it-sa 365: Are we currently witnessing the beginning of a genuine AI-versus-AI arms race in cybersecurity, or will human expertise remain decisive on both sides for years to come?
Dan Bird: We are already living in the era of algorithm versus algorithm. Artificial intelligence is increasingly taking over tasks that previously required significant time and deep human expertise, from software analysis and vulnerability discovery to exploit development and the linking of individual attack steps into sophisticated attack chains. As AI capabilities continue to advance, a growing proportion of cyberattacks will be conducted at machine speed and on a massive scale.
Humans are not being replaced, but their role is changing. I expect AI to take over much of the routine operational workload, while people remain responsible for judgement and decision-making. For defenders, the key takeaway is this: if attackers are using AI at machine speed, cybersecurity can no longer rely primarily on processes designed around human speed. AI versus AI is becoming the new reality.
Explore the topic area Artificial Intelligence & IT Security on it-sa 365.
it-sa 365: What impact is generative AI already having on the speed and scalability of cyberattacks?
Dan Bird: The most immediate impact is speed. Developing a working exploit used to be an iterative process: generating an idea, testing it, evaluating the outcome and refining the approach. AI can complete this cycle far more quickly, pursue multiple approaches simultaneously and continue operating without interruption.
Tasks that once took experienced security researchers days or weeks can increasingly be completed in a matter of hours, and sometimes even minutes.
At the same time, AI is transforming the scalability of attacks. Earlier forms of automation largely repeated known attack patterns. Modern AI can adapt its methods to specific software or IT environments and apply them across multiple targets simultaneously.
As a result, relatively small groups of attackers can now carry out activities that previously required far larger teams of specialised professionals.
The kinds of new attack waves that individual AI models can already trigger are illustrated by the article “New waves of attacks feared from Anthropic’s AI model”.
it-sa 365: Which phases of a cyberattack can be automated most effectively using AI?
Dan Bird: AI performs particularly well in situations that require analysing technical information, testing different possibilities and adapting approaches based on the results. This is already evident in vulnerability analysis and exploit development. AI models can examine source code, identify potential weaknesses and develop working attacks with significantly less human effort.
More importantly, AI is increasingly capable of connecting individual attack stages. After gaining initial access, attackers often need to obtain credentials, escalate privileges or move laterally within an environment before reaching their ultimate objective. Current research demonstrates that AI can combine multiple vulnerabilities to identify precisely these types of attack paths. The trend is therefore moving away from automating individual tasks towards automating entire attack chains.
Find out more about how to identify and defend against current cyberattacks.
it-sa 365: Does AI primarily make professional attackers more effective, or does it lower the barriers to entry for less experienced actors?
Dan Bird: Both. For experienced attackers, AI acts as a force multiplier. Individual actors can target more organisations simultaneously, test a greater number of attack methods and complete tasks that previously required much more time or larger teams. As a result, already capable attackers become even faster and more efficient.
At the same time, AI lowers the barriers to conducting technically sophisticated attacks. Traditionally, there was a significant gap between discovering a vulnerability and being able to develop a working exploit. Today, AI can perform parts of that process.
This does not mean expertise is no longer important. It does, however, mean that capabilities once reserved for highly skilled specialists are becoming available to a much wider group of actors. That may ultimately prove to be the more significant change. AI is not only enhancing the capabilities of the most advanced attackers; it is also enabling less experienced actors to launch attacks at a scale that was previously difficult to achieve.
The additional risks posed by poisoned AI supply chains for organisations are explored in the article “Supply Chain Attacks: Poisoned AI”.
it-sa 365: What capabilities must modern security solutions develop in order to keep pace with AI-driven attacks?
Dan Bird: First and foremost, defenders do not need more security alerts. Most security teams already have more information than they can realistically process. What matters is understanding which vulnerabilities genuinely create realistic attack opportunities and which risks are truly relevant to the organisation. A vulnerability that appears critical on paper may have limited practical impact if it cannot actually be reached or exploited in the specific environment.
