olly - stock.adobe.com
AI cybersecurity vs. AI cyberattacks: Who's winning?
To stay ahead in the AI vs. AI cybersecurity race, businesses must incorporate the technology into detection, investigation, vulnerability management and response.
The emergence of AI and its increasing accessibility have changed the nature of cyber conflict. As both defensive and offensive systems become more autonomous, cybersecurity is rapidly shifting toward an AI-versus-AI context, where success depends on who can make decisions faster to overcome the opposing side.
In today's complex threat environment, security teams rely on AI to analyze millions of security events, prioritize alerts and accelerate incident response. However, cybercriminals are now using the same technology to automate reconnaissance, create highly customized phishing messages and develop evasive malware that is difficult to detect.
For CISOs and other security leaders, this shift represents more than a technology trend. While AI offers numerous ways to enhance security operations, it also expands the attack surface. It makes enterprises vulnerable to various cyberattacks, enabled by attackers' ability to execute them at high speed and scale. This means enterprises must evaluate AI from two different sides: as an important capability that strengthens cyber defenses and as a risk factor that changes how cyberattacks are planned and executed.
The AI vs. AI cybersecurity arms race
The growing use of AI for both defense and attack introduces an important question: Who holds the strategic advantage? The answer is not straightforward.
On the offensive side, AI's force multiplier is evident. Human capabilities no longer constrain attackers; they use AI to automate the collection of vast volumes of data from various public sources, automate reconnaissance, analyze large volumes of scan results and prioritize vulnerable systems at a scale that would be difficult to achieve manually. AI can also create personalized phishing messages and deepfakes to impersonate other people.
On the other hand, AI helps defenders use their asymmetrical data volume to their advantage. For instance, enterprises generate a large volume of data from their digital interactions, such as system logs, network flows and cloud data, that attackers generally can't observe. When defenders use AI to analyze this data, it enables them to do the following:
- Perform behavioral analysis to spot threats early.
- Automate triage to filter false positives at high speed.
- Cross-correlate to link different alerts into a unified attack pattern.
- Accelerate incident response to orchestrate containment faster than a human analyst.
Now, what happens when automated attacks encounter automated defense? Traditional cyberattacks require human operators to execute. For example, an attacker needs to identify what to scan, which vulnerability to exploit and how to modify their attack to reach the next stage. Using AI automates many of these steps, and AI agents can autonomously perform substantial portions of the attack lifecycle.
The same change is occurring on the defensive side. AI can automatically analyze authentication events, endpoint connections, network activity and information from threat intelligence platforms, correlate related events and execute predefined actions to cease malicious activity.
With their additional autonomy, AI agents like Claude Mythos Preview demonstrate how AI can perform vulnerability research, code analysis and exploit validation with limited human intervention. Instead of scanning for known vulnerabilities, an AI agent can inspect code, identify potential weaknesses, test whether they're exploitable and prioritize vulnerabilities based on their potential effect. This enables security teams to identify and validate critical weaknesses before attackers exploit them.
There is no apparent winner in the AI cybersecurity arms race. Attackers use AI to gain speed, execute attacks at scale and lower the technical barrier for non-tech-savvy attackers. At the same time, defenders have greater visibility into their internal data and can respond automatically. The balance will depend on which side can integrate AI more effectively into its operations while maintaining human oversight and control.
How AI empowers cyber threat actors
AI has contributed to making cyberattack techniques faster, more sophisticated and easier to execute on a large scale. Not only does AI amplify existing attack vectors, but the emergence of deepfake technology also adds a new dimension to the fight.
AI enables faster and more sophisticated attacks
The greatest risk AI poses to cybercrime lies in its ability to amplify existing attack tools and techniques. AI can assist with reconnaissance, analyzing information collected from various public sources and identifying relationships among entities, such as individuals or businesses, in addition to helping attackers prioritize targets based on different criteria. This enables attackers to move from the information gathering phase to direct engagement through social engineering attacks with considerably less manual effort.
In the past, social engineering campaigns suffered from numerous weaknesses. Traditional phishing messages featured poor grammar, spelling errors and generic content that was easy to identify. Generative AI enables attackers to create polished, grammatically correct and highly personalized messages with minimal effort.
Consider this scenario: a chief financial officer whose professional profile on LinkedIn, their corporate website, a conference presentation and social media activity are publicly available. AI can correlate and organize these details into a complete profile. It can also suggest a customized phishing email tailored to the target's preferences. Although the attack itself still requires human judgment to ensure everything is correct, the time required to execute it is substantially reduced.
