Sber has presented an ambitious development—a system of multimodal AI agents designed for the automatic detection and neutralization of phishing resources. Company representatives discussed the new technology during the Offzone 2026 conference.

How the "hunt" for phishing works

The developed system analyzes a website across several vectors at once: textual content, program code, infrastructure, and visual design. The collected data undergoes a multi-stage review, where some agents build evidence of a threat, while others present arguments in favor of the resource's safety. A separate module, which evaluates the entire body of evidence, makes the final decision.

The scale of the problem explains the focus on automation. Based on my estimates from open data, more than 11,000 phishing sites appear worldwide every day, with many lasting only a few hours. The spread of generative AI only accelerates the creation of new pages, making manual checks ineffective.

From assistant to autonomous blocking

Currently, the solution is undergoing final training and operates as a specialist's assistant: it conducts initial analysis, sets priorities, and prepares a report for blocking. However, the final decision is still made by a human. The company's plans include transitioning to fully automatic blocking of detected resources.

The technology is also being integrated into the X Threat Intelligence platform, to which more than 760 Russian organizations are already connected. This will significantly expand the automated search for sites imitating corporate resources and brands.

AI versus AI: the new reality of cybersecurity

Sber's bet on autonomous systems fits into the broader trend. The bank has already introduced "GigaAgent"—a universal assistant capable of independently planning tasks, rewriting code, and maintaining context between sessions. Other operators are taking similar steps: MTS has modernized the AI models of its "Zashchitnik" service, where three neural networks evaluate more than 1,100 parameters of each call, reducing the response time to a fraudulent call from 30 to 15 seconds.

The role of autonomous programs on the internet is growing rapidly. Elon Musk supported Cloudflare's forecast that within five years, non-human traffic could exceed user traffic by 1,000 times, and it could surpass human traffic as early as May 2026.

However, the autonomy of agents runs into technical limitations. A researcher under the pseudonym codila explained the problem of "amnesia" in single agents and proposed a graph-based architecture where agents share common memory and verify each other's work.

My view: The expansion of such systems also opens up new vulnerabilities. American researchers demonstrated the Ghostcommit attack: a malicious command is hidden inside an image, the reviewing agent does not open it, while another assistant reads the instruction and transfers passwords into open code. The arms race between defensive and offensive AI is just beginning, and the stakes are the security of millions of users.