Russia's largest bank is betting on multimodal AI agents to combat phishing. The development, presented at the Offzone 2026 conference, promises to turn manual verification of suspicious resources into a fully automated process.

How the new system works

The technology analyzes a website across multiple vectors at once: textual content, program code, infrastructure, and visual design. The collected data undergoes multi-stage verification, where some agents build evidence of a threat, others provide counterarguments, and a separate module makes the final decision based on the aggregate of evidence.

The scale of the problem explains this approach. By my estimates, more than 11,000 phishing pages appear worldwide every day, with many living only a few hours. With the spread of generative AI, the creation of new sites has accelerated manifold, making manual moderation a losing strategy by definition.

Currently, the system operates in assistant mode: it conducts initial analysis, sets priorities, and prepares a report for blocking, but the final word remains with a specialist. Plans include transitioning to fully autonomous blocking of detected resources.

Integration and ecosystem context

The development is intended to be integrated into the X Threat Intelligence platform, to which more than 760 Russian organizations are already connected. This will expand automated search for sites imitating corporate resources and brands.

The bet on autonomous systems fits into the company's overall direction. Earlier, the bank introduced "GigaAgent" — a universal assistant capable of independently planning tasks, rewriting its own code, and maintaining context between sessions. Other operators are taking similar steps: for example, MTS updated the AI models of its "Zashchitnik" service, where three neural networks evaluate more than 1,100 parameters of each call, reducing the response time to a fraudulent call from 30 to 15 seconds.

Arms race in the AI sphere

The role of autonomous programs on the internet is growing rapidly. Elon Musk supported Cloudflare's forecast that within five years, non-human traffic could exceed user traffic by 1,000 times, and surpass human traffic as early as May 2026.

However, agent autonomy runs into technical limitations. A researcher under the pseudonym codila explained that a single agent "suffers from amnesia" and proposed a graph architecture where agents share common memory and verify each other's work. Expanding such systems also opens new vulnerabilities: American researchers demonstrated the Ghostcommit attack, where a malicious command hides inside an image, and the verifying agent does not open it, while another assistant reads the instruction and transfers passwords into open code.

My analysis: Sber's initiative is a timely step, but the arms race with fraudsters is just beginning. While AI agents protect the corporate perimeter, attackers are already using the same technologies to bypass systems. The key success factor will be not just automation, but the architecture's ability for collective learning and real-time adaptation.