KELA REPORT
KELA AI Cybercrime Report Q4 2026: Inside the criminal market for adversarial AI
The controls that govern commercial AI stop where the criminal market begins.
Share:

There is a market selling AI built for cybercrime, and its own customers aren’t impressed.
Commercial AI platforms publish usage restrictions, monitor for abuse and increasingly operate under binding law. Adversaries know that downloading an open-weight model, modifying it and running it on their own hardware puts all of that out of reach.
That is the Adversarial AI gap. KELA CIC spent this cycle inside it, reading what is on sale and what the buyers say it delivers.
Key findings:
- Actors who want capability attack commercial models through fraud; actors who want invisibility accept degraded output.
- The premium sits on the guardrails: sellers advertise jailbroken commercial models and modified local ones.
- The buyers are skeptical: practitioners call uncensored models overrated and say modified models aren’t reliable.
- A market shaped like the commercial one: access billed per token in cryptocurrency, preconfigured bots, and consulting for criminals.
- From advice to execution: models wired into agentic frameworks that reach scanners and command line tools, running sequences with little human involvement.




