AI Academy · Book
Executives & Directors · Module 05 · Chapter 010

AI in Cybersecurity

Attackers already use AI, mostly to do familiar things faster and at greater scale. Defenders can use it the same way: to turn a flood of signals into faster, better decisions. The value lies in risk removed rather than alerts cleared, and some of the strongest defenses against AI-powered fraud are plain process controls.

≈ 17 min read

After this chapter you can

  • Explain how attackers already use AI, mostly to scale and speed up known techniques.
  • Distinguish an anomaly from a confirmed attack, and name both kinds of detection error.
  • Rank vulnerabilities by likelihood of exploitation and business criticality, not generic severity.
  • Decide which security actions AI may take alone and which need human approval.
  • Judge security AI by risk removed, and name the monitoring and incident-reporting duties it touches.
  • Use process controls such as out-of-band callbacks against deepfake fraud, as the Arup case shows.

In mid-September 2025, the security team at the AI company Anthropic noticed a pattern of activity on its own platform that did not look like ordinary use. Over the next ten days it pieced together what was happening. A group that Anthropic assessed with high confidence to be Chinese and state-sponsored had broken a hacking campaign into small, innocent-looking tasks and handed them to an AI coding agent, telling it that it worked for a legitimate security firm. The agent probed about thirty organizations: technology companies, financial institutions, chemical manufacturers and government agencies. By Anthropic’s estimate the AI did 80 to 90 percent of the work, with humans stepping in at only four to six decision points per campaign. At its peak the agent made thousands of requests, often several per second. A small number of the intrusions succeeded1.

The report contained a second detail that is easy to miss. The agent made mistakes. It sometimes claimed to have stolen credentials that did not work, and presented public information as if it were a secret find. Speed and scale had arrived; perfect judgment had not.

Those two facts describe AI in cybersecurity on both sides of the contest. Attackers are not waiting for the technology to mature. They are already using it to do what they have always done, faster and on more targets at once. Defenders can use it to do the same: to read more signals, connect them sooner and act within minutes rather than days. Neither side has a machine that is always right, so for an executive the question is where AI shortens the path from signal to sound decision, and where it must not be allowed to act alone.

Better decisions, not more alarms

Security leaders have a common vocabulary for their work, and one of the most widely used is the US National Institute of Standards and Technology’s Cybersecurity Framework. Its 2024 revision organizes security into six functions. Five of them form an operating loop: identify what you have and what threatens it, protect it, detect when something goes wrong, respond, and recover. The sixth, govern, was added in that revision and sits above the others: it sets the risk appetite, the roles and the rules2.

The NIST Cybersecurity Framework 2.0 loop - identify, protect, detect, respond, recover - with govern at the center; AI helps at each step within limits set by governance.IdentifyKnow assetsand exposureProtectFix whatmatters firstDetectFind the real signalRespondContain within limitsRecoverRestore and learnGovernRisk appetite, roles, rules
Figure 5.10.1 AI can speed up every step of the security loop. Governance decides what it may do alone.

AI can help at every point on that loop. It can keep the inventory of systems current, rank weaknesses by how likely they are to be used, sift telemetry for the few events that matter, draft the incident timeline and recommend containment. These are capabilities; the outcome evidence later in this chapter comes from a breach-cost survey and a competition, not from controlled tests in production. It can also hurt at two points: by suppressing a signal that mattered at detection, or by taking a heavy action on a false alarm at response. The useful executive question is therefore narrower than “where can we use AI in security?” It is: which step in our loop is the bottleneck, and what may AI do there without a person?

Attackers use AI mostly to go faster

The evidence on attackers is now broad enough to describe with some confidence. IBM’s 2026 study of 602 breached organizations found that one in four malicious breaches was AI-enabled, through means such as deepfake impersonation and AI-assisted malware, and that those breaches cost an average of 6 million dollars, about a million more than the global average of 4.99 million across all breaches3.

One in four malicious breaches was AI-enabled and cost about 6 million on average, while extensive defensive use of AI and automation saved almost 2 million per breach.1 in 4Malicious breachesAI-enabledDeepfakes, AI-assisted malware6MAverage cost ofthose breachesUSD; global average 4.99M~2MLower cost per breachExtensive security AI users;an associationSource: IBM Cost of a Data Breach 2026 · 2026
Figure 5.10.2 The same study shows both sides: AI-enabled breaches cost more, and extensive defensive AI goes with cheaper breaches.