Cybersecurity therefore needs to become far more evidence-based. Organisations must be able to determine which vulnerabilities are genuinely exploitable, understand their potential impact, remediate the risks that truly matter and then verify that those actions have actually eliminated the attack path. Implementing security controls is not the same as reducing risk.
How organisations can respond to exactly these kinds of threats with AI-powered data resilience is shown in the article “The Key to AI-Powered Cyber Data Resilience”.
it-sa 365: Where do today’s AI systems face their biggest limitations in cyber defence?
Dan Bird: One of the greatest challenges is distinguishing between a convincing answer and a verifiable one. Generative AI is highly effective at interpreting information, but in cybersecurity its conclusions must always be supported by evidence from the real IT environment. A confidently phrased response from an AI model is not proof that a vulnerability is or is not exploitable.
Another challenge is predictability. Autonomous security systems frequently operate in production and business-critical environments, which means they cannot be allowed to act without constraints.
A promising approach is to give AI the freedom to develop strategies and make decisions, while restricting execution to approved and validated actions. This preserves adaptability while ensuring behaviour remains controlled and secure.
it-sa 365: Why is it no longer sufficient simply to identify known vulnerabilities?
Dan Bird: The number of known vulnerabilities has become so large that organisations can rarely remediate them all before they are potentially exploited.
At the same time, security risk is not simply a list of isolated vulnerabilities.
A critical vulnerability may be practically irrelevant if it cannot be reached or exploited in a specific environment. Conversely, several less severe vulnerabilities, combined with excessive privileges, weak credentials or misconfigurations, may create a direct path to critical systems.
This highlights the difference between vulnerabilities and exposure. Visibility shows which vulnerabilities exist. Exposure demonstrates how an attacker could exploit existing conditions. Only then can risks be prioritised effectively.
it-sa 365: What role will automated and continuous security testing play compared with traditional penetration testing?
Dan Bird: The faster attacks evolve, the faster security testing must become. Human penetration testers will continue to play an important role, particularly for highly specialised assessments and unusual scenarios. However, traditional point-in-time penetration tests alone cannot provide the necessary frequency or scale. A one-off assessment reflects security posture only at the time of testing. The environment may change shortly afterwards.
AI and automation are making continuous security validation practical at scale for the first time. I believe the future lies in AI-powered security testing, while human experts focus on exceptional or particularly complex cases. If attackers use AI continuously, defenders can no longer rely on assessing their systems only once or twice a year.
it-sa 365: What role will autonomous AI agents play in cybersecurity over the next five years?
Dan Bird: I expect autonomous AI agents that can operate safely in production IT environments to become the new standard. They will continuously verify whether security controls are actually effective, identify vulnerabilities with genuine business impact and enable more informed risk prioritisation.
At the same time, they will evolve from passive assistants into active participants. They will assess situations independently, select appropriate tests, execute approved actions, evaluate outcomes and adapt their next steps accordingly.
The challenge will be implementing that autonomy safely. Autonomous does not mean uncontrolled. AI can analyse and make decisions independently while remaining subject to clearly defined and validated operational boundaries. Humans will still be involved, particularly when situations fall outside those boundaries, but increasingly only by exception rather than at every step.
Why interconnected AI agents need their own “conductor” is explained in the article “The AI Orchestra: Why Multi-Agent Systems Need a Conductor”.
it-sa 365: Will organisations eventually deploy their own AI agents to continuously search for attack paths and verify security controls?
Dan Bird: Yes, absolutely. Autonomous systems will become an integral part of security operations because organisations need continuous assurance that their safeguards are actually working and can no longer depend on occasional assessments.
The real value lies in continuous feedback. Organisations will be able to make changes to their IT environments, verify them immediately and determine whether a potential attack path has genuinely been removed. Because IT environments are constantly evolving, this evidence can be continuously refreshed rather than becoming outdated between assessments. Cybersecurity therefore shifts from a periodic exercise to a continuous process.
it-sa 365: How transparent must AI-based security solutions be for organisations to trust their results?
Dan Bird: AI-based security solutions must be transparent enough for security teams to understand and validate their findings rather than relying solely on the AI’s assessment. If an AI system identifies a serious risk, users should be able to see exactly what was detected, how the finding was verified and what evidence supports the conclusion.
