Recent advances in artificial intelligence, particularly in large language models (LLMs) and agentic AI, are beginning to produce a structural change in cybersecurity comparable, in several respects, to the transformation already visible in software development.
AI can, of course, be used by security researchers, defenders, and attackers as a productivity tool. It can accelerate existing tasks, reduce manual effort, and make specialist capabilities more accessible. However, viewing AI primarily through this lens captures only one part of the transformation now underway.
AI is changing the cybersecurity landscape at several different levels simultaneously. At least six distinct patterns are emerging.
First, AI is expanding the attack surface. Put simply, AI is creating new things to attack and exploit. Models, retrieval-augmented generation (RAG) systems, embeddings and vector stores, agent memory, tools, plugins, skills, model repositories, orchestration layers, and AI supply chains are becoming components of production systems. Each introduces new assets, interfaces, dependencies, trust boundaries, and failure modes, together with associated risks that must be understood and managed.
Second, AI is creating new ways to attack. AI systems are increasingly becoming components of the attack process itself. Models can assist with reconnaissance, social engineering, vulnerability analysis, reverse engineering, malware development, exploit adaptation, and other stages of offensive operations. In some cases, AI does more than accelerate an existing technique: it changes how an attack can be constructed, coordinated, personalized, or executed. AI is therefore becoming part of the attack capability itself.
Third, AI is lowering the barrier to entry. Tasks that previously required substantial technical expertise can increasingly be performed with AI assistance and, in some cases, delegated partially or largely to autonomous systems. This changes the economics of cybersecurity by reducing the knowledge, time, and effort required to learn, understand, and perform many technical tasks. Capabilities that were once concentrated among highly skilled specialists may therefore become accessible to a much broader population.
Fourth, AI is increasing the speed and scale of cybersecurity operations. Vulnerability discovery, source-code auditing, reverse engineering, exploit development, detection engineering, incident investigation, and remediation can all potentially be accelerated. This affects attackers and defenders alike and may significantly compress the time between vulnerability introduction, discovery, disclosure, exploitation, detection, and remediation. AI also introduces a new degree of parallelism: many AI systems or agents can operate simultaneously, examining different parts of a codebase, attack surface, or incident at the same time.
Fifth, cybersecurity is beginning to move from AI-assisted workflows toward autonomous agents. The distinction is significant. An AI assistant recommends or performs individual tasks under human direction; an autonomous agent can investigate an environment, formulate intermediate objectives, select tools, execute actions, observe their results, and adapt its behaviour in pursuit of a broader goal. As these systems mature, some areas of cybersecurity may increasingly become environments in which autonomous defensive agents interact with autonomous offensive agents.
Sixth, AI capability is becoming a matter of national strategy. Access to advanced models, computing infrastructure, semiconductor supply chains, data, energy, technical expertise, and sovereign AI infrastructure is increasingly intertwined with economic competitiveness, intelligence capabilities, military power, and national security. In cybersecurity specifically, states with greater AI capability may gain advantages in vulnerability research, intelligence analysis, cyber defence, offensive cyber operations, and the protection of critical infrastructure. AI is therefore becoming not merely another technology sector, but an increasingly important component of strategic infrastructure and national cyber capability.
These six developments are closely related, but they describe different dimensions of the transformation:
- new attack surfaces
- new attack methods and capabilities
- lower barriers to entry
- greater speed and operational scale
- increasingly autonomous actors
- strategic competition and national capability
Future articles will focuses on each of these developments.
Stay tuned