Better Cybersecurity Should Be Responsible For Containing AI Threats
The focus of the recent cybersecurity discussion has swiftly shifted to artificial intelligence and the existential damage it might do. True, autonomous systems can speed up reconnaissance and vulnerability discovery; generative AI can create convincing phishing messages, deepfakes, and malicious code; and increasingly powerful AI agents may eventually carry out complex attacks with little assistance from humans. These developments are worthy of careful consideration. However, portraying AI as the ultimate antagonist poses a risk. The more crucial question is whether our cybersecurity architecture is ready for a digital world where both attackers and defenders have access to increasingly potent AI.
Because AI is essentially an accelerant, the distinction is crucial. It can increase an adversary’s efficiency, but it can also increase the speed and capability of a security team. In addition to automating detection, correlation, and response, it can automate parts of an attack. It can assist in finding vulnerabilities, but it can also assist defenders in recognizing and ranking them. Therefore, preventing AI from entering cybersecurity is not the true strategic challenge. It is the process of creating a robust cybersecurity architecture that allows AI to enter securely.
The most recent data supports this point. Verizon’s 2026 Data Breach Investigations Report examined over 31,000 actual security incidents, including over 22,000 confirmed breaches in 145 countries. For the first time in the report’s history, it was discovered that software vulnerability exploitation had surpassed stolen credentials as the primary initial breach vector, accounting for 31% of breaches. Additionally, Verizon found that ransomware was involved in 48% of breaches and that generative AI played a role throughout several stages of attacks.
Verizon’s 2026 Data Breach Investigations Report:
Every executive and policymaker should be concerned about those figures. However, they also indicate that the fundamentals are still important. Even though AI is slowing down the pace of cyber threats, vulnerabilities, credentials, human behavior, third parties, and insufficient security architecture continue to compromise organizations. At this stage, AI may or may not be controllable, and there is much debate about what guardrails can be mandated and enforced on frontier models. That will continue to be an ongoing debate.
But what is within our control is stronger cybersecurity. Zero Trust, segmentation, strong identity, encryption, ongoing monitoring, public-private collaboration, and strictly regulated access to sensitive systems are the cornerstones of this more robust ecosystem.
The Threat Equation Is Changing Due to AI
Artificial intelligence is undoubtedly altering cyber risk. While AI-assisted tools can assist attackers in researching targets, identifying vulnerabilities, and developing or modifying malicious tooling, generative AI lowers the barriers to creating convincing social engineering campaigns. According to Verizon’s 2026 study, threat actors were utilizing generative AI for malware development, targeting, and initial access. This indicates that AI is not just a theoretical future concern but is already a part of the operational threat environment.
The development of agentic AI adds another dimension. An AI system that merely responds to a query presents one type of risk. A completely different security challenge arises when an AI agent can access databases, communicate with applications, write code, make decisions, and act on behalf of a person or organization. An AI system’s identity, permissions, monitoring, and boundaries become increasingly crucial as it gains more autonomy.
However, the same capabilities that pose a threat can also fortify the defense. AI is able to correlate indicators from various systems, identify anomalous behavior, prioritize vulnerabilities, process security telemetry at a scale that is unattainable for human analysts, and help with incident response. It can assist security operations centers in separating real threats from the large volume of alerts generated by contemporary networks.
For this reason, AI vs. cybersecurity shouldn’t be the only way to describe the future. AI-enabled attackers versus AI-enabled defenders presents a more realistic image. Organizations that incorporate AI into a more comprehensive security architecture rather than using it as a stand-alone technology will benefit.
An Antiquated Security Architecture Is the True Issue.
The concept of a perimeter served as the foundation for cybersecurity for many years. To keep untrusted actors out, organizations constructed firewalls around trusted internal networks. When corporate servers hosted applications, employees worked mostly from offices, and organizations kept data within their boundaries, that model made sense.
There is no such world anymore. Workers use mobile devices and work remotely. Applications are spread across several clouds. Corporate networks are connected to Internet of Things devices. Information technology and operational technology are interacting more and more. Business systems are accessible to outside vendors. Organizations, platforms, and jurisdictions exchange sensitive data. Additionally, AI agents are starting to act as a bridge between people, data, and applications.
There is no longer just one perimeter to protect. This is the main reason Zero Trust has grown in significance. The fundamental idea is that no user, device, application, or digital identity should be implicitly trusted just because it is connected to a network or has already undergone authentication. Identity, context, behavior, authorization, and need should all be considered when evaluating access.
That idea must apply to more than just human users in an AI-driven setting. It is becoming increasingly necessary to treat AI agents, automated services, and machine identities as entities with grantable, monitorable, restricted, and revocable permissions. For organizations, the question should be simple: What can this entity access, what can it do, why does it need that access, and how soon can that access be terminated? As AI systems grow more autonomous, that question becomes even more crucial. Please refer to The Benefits and Risks Every Business Leader Needs to Understand About AI:
What AI Can’t Access Could Be the Most Crucial AI Security Decision
The haste with which enterprises are implementing AI makes it tempting to give models access to vast amounts of organizational data. An AI system’s capacity to respond to queries and carry out tasks can be enhanced by more data, but unrestricted access poses a serious cybersecurity and privacy risk.
