In today’s digital age, the line between defence and offence in cybersecurity is becoming ever more blurred. With the rise of artificial intelligence (AI), organisations are facing a new frontier: AI-powered attacks are ramping up in scale, sophistication and speed — and at the same time, defenders are deploying AI-driven cybersecurity tools in a bid to stay ahead. This article charts the evolution of AI in cybersecurity: how we got here, what the current landscape looks like, the opportunities and perils, and how organisations should think about navigating this high-stakes arena.
1. From manual defences to intelligent automation
Not too long ago, cybersecurity was largely reactive: manual rule-based firewalls, signature-based malware detection, human analysts poring over logs. But as attacks grew in volume and complexity — across networks, endpoints, cloud systems — traditional defences began to buckle under scale. The adoption of machine-learning (ML) and AI for threat detection, anomaly identification, behavioural analytics and automated response has changed that. According to recent analysis, AI capabilities are being applied to threat detection, phishing prevention, identity and access management and network security. [1] Organisations now view AI not as optional but as essential to managing modern cyber risk.
2. How AI is used by attackers: the offensive side
As defenders adopt AI, so do adversaries. The evolution of AI has given attackers new tools and capabilities. Examples include:
- AI-generated phishing and social engineering: Attackers use natural-language processing (NLP) and generative AI to craft personalised, highly credible messages that evade older filters. [2]
- Automated reconnaissance and vulnerability scanning at scale: One report found automated AI-powered scans reached 36,000 per second globally, illustrating how AI raises the bar for speed. [3]
- Use of AI agents and autonomous systems: According to the Gartner, Inc. prediction, by 2027 AI agents will cut the time to exploit account exposures by 50%. [4]
- Deepfakes, voice-cloning and impersonation: Attackers can mimic voices and identities, aiding fraud and extortion. [5]
3. How AI is used in defence: the protective side
But AI is not just part of the problem — it’s undeniably part of the solution. Some of the key defence use-cases include:
- Early detection and anomaly identification: AI systems can analyse huge volumes of traffic, logs and user behaviour and flag deviations that traditional systems might miss. [8]
- Automated response / remediation: By integrating AI into security-operations-centre (SOC) workflows, organisations can triage alerts, isolate affected systems, and limit the blast radius of attacks faster than purely manual methods. [9]
- Predictive / proactive threat intelligence: Rather than just reacting, AI can help anticipate likely attack vectors, build models of adversary behaviour, and stress-test defences. [10]
- Operational efficiency: The talent gap in cybersecurity is severe; AI helps extend the reach of existing teams, reduce false positives and enhance productivity. [11]
4. The pros and cons: diving into the trade-offs
Of course, as with any technology, AI in cybersecurity brings a mixed bag of advantages and challenges. Let’s unpack them.
Pros:
- Scale and speed: AI can process and analyse enormous data volumes in real time, far beyond what human teams could manage.
- Improved detection of unknown threats: Machine learning can identify anomalies and patterns that don’t match known signatures, enabling defence against zero-day and evolving threats. [12]
- Operational efficiency: By automating routine tasks, AI frees up human analysts for higher-value work, helping to address the skills shortage.
- Faster response and remediation: In an attack, minutes count — AI-enabled response can reduce dwell time and limit damage.
- Adaptive learning and improvement: AI systems can learn from each incident, refining detection and response over time.
Cons / Risks:
- False positives / over-reliance: AI isn’t perfect — it may raise too many alerts or miss context if poorly trained, leading to alert fatigue or complacency.