In addition, AI can produce messages in different languages, adapt them to match target industries and create different versions for each recipient. A 2024 arXiv report found that AI-assisted phishing campaigns had click-through rates as high as 54%. In comparison, traditional phishing attempts only reached about 12% click-through rates.
Generative AI lowers the barrier to cybercrime
AI significantly lowers the technical barrier to entry for cybercrime. Beginner hackers with limited coding skills can use generative AI systems to serve as interactive coding tutors. AI can describe code functionality, translate scripts between programming languages, debug syntax errors and even suggest alternative routines when a script fails to execute as intended. This means a criminal who previously needed strong technical skills and time to gather intelligence about their targets can now use AI to reduce some of these barriers.
For advanced threat actors, AI tools serve as a force multiplier for a variety of attack vectors. A recent report by Microsoft Threat Intelligence found that some North Korean-backed actors, such as Jasper Sleet and Coral Sleet (formerly Storm-1877), are using AI across different attack lifecycles, including identity fabrication, social engineering and long-term operational persistence.
In this context, AI can generate code for network sockets and develop obfuscation functions or encryption wrappers. It can also help attackers modify malware components, troubleshoot code, reimplement functionality and develop supporting scripts -- shortening the time required to adapt malicious tooling to a target environment.
AI introduces a new attack surface: Deepfakes
AI becomes even more dangerous when combined with synthetic media. Nowadays, attackers use AI to impersonate executives, suppliers or business partners using voice and video cloning -- also known as deepfakes. While this might have seemed somewhat imaginary years ago, recent incidents show that criminals have executed attacks that cost targets millions of dollars using deepfake technology.
In February 2024, a finance worker at a global firm in Hong Kong was tricked into sending $25 million to fraudsters. They used deepfake technology to impersonate the company's chief financial officer during a video conference call. While this attack was considered the most prominent and costliest one, deepfake fraud continues to accelerate. According to Surfshark, recorded global losses from deepfake fraud have reached $3.7 billion, including $764 million during the first half of 2026.
Nation-state actors are using AI beyond phishing campaigns; they're also using it to create fabricated media for social media platforms and news websites to manipulate public perception. The aim of such attacks is to influence people's decisions and flood information channels with a large volume of fake data, making it harder to distinguish authentic information from fabricated content.
There are different examples of using fabricated media to influence public opinions; a notable example appeared during the German election in February 2025, when a known Russian disinformation campaign named Storm-1516 fabricated deepfake "whistleblower" videos to spread a false child-abuse allegation against a German government minister right before the vote.
How businesses use AI to strengthen cybersecurity
The same capabilities that make AI attractive to cybercriminals -- such as speed, scale, pattern recognition and automation -- also make it appealing for defenders.
Today's IT environments are complex and span on-premises and cloud settings. They generate a large volume of security data that human security experts can't analyze on their own. Because adding more security analysts doesn't solve the problem, businesses are using AI to process security signals at high speed.
AI improves threat detection
In the past, traditional security tools relied on signature-based rule detection methods to spot malicious activities. While this approach is suitable for detecting known threats, it provides limited protection against previously unseen risks and polymorphic malware.
In contrast, AI can extend traditional threat detection by enabling behavioral analytics, anomaly detection and large-scale correlation. In this approach, AI systems can process large volumes of data generated by digital interactions across an enterprise IT environment at speeds and scales that are beyond what human analysts can inspect. This enables security teams to reduce alert fatigue and detect attacks before they escalate.
The core mechanisms of AI-driven threat detection include the following:
- Behavioral analytics. AI helps establish a baseline for typical user, device and application interactions. When an activity deviates from the established baseline, the system flags it as suspicious and, if automated prevention is enabled, can block or contain it.
- Cross-domain correlation. AI-enhanced extended detection and response (XDR) improves cross-domain correlation across different parts of the IT environment, rather than treating each event as a separate incident. In traditional security, email gateways, endpoint antimalware and cloud access tools produce isolated alerts because they do not integrate well. AI-powered XDR can link these events to show specific, multi-stage attack patterns.
- Natural language processing (NLP). NLP models can analyze unstructured text data such as emails, chat logs and support tickets to detect abnormal linguistic patterns, such as those in a phishing email that try to trick someone into clicking a malicious link.
