergoing final training and operates in specialist assistant mode. It conducts initial analysis, sets priorities, and prepares a report for blocking, while the final decision remains with a human. However, Sber has already announced a transition to fully automatic blocking of detected resources.
Integration and evolution of AI security
A key step is integrating the development into the X Threat Intelligence platform, to which more than 760 Russian organizations are already connected. This will extend automated searches for sites imitating company brands to the platform's entire client base, creating a distributed protection network.
Sber's actions fit into the broader trend toward autonomy. Recently, the bank introduced "GigaAgent"—a universal assistant capable of independently planning tasks and rewriting its own code. Similar processes are underway at other operators: for example, MTS modernized its "Zashchitnik" AI models, reducing response time to fraudulent calls from 30 to 15 seconds by analyzing more than 1,100 parameters.
Predictions about the total dominance of non-human traffic no longer seem like science fiction. Discussions at the level of leading experts, including Elon Musk, indicate that by May 2026, traffic from AI agents could exceed user traffic, and within five years—surpass it by 1,000 times.
However, autonomy also brings new risks. Researchers have already demonstrated attacks like Ghostcommit, where malicious commands are hidden inside images, deceiving verification agents. This creates an arms race: security systems must become more complex, but each new complexity opens new attack vectors.
My view: Sber's initiative is a timely and technically mature response to the avalanche-like growth of phishing. However, the key challenge lies not in detection, but in response speed and the resilience of the AI systems themselves to adversarial attacks. Success will depend on the architecture's ability to self-learn and share "memory" between agents, as some researchers propose. The bank that solves this problem first will gain not just a protective perimeter, but a strategic advantage in the digital economy.