Russia's largest bank has unveiled an innovative development—a system of multimodal AI agents designed to automatically detect phishing resources. The announcement was made at the Offzone 2026 conference, where company representatives revealed details of the new approach to combating cyber threats.
How the new system works
The developed technology analyzes a website across several key parameters simultaneously: textual content, program code, infrastructure, and visual design. The collected data undergoes multi-stage verification, where some agents build arguments in favor of a threat, others against it, and a separate module makes the final decision based on the entire body of evidence.
The scale of the problem explains such an emphasis on automation. By my estimates, more than 11,000 phishing sites appear worldwide every day, and many of them exist for only a few hours. The spread of generative AI only accelerates the creation of new pages, making manual verification increasingly ineffective.
At the current stage, the solution is undergoing final training and functions as a specialist's assistant: it conducts initial analysis, sets priorities, and prepares a report for blocking. The final decision remains with the employee. However, the plans include a transition to fully automatic blocking of identified resources.
Integration and prospects
The technology is also planned to be integrated into the X Threat Intelligence platform, to which more than 760 Russian organizations are already connected. This will expand automated searches for sites imitating company resources and their brands, which is critical amid the growing number of cyberattacks.
This initiative by Sber fits into a broader trend: the bank had previously introduced "GigaAgent"—a universal assistant capable of independently planning tasks, rewriting its own code, and maintaining context between sessions. Other operators are taking similar steps—MTS has updated the AI models of its "Zashchitnik" service, where three neural networks evaluate more than 1,100 parameters of each call, reducing the response time to a fraudulent call from 30 to 15 seconds.
The role of autonomous programs on the internet is growing rapidly. Elon Musk supported Cloudflare's forecast that within five years, non-human traffic could exceed user traffic by 1,000 times, and it could surpass human traffic as early as May 2026.
However, agent autonomy hits technical limitations. A researcher under the pseudonym codila explained why a single agent "suffers from amnesia" and proposed a graph architecture where agents share common memory and verify each other's work.
The expansion of such systems also opens up new vulnerabilities. American researchers demonstrated the Ghostcommit attack: a malicious command is hidden inside an image, the verifying agent does not open it, while another assistant reads the instruction and transfers passwords into open code.
My view: Sber is taking an important step in the right direction, but the arms race between AI defense and AI attacks is just beginning. The key success factor will be not just automation, but the creation of resilient multi-agent systems with shared memory—it is precisely such architectures that can counter new threat vectors, including attacks like Ghostcommit, which already bypass traditional verification mechanisms.