Russia's largest bank has unveiled a system of multimodal AI agents designed to automatically detect phishing resources. The presentation took place at the Offzone 2026 conference, where developers revealed details of the new solution's architecture.
The developed technology conducts a comprehensive analysis of a web page across multiple vectors at once: textual content, program code, hosting infrastructure, and visual design. The collected data undergoes multi-stage verification. Within the system, a principle of adversarial competition operates: one group of agents builds evidence of a threat's presence, another refutes it, after which a separate module makes the final decision based on the aggregate of arguments.
The scale of the problem the bank faced is impressive. By my estimates, more than 11,000 phishing domains are registered worldwide every day, with a significant portion of these sites living for only a few hours. The spread of generative AI only worsens the situation: attackers can now churn out fake pages at unprecedented speed, rendering manual moderation pointless.
From assistant to autonomous guardian
At the current stage, the system operates in "advisor" mode — it conducts initial analysis, sets priorities, and prepares a report for a security specialist who makes the final decision on blocking. However, Sber's plans include a transition to fully automatic blocking of detected resources.
The key bet is placed on integration with the X Threat Intelligence platform, to which more than 760 Russian organizations are already connected. This will allow scaling the automated search for sites imitating company brands across the entire ecosystem.
AI vs. AI: a new arms race
Sber's initiative is part of a broader trend. Earlier, the bank already introduced "GigaAgent" — a universal assistant capable of independently planning tasks and rewriting its own code. Other operators are taking similar steps: MTS has modernized the AI models of its "Zashchitnik" service, where three neural networks analyze more than 1,100 parameters of each call, reducing the response time to a fraudulent call from 30 to 15 seconds.
Predictions of total dominance of non-human traffic no longer look like science fiction. Elon Musk supported Cloudflare's estimate that by May 2026, traffic from AI agents will exceed user traffic, and in five years will surpass it by 1,000 times.
However, agent autonomy runs into technical limitations. A researcher under the pseudonym codila drew attention to the "amnesia" of single agents — they lose context between sessions. The solution appears to lie in a graph architecture, where agents share common memory and verify each other's work.
The expansion of such systems inevitably opens new vulnerabilities. American researchers demonstrated the Ghostcommit attack: a malicious command hides inside an image, and the reviewing agent does not open the file, while another assistant reads the instruction and transfers passwords into open code.
My conclusion: Sber's bet on multimodal agents is the right step, but it is only an intermediate stage in the evolution of cybersecurity. The arms race between AI attackers and AI defenders is just beginning, and victory will go to those who can create self-learning systems with shared memory, resilient to new attack vectors.