- Talent, cost and complexity: Implementing and maintaining AI solutions requires skilled personnel, budget and integration into legacy systems. Decision-makers flagged talent (63 %), cost (55 %) and technical complexity (50 %) as key concerns. [10]
- New attack surface / adversarial AI: AI systems can themselves be attacked — via adversarial inputs, model poisoning, supply-chain issues or misuse. [13]
- Bias, transparency and governance: If AI models are opaque (“black-box”), decision-making may be unclear; bias in data may lead to unequal protection, and governance/regulatory compliance is a growing concern. [14]
- Arms-race dynamics: As defenders adopt AI, attackers also up their game. The reality is a continuous cat-and-mouse — staying ahead is expensive and complex. [15]
- Over-promising and under-delivering: AI hype is real. For example, Gartner estimates over 40 % of “agentic AI” projects will be cancelled by 2027 due to unclear value or risks. [16]
5. The evolving landscape and key trends
The interplay of AI in cybersecurity has matured to a point where we’re no longer simply exploring experiments — this is now mainstream. Several key trends are worth highlighting:
- Generative AI and unstructured data security: Organisations are shifting from protecting just structured data (databases) to unstructured data (text, images, video) because GenAI tools present new risks. [11]
- Machine identity and expanded attack surface: With AI/automation, DevOps, cloud and machine-to-machine communication proliferate — organisations must now manage machine identities (not just human) to prevent abuse. [11]
- Tactical AI rather than abstract promise: Security leaders are now moving away from broad “AI for everything” strategies and favouring narrow, measurable use-cases where benefits are clear. [17]
- Cyber-resilience and human-machine partnership: Instead of viewing AI as a silver bullet, many organisations now emphasise resilience: combining humans + AI, embracing culture, incident-response readiness, and continuous improvement. [11]
- Regulation, governance & AI risk management: With regulations such as the EU AI Act and growing scrutiny over AI systems, security teams must treat their own AI deployments as potential risk zones. [14]
6. Our view: navigating the arms race
In my view, we are firmly in the midst of a technological arms race where attackers and defenders both wield AI — with the advantage largely going to whoever is faster, smarter and better resourced. But speed alone isn’t enough. What distinguishes successful defenders is a clear strategy that recognises that AI is a tool *within* a broader security ecosystem — not the entire ecosystem. Here are a few practical reflections:
- Start with measurable use-cases — e.g., using AI for alert triage or anomaly detection — rather than broad “AI transformation” aspirations.
- Ensure you build the human-AI partnership: Analysts need to understand what the AI system is doing, why it is raising alerts and how to interrogate its decisions (to avoid over-trust).
- Focus on resilience: assume compromise, build processes for containment and recovery, and train for scenarios where AI fails or is fooled.
- Govern your AI: know which models you use, how they were trained, what data they ingest, and what their vulnerabilities might be — model poisoning, adversarial inputs, supply-chain risk.
- Manage talent and culture: the best AI tool is only as good as the people using it — invest in skills, clarity of roles, and continuous learning.
- Keep the arms-race mindset alive: attackers will keep innovating — you must continuously adapt your defences, monitor for emerging threats (e.g., agentic AI, deepfakes, voice-cloning) and ensure you’re not simply reacting to yesterday’s problem.
Summary: The evolution of AI in cybersecurity has transformed both sides of the battle: attackers now wield AI to automate, personalise and scale their operations, while defenders are leveraging AI to detect, respond and anticipate threats at speed and scale. The potential benefits are significant — better detection, faster response, operational efficiency — but so too are the risks: false alarms, governance issues, new attack surfaces, talent gaps and the ever-present arms-race nature of the field. Organisations that succeed will be those that embrace AI tactically, integrate it into a broader resilient security strategy, and maintain human-machine collaboration with strong governance and continuous adaptation.
Citation list:
[1] AI in Cybersecurity: How AI is Changing Threat Defence — Syracuse iSchool — link
[2] What are AI Generated Attacks? — MixMode — link
[3] AI-powered, automated attacks have reached record numbers — Security Magazine — link
[4] Gartner Predicts AI Agents Will Reduce The Time It Takes To Exploit Account Exposures by 50% by 2027 — Gartner — link
[5] AI Cyber Attack Statistics 2025 — Tech Advisors — link
[6] Darktrace 2025 Report: AI threats surge, but cyber resilience grows … — Industrial Cyber — link
[7] Majority of Orgs Hit by AI-Cyber-Attacks as Detection Lags — Infosecurity Magazine — link
[8] AI in Cybersecurity: Defending Against The Latest Cyber Threats — PurpleSec — link
[9] AI SOC Agents in Gartner® Hype Cycle: Key Insights for Security Operations … — Dropzone.ai blog — link
[10] AI Adoption in Cybersecurity Tools | Gartner Peer Community — link
[11] Gartner Identifies the Top Cybersecurity Trends for 2025 — Gartner Press Release — link
[12] Advancing Cybersecurity: a comprehensive review of AI-driven … — Journal of Big Data — link
[13] NIST Identifies Types of Cyberattacks That Manipulate Behaviour of … — NIST — link
[14] The 2025 Hype Cycle for Artificial Intelligence Goes Beyond GenAI — Gartner article — link
[15] AI Is the Greatest Threat — and Defence — in Cybersecurity Today … — McKinsey blog — link
[16] Gartner Predicts Over 40% of Agentic AI Projects Will Be Cancelled by End of 2027 — Gartner — link
[17] AI and Resilience Take the Spotlight in 2025: Key Trends from Gartner® Cybersecurity Research — Rapid7 blog — link
beFirstComment