Not every piece of data is equally sensitive or valuable. It is inappropriate to treat public information, internal business records, intellectual property, personally identifiable information, financial data, healthcare records, operational technology information, and national security information as belonging in the same digital environment.
As a result, one of the most crucial defenses in the AI era is data segmentation. Businesses should ascertain what data an AI system truly requires to complete a given task and limit access to that data. Unrestricted access to proprietary intellectual property is not necessary for an AI assistant assisting staff in finding public policies. Financial systems shouldn’t be automatically accessible to an AI system that supports customer service. Just because the underlying network allows it, an AI tool that analyzes corporate documents shouldn’t be able to move laterally into operational technology environments.
Minimum necessary access should be the guiding principle. Boundaries around sensitive data can be established through micro-segmentation, identity-based controls, data classification, encryption, and ongoing monitoring. These boundaries may restrict the extent of the compromise and the amount of information that can be revealed if an AI system is compromised. In essence, this is Zero Trust applied to AI and data.
Specialized AI Protocols Are Required for Specialized Networks
When AI is implemented in specialized settings like hospitals, financial institutions, manufacturing facilities, energy systems, transportation networks, telecommunications infrastructure, and national security systems, the problem becomes even more significant.
In these settings, AI can be very beneficial. It can monitor industrial machinery, spot irregularities, streamline processes, help with medical analysis, and enhance cyber threat detection. Therefore, many of AI’s potential advantages would be lost if it were kept entirely apart from these systems.
However, integration needs to be managed. Establishing clear protocols that specify which AI systems can communicate with specialized networks, what data they can access, and what actions they are allowed to take are all important. Stronger authentication, more segmentation, limited permissions, and ongoing auditing should all be used in higher-risk environments. Instead of having direct access to sensitive systems, AI should sometimes function through controlled gateways or isolated execution environments.
Additional authorization should be required for high-consequence actions, especially when an AI decision could have an impact on financial assets, physical infrastructure, safety, or national security.
An AI agent shouldn’t be allowed to increase its own privileges just because it thinks it would be more efficient. Furthermore, without policy controls, an AI system shouldn’t be automatically permitted to transfer its power to another agent. Preventing AI from performing beneficial tasks is not the goal. Making sure AI can only carry out tasks for which it has been given permission is the goal.
For operational technology, this is becoming especially crucial. Because the potential advantages of AI must be weighed against the risks of introducing new digital pathways into systems that may impact physical processes and critical infrastructure, CISA and its partners have been creating guidelines for safely integrating AI into OT environments.
Today’s Security Strategy Includes Post-Quantum Cryptography
Alongside AI, there is another technological shift that businesses cannot afford to overlook: quantum computing. Some of the public-key cryptography that underpins modern digital communications, transactions, and identities may eventually be threatened by a sufficiently powerful quantum computer. What happens when such a machine is made available is not the only issue. With the hope that future quantum capabilities will enable them to decrypt it, adversaries can gather encrypted data now.
The cybersecurity planning timeline is altered by the “harvest now, decrypt later” threat. Organizations should already be assessing their cryptographic exposure if they have information that needs to be kept secret for years or decades. Even if they are encrypted today, government records, defense information, intellectual property, healthcare data, financial information, and strategic business communications may still be valuable in the long run.
The time to start switching to post-quantum cryptography is now, according to NIST. Organizations are required by NIST’s transition planning to identify vulnerable cryptographic systems and start replacing or updating them. Three completed post-quantum standards are available for implementation. High-risk systems are anticipated to transition earlier under the current transition framework, which will eventually deprecate and remove quantum-vulnerable algorithms from NIST standards.
This will not be an easy migration. Applications, cloud platforms, devices, communications systems, and supply chains all incorporate cryptography, and many organizations lack a comprehensive inventory of the applications that use cryptographic algorithms.
AI itself may be able to help with that. AI can assist businesses in identifying vulnerable systems, finding cryptographic dependencies, analyzing software inventories, and setting migration priorities. Therefore, the same technological revolution that gives rise to new security challenges can also assist organizations in managing those challenges.
The Force Multiplier is Public-Private Cooperation.
Compared to government agencies, technology companies, cybersecurity firms, and private infrastructure operators view threats differently. Individual businesses typically cannot match the government’s intelligence, law enforcement, and comprehensive understanding of nation-state activity. Neither side can sufficiently protect the ecosystem on its own.
