How AI Is Changing Cybersecurity

How AI Is Changing Cybersecurity

Share

Security has always been an arms race, but AI changes the tempo of it. Both sides now have tools that can read code, write convincing text, and work through the night without getting tired. The question that matters is who gets more out of that first, and the early evidence suggests attackers have had a head start.

Attackers are moving first

Microsoft’s 2026 Digital Defense Report, covering July 2025 through June 2026, makes that case bluntly. As summarized by Help Net Security, the report describes a window in which attackers collect the benefits of AI first while defenders scramble to close the gap. Finding and weaponizing a software flaw used to take real expertise; in many cases it now comes down to writing a prompt. The median time between a vulnerability being discovered in the wild and being weaponized has fallen well below 24 hours, and the number of tracked CVEs is on pace for a record of roughly 72,000 this year.

Microsoft's 2026 Digital Defense Report, covering July 2025 through June 2026, makes that case bluntly. As summarized by Help Net Security, the report describes a window in which attackers collect the benefits of AI first while defenders scramble to close the gap. Finding and weaponizing a software flaw used to take real expertise; in many cases it now comes down to writing a prompt. The median time between a vulnerability being discovered in the wild and being weaponized has fallen well below 24 hours, and the number of tracked CVEs is on pace for a record of roughly 72,000 this year.

The same report describes a lab test in which AI agents, left to attack an emulated enterprise network with no defenders in the way, took over the entire domain through a 32-step attack chain. That’s a controlled experiment, not a real breach, but it shows the direction of travel: tasks that once needed a skilled team are being chained together automatically.

The old tells are gone

The most visible change is in social engineering. Phishing emails used to give themselves away with clumsy grammar and generic greetings. AI writes clean, personalized messages in any language and can tailor each one to its target using scraped public information. Microsoft’s incident responders found phishing was the way in for 23 percent of the intrusions they investigated, up from 7 percent a year earlier. Voice and video are following: deepfaked calls impersonating executives or relatives are now cheap enough to be routine, which is pushing companies toward phishing-resistant authentication and out-of-band verification for anything involving money.

Defenders get help too

The other side of the ledger is real. Security teams have long been drowning in alerts and short of skilled analysts, and that is exactly the kind of work AI is good at: sorting thousands of low-level signals, summarizing what happened, and drafting a first response so a human can focus on the decisions that matter. Industry surveys suggest roughly two-thirds of organizations now use AI and automation in their security operations, and IBM’s breach-cost research has reportedly found that extensive use cuts average costs by about $2.2 million, though that figure comes from a secondary summary.

There is a catch. Automation helps most with volume, not with the hardest problems, and an analyst who trusts a confident but wrong AI summary can be worse off than one who has no summary at all.

The AI systems themselves become targets

Companies are also wiring AI into their own products, and that creates a new kind of attack surface. The most common weakness is prompt injection, in which malicious instructions are hidden in a web page, document, or email that an AI model is asked to read. It sits at the top of OWASP’s list of risks for LLM applications. For a chatbot that is an embarrassment; for an AI agent with access to files, email, or internal tools, it can mean data leaving the building or actions being taken without the user’s say-so. The more autonomy we give agents, the more this matters, a trend we looked at from the infrastructure side in why AI inference is becoming the next big infrastructure challenge.

Labs are starting to gate the most capable tools

The same capabilities that help defenders find bugs can help attackers exploit them, and AI developers are beginning to treat that as a release-management problem. Anthropic, for example, has kept its most cyber-capable model, Claude Mythos Preview, out of general availability and is working with a small number of trusted organizations through Project Glasswing, while the Mythos-tier model it does sell publicly ships with extra safeguards for cybersecurity. (Anthropic makes Claude, so treat that as a company example rather than a neutral survey of the industry.)

What changes in practice

For most organizations the practical lessons are unglamorous. Patch faster, because the gap between disclosure and exploitation is closing. Assume phishing will be convincing and rely on controls like hardware-backed MFA rather than on employees spotting typos. Treat AI agents like any other privileged user, with narrow permissions and logging. And remember that the machines running all of this sit in physical facilities with their own risks, from the grid to the cooling plant, which we described in what happens inside an AI data center. AI hasn’t made security a different discipline, but it has shortened the time you have to get the basics right.

Scroll to Top