Time Is Up—It’s Happening Now
The concept of leveraging artificial intelligence (AI) to expand adversarial cyber attacks is now well beyond theoretical.
AI agents have already proven themselves as the ideal tool for adversaries wanting to cause irreparable harm across all facets of digital infrastructure. At the core, AI agents are large language models that have a set of instructions, context, access to tools and the ability to take action. Using agents enables automation of a vast array of techniques and tools to discover vulnerabilities, build attack sequences and pivot to new tactics with speed and scale never before imagined.
So, why can’t defenders do the same?
In principle, we can, but experts recognize there is a multiyear catch-up effort. That’s the best-case scenario, and providing that defenders are organized, united and focused on this objective. At the 2026 RSA Conference, industry legend Kevin Mandia, now founder and CEO of AI security company Armadin, stated that “It’s a perfect storm for offense over the next year or two” as defenders try to catch up. “The scale and scope and total recall of an AI agent compromising you and swarming you is not humanly comprehensible.”
With its 24/7 army of highly effective AI agents attacking our systems, the adversary never sleeps.
Agentic AI Is Nonnegotiable for Cyber Defense
We have reached a critical threshold where traditional human analysis is no longer a viable shield. The volume and velocity of AI-driven threats have outpaced the cognitive capacity of even the most elite security operations center teams.
To survive this shift, we must deploy agentic AI to remove the human bottleneck and handle the heavy lifting:
• Architectural Resilience: Building new systems from the ground up with significantly fewer software defects and inherent “resilience” against long-established security risks, such as access control, memory errors and OWASP Top 10.
• Autonomous Testing and Hardening: Identifying and patching weaknesses with a new level of thoroughness before a system is deployed.
• Continuous, Adaptive Monitoring: No longer just watching for known threats. Now with the goal of training defensive AI to meet adversarial agents at hyper-speed, blow-for-blow, at the tactical edge.
There is still an opportunity to leverage AI defensively to counter a wide range of attacker approaches, exploiting vulnerabilities that exist across all facets of digital infrastructure. The defender’s effort requires time to plan and implement an asymmetrical advantage compared to those on the offensive side.
While all of the above are essential, fragile code and architecture are frequently cited as responsible for more than 70% of critical vulnerabilities. That’s not new news. It’s just that AI now exploits this soft underbelly that has long been avoided.
Regaining the Time Advantage
Architectural resilience and autonomous testing and hardening represent the foundational measures that must be applied to defend against adversarial AI. Human defenders may be creative and experienced, but can they maintain context in real time across an information technology (IT) environment at the same pace as AI? And why do so many attacks need to be thwarted at time of execution, like an outfielder catching fly balls at a rate of thousands per minute?
The common thread is the need for a time advantage in the face of overwhelming odds. Barring time travel as an option in today’s world, the best advantage we can gain is by preparing for cyber adversaries well in advance of bringing systems online.
Per Palo Alto Networks Unit 42, the average time through the cyber kill chain, from discovery to exploitation of a weakness, has moved from weeks to hours. AI-assisted workflows largely remove the human capital constraint, allowing attackers to seek out vulnerabilities and work through the sequence across hundreds of targets in parallel.
Three Top Categories of How AI Is Leveraged by Adversaries
Agentic Orchestration
Fewer resources and faster attack time across the cyber kill chain mean that cyber adversaries can outmaneuver human analysts, who have long been overwhelmed even before AI. According to Palo Alto Networks Unit 42, agentic AI data exfiltration attack speed has quadrupled. Yet, in more than 90% of breaches, preventable gaps materially enabled the intrusion.
Hyper-Personalization of Identity Deception
Phishing, the approach of deceiving humans into taking action on behalf of the attacker, spans the kill chain on reconnaissance, weaponization and most significantly on delivery. AI transforms this into phishing on steroids with more realistic impersonation techniques, leveraging deepfake images and voices, with context of people and their roles, and in greater volume. IBM X-Force research demonstrated that AI can generate highly convincing phishing emails in five minutes compared to the 16 hours typically required by experienced human operators—a 192 times improvement in efficiency. And per DarkTrace, AI-powered phishing attacks are 67% more successful than traditional ones. Voice cloning now requires just three to five seconds of audio, and convincing video deepfakes can be created in 45 minutes with free software.