Therefore, rather than being a policy goal, public-private cooperation should be viewed as a strategic cybersecurity capability. The United States has already created significant models for this cooperation through CISA, information-sharing organizations, industry-specific partnerships, and programs like the Joint Cyber Defense Collaborative. However, the model must become more operational and quicker. Businesses require actionable threat intelligence, and the government requires prompt visibility into attacks, vulnerabilities, and new technologies found in commercial networks.
The goal should be an ongoing feedback loop in which industry shares what it observes in operational environments, the government shares what it knows about threats, and both parties use that information to bolster defenses. Because the AI technology ecosystem is primarily commercial, this collaboration is particularly crucial. Private businesses are developing many of the fundamental AI models, cloud platforms, semiconductor technologies, and applications that will influence national security in the future.
Thus, it is impossible to separate cybersecurity policy from technology policy. On secure AI, post-quantum cryptography, identity management, critical infrastructure security, and cyber-resilient architectures, universities, national laboratories, tech companies, cybersecurity firms, and government agencies should work together more. Making security a shared ecosystem responsibility should be the aim.
More AI Is Required for Defense
The volume and speed of contemporary digital activity are too much for the cybersecurity workforce to handle by hand. AI can offer the analytical scope required to complement human knowledge.
Continuous network behavior analysis, correlation of threat intelligence, anomaly detection, and vulnerability prioritization are all possible with defensive AI. It can assist in determining whether seemingly unconnected incidents are, in fact, a component of a coordinated assault. Before attackers can move laterally through an environment, it can help security teams identify compromised identities and devices.
AI can also automate parts of incident response. A system may isolate a compromised endpoint, revoke a credential, or block suspicious traffic under well-defined policies, all the while forwarding higher-consequence decisions to a human analyst. However, defensive AI requires its own safeguards. Organizations should know the data an AI security system uses, the reasons for its conclusions, and the actions it can take. Appropriate human oversight should continue to apply to high-stakes decisions. Instead of adding another opaque layer of unchecked power, AI should speed up and improve the efficiency of security experts. Therefore, replacing people with autonomous cybersecurity is not the best model. It is machine intelligence combined with human expertise.
Resilience Is More Important Than the Delusion of Prevention
The fact that no organization can ensure that it will never be compromised is one of the most crucial lessons of contemporary cybersecurity. A well-developed security strategy acknowledges that some attacks will eventually be successful.
The goal is to increase their difficulty, minimize their effects, quickly identify them, and quickly recover from them. Cyber resilience is that. Sensitive information is divided rather than concentrated in a single setting when it is resilient. In order to prevent a compromise in one area from automatically becoming a compromise everyplace, critical systems are segmented. It implies that encryption is being prepared for the post-quantum era, identities have minimal privileges, and AI agents have restricted permissions.
It also implies that recovery systems need to be safeguarded. It is not possible to connect backups to the same environment that an attacker is attempting to breach. An organization cannot start responding to an incident only after significant harm has been done to it. Anticipating, detecting, containing, recovering, and adapting must become ongoing processes in cybersecurity.
My work on cybersecurity, emerging technologies, and digital trust, including Inside Cyber: How AI, 5G, IoT, and Quantum Computing Will Transform Privacy and Our Security, all revolve around this central theme. Although technology is constantly changing, the basic need is still the same: security architectures must be able to change with the times.
Better Cybersecurity Is the Solution, Not Less AI.
AI-powered cyberattacks will make a lot more headlines. There ought to be. Organizations that undervalue how technology is changing the threat landscape will be at risk.
However, the bigger strategic error would be to believe that limiting AI is the only solution. AI is essential to the US and its allies’ economic competitiveness, scientific advancement, healthcare, defense, intelligence, and national security. Rather than retreating from innovation, the goal should be responsible adoption backed by a robust security architecture.
This entails integrating Zero Trust into AI settings instead of handling it as a stand-alone project. It entails dividing up sensitive data before integrating it with strong AI systems. It entails granting least-privilege permissions and identities to AI agents. It entails creating protocols that regulate AI’s interactions with specialized networks. It entails hastening the transition to post-quantum cryptography prior to the development of a quantum computer that is relevant to cryptography. It entails using AI aggressively on defense while maintaining the proper level of human oversight. Additionally, it entails fortifying the public-private alliances necessary to protect an ecosystem that is not under the control of a single entity.
AI will contribute to the cybersecurity issue. Additionally, it will play a bigger and bigger role in the cybersecurity solution. Businesses that use the least amount of AI or even the most advanced AI won’t always be the ones that succeed. They will be the companies that know how to manage access to technology, safeguard data, divide systems, confirm identities, bolster encryption, and keep an eye on their online spaces.
Whether AI succeeds or fails won’t affect cybersecurity in the future. Whether we create systems robust enough to function in a world where AI is ubiquitous will determine this. Keeping AI out of cybersecurity is the true challenge. It is constructing a cybersecurity framework robust enough to allow AI to enter safely.