AI reduces the security operations center workload
Modern SOC teams struggle with a large volume of security alerts. When analysts spend time investigating low-risk events and using different tools and services to collect context around them, little time remains to inspect and investigate.
AI can help transform this manual process from alert-by-alert analysis to risk-based triage. It can examine multiple alerts associated with a specific user, IP address or device to determine whether they belong to a single incident. Instead of showing five isolated alerts on the analyst's dashboard, AI can display them in a consolidated view, explain their relationships, enrich them with context from various sources and prioritize them based on their effect on enterprise resources.
Threat intelligence is another area where AI can reduce cognitive load for security analysts and accelerate decision-making. Traditionally, security analysts need to move among security alerts in security information and event management (SIEM) platforms, threat intelligence platforms and technical details in vulnerability databases to determine if a specific indicator is linked to a specific threat actor. AI now automatically correlates and enriches data across disparate sources in real time, and presents the results in a consolidated view, rather than requiring analysts to pivot among different tools.
Using AI in SOC also means using NLP to query threat data. An analyst can ask questions in plain language, such as: "Has this IP address been associated with a ransomware operation in the last six months?" AI will execute the query and provide an answer with citations, rather than requiring the analyst to manually search common vulnerabilities and exposure databases and vendor blogs to obtain the desired result.
AI accelerates incident response
AI helps accelerate incident response across every stage of the incident response lifecycle, from detection to post-incident learning by doing the following:
- Faster detection. AI creates a baseline of normal behaviors for users, devices and applications. When a deviation appears, AI will flag it in real time.
- Automated investigation. When an alert is triggered, AI can pull all related artifacts, such as process trees, network connections and registry changes, from various security tools, like endpoint detection and response, SIEM and firewall logs.
- Root cause detection. AI correlates information across endpoint devices, cloud applications and identity systems to determine the initial access point and which system, user account and data were affected with that access.
- Automated containment. Security Orchestration, Automation and Response can use AI-generated recommendations or AI-assisted playbooks to automate containment measures, such as isolating infected endpoints or deactivating compromised user accounts.
- Prioritization. When many alerts are triggered at once, AI scores each issue based on how easily it can be exploited, how vital the system is to daily business operations and the extent to which the damage can propagate. This creates a ranked to-do list. The incident response team can prioritize the highest-scoring alerts rather than treating every alert as equally urgent.
- Post-incident learning. AI can turn every security incident into a source of intelligence to improve future detection and response. In a traditional approach, security analysts need to manually reconstruct the attack timeline, identify the techniques used, map them to frameworks, determine which security controls have failed and document their recommendations. AI accelerates this process and aids in mapping attacker behaviors to relevant MITRE ATT&CK techniques and identifying which security controls failed to contain the incident.
The need for humans in AI-powered cybersecurity
While AI accelerates incident response, it shouldn't replace human judgment, especially when a specific action has a significant business impact, such as stopping a production server. The best approach is to put a human in the loop; hence, AI is used for enrichment, correlations and handling low-risk, repetitive work, while human analysts are responsible for executing final decisions.
Bolster cybersecurity defense with these strategies
The following strategies can help security leaders prepare for a situation in which both attackers and defenders operate with AI assistance.
- Treat AI as a security risk, not just a productivity tool. Identify where AI is used within organizational workflows. Security teams should be aware of what data AI can access, where it's processed and whether any external systems can access it.
- Automate the tasks that require extensive manual effort. Automate the SOC tasks that cause bottlenecks, which can enable an attacker to gain an advantage over a security operation.
- Keep humans in the decision loop. AI can automate different tasks in SOC work; however, for critical decisions that affect business operations, humans should oversee and approve AI decisions before it applies them.
- Focus on behavioral detection. Cybercriminals continually work to develop their attack tools and techniques. Therefore, security teams should rely more on behavioral detection to understand what an attacker is doing rather than simply identifying specific malware.
- Test cybersecurity defenses against AI-powered attacks. Continually conduct penetration testing exercises that resemble AI-powered attacks. For example, a security team can test whether an attacker can find information in publicly available sources about company employees to create convincing spear-phishing messages. The enterprise should then assess how its security controls can counter such attacks.
Nihad A. Hassan is an independent cybersecurity consultant, digital forensics and cyber OSINT expert, online blogger and author with more than 15 years of experience in information security research. He has authored six books and numerous articles on information security. Nihad is highly involved in security training, education and motivation.