In cybersecurity, a plausible-sounding answer is not enough. The outcome must be demonstrably supported by the realities of the environment. This becomes even more important as AI takes on more operational responsibilities. Trust cannot be based solely on model performance. It is built through consistent, reproducible results and the ability to understand and verify what the system has done at any time.
AI can provide valuable analysis and identify connections, but its conclusions and actions must always be backed by robust evidence.
it-sa 365: What regulatory or organisational guardrails are needed to ensure the responsible use of AI in cybersecurity?
Dan Bird: Governance should focus primarily on what an AI system is actually permitted to do. Organisations need clearly defined use cases, permissions, control mechanisms and lines of accountability for autonomous actions, particularly when AI is deployed in production environments.
The greater a system’s autonomy, the more important controlled and predictable processes become. This is one reason deterministic models currently offer advantages in many scenarios.
At the same time, regulators are increasingly focusing on measurable outcomes. A good example is the European Central Bank’s current requirements regarding AI-driven cyber threats. The emphasis is no longer solely on the existence of security processes, but on proving that those processes effectively reduce operational risk. This focus on verifiable outcomes will become increasingly important as AI adoption expands across cybersecurity.
it-sa 365: Which development in the AI-versus-AI landscape do you believe is currently most underestimated?
Dan Bird: I believe we still underestimate how profoundly AI is changing the economics of cyberattacks. Much of the public discussion focuses on whether AI can discover entirely new vulnerabilities.
The more immediate transformation, however, is that even complex attacks can now be developed faster and repeated more cheaply. That fundamentally changes target selection.
Highly customised attacks previously required so much expertise and effort that attackers had to carefully evaluate whether a particular organisation was worth targeting. If small teams can now use AI to attack many organisations simultaneously while tailoring their methods to each target, that calculation changes dramatically.
Small and medium-sized businesses will no longer be able to assume that they are economically unattractive targets for sophisticated attackers.
it-sa 365: How will the role of security teams change as AI takes over more operational tasks?
Dan Bird: Security teams will spend far less time manually processing large volumes of individual alerts. Instead, their focus will shift towards determining which risks genuinely require action. AI can handle much of the repetitive technical work, while human experts concentrate on evaluation, exceptions and the business implications of security decisions.
Even performance measurement will change. Applying a patch or closing a ticket only shows that a task has been completed. It does not demonstrate that the underlying risk has actually been removed. In the future, the central question will be: did this action genuinely make the organisation harder to attack? AI and automation make it possible to answer that question continuously and far more frequently.
it-sa 365: If we discuss AI versus AI again in five years, will AI primarily benefit attackers or defenders?
Dan Bird: I am convinced that defenders can ultimately gain the upper hand, provided they adopt AI as consistently as attackers do. If attackers use AI to identify vulnerabilities, develop exploits and pursue attack paths at machine speed, defenders cannot respond with security processes that remain largely dependent on human speed. Autonomous attacks must be met with equally autonomous defence.
However, simply adding AI to existing security workflows will not be enough. Success will depend on using AI to continuously determine which vulnerabilities are genuinely exploitable, focusing resources on the risks that matter most and proving that those risks have actually been eliminated.
This creates a continuous cycle of learning and improvement that allows defenders to operate at machine speed as well. In five years’ time, the decisive factor will not be who possesses the most powerful AI, but who has built the most effective security model around it.
The arms race between attacker and defender AI is also a central theme of the it-sa Expo&Congress 2026, Europe’s leading trade fair for IT security: from 27 to 29 October 2026, experts from research, operations and regulation will meet in Nuremberg to discuss how AI can be used securely, controllably and in compliance with regulations in cyber defence.
Secure your ticket now and join us!
Interview conducted by Nicole Wörner.
Author biography:
Dan Bird is Field Chief Technology Officer (EMEA) at Horizon3. He brings decades of experience from the UK Ministry of Defence, where he led large-scale technology programmes, supported national crisis response initiatives and contributed to defence innovation. At Horizon3, he works with organisations across the EMEA region to strengthen resilience against increasingly sophisticated cyber threats.