What attackers do with AI matters as much as how often. Verizon’s 2026 breach report, which drew in part on data from AI providers’ misuse investigations, found that the median threat actor used AI assistance in fifteen different documented techniques, from choosing targets to writing malware. Yet fewer than 2.5 percent of AI-assisted malware observations involved techniques that were not already well known4. AI is mostly a force multiplier for familiar attacks, not a source of new ones.

Fraud data points the same way, with a warning about measurement. The FBI’s Internet Crime Complaint Center received more than 22,000 complaints in 2025 that reported AI-related information, with losses of 893 million dollars. Business email compromise, the impersonation of executives and suppliers to redirect payments, cost 3.05 billion dollars in total, but only about 30 million of that was tagged as involving AI. The two figures count different things: the 893 million covers complaints of any kind that mentioned AI, while the 3.05 billion covers all business email compromise, whether or not AI was noticed. The FBI’s own reading is that many victims do not realize how far AI was involved5. The safest assumption is that a convincing email, voice or face may now be synthetic.

That conclusion has a reassuring side. If attackers mostly use AI to run known plays faster, the known defenses still work, provided they are actually in place. How attackers turn an organization’s own AI assistants against it, through hidden instructions and poisoned content, is a different problem, and it belongs to Security and AI Attacks in Module 0667.

An anomaly is a signal, not a verdict

Much defensive security AI starts with anomaly detection. The system learns what normal looks like for each user, device and service, then flags what deviates: a login from an unusual place, a burst of file access, a server talking to an address it has never contacted. That is useful, and it is also where many programs go wrong, because an anomaly is only a deviation. It is not proof of an attack.

Consider, as an illustration, a single flag: an employee downloads an unusually large volume of files late in the evening. It could be data theft before a resignation. It could equally be a planner pulling a year of records for an audit due the next morning. The anomaly is identical; the meaning is opposite. What separates the two is context, and correlation is where AI earns its keep. One unusual login means little. An unusual login, followed within the hour by a privilege change, a new device and a large download, tells a story no single alert can. Systems that join those dots across identity, email, endpoints, network and cloud turn thousands of weak signals into a short list of incidents worth a person’s attention.

Two kinds of error follow, and an executive should ask about both. A false positive treats normal work as an attack: a locked account, a blocked shipment, an angry customer. A false negative misses a real attack, or quietly drops the alert that would have revealed it. Dashboards tend to show the first because it is visible. The second is the one that ends up in the incident report.

Insider-risk monitoring sharpens the point, because the signals are about people. Watching employees’ behavior closely enough to spot data theft is processing of personal data that usually needs a formal impact assessment in Europe, and often the agreement of a works council, before it starts. The legal anchors appear in the box on monitoring and reporting duties below.

Fix what attackers will actually use

The same logic, ranking by meaning rather than by volume, applies to the weaknesses in an organization’s own systems. In 2025, 48,185 new software vulnerabilities were published, about 132 a day and a fifth more than the year before8. No team patches that many. Yet only about 6 percent of published vulnerabilities have ever been seen exploited in the wild, and ranking by the predicted likelihood of exploitation achieves the same risk coverage as fixing every flaw with a high generic severity score, for about one-sixth of the effort9.

Exploited vulnerabilities started 31 percent of breaches, yet only 26 percent of known-exploited flaws were fully fixed in 2025, with a median of 43 days to fix.31%Breaches that began withan exploited flawNow the most common way in26%Known-exploited flawsfully fixedIn 2025, down from 38%43 daysMedian time to fixUp from 32Source: Verizon DBIR 2026 · 2026
Figure 5.10.3 Attackers increasingly walk in through known holes, and organizations are closing them more slowly.

The order matters more each year. Exploiting a vulnerability is now the most common way attackers get in, ahead of stolen credentials. Yet in 2025 organizations fully fixed only about a quarter of the flaws already on the US government’s list of vulnerabilities known to be exploited, and the median fix took 43 days4.

A two-by-two of exploitation likelihood against business criticality; likely-to-be-exploited flaws on critical systems are fixed first.HighLowBusinesscriticalityLowLikelihood of exploitation · HighHarden and watchCritical but unlikely targetFix nowLikely to be used on what mattersBatchRoutine maintenanceContainLikely target with little at stake
Figure 5.10.4 Rank weaknesses by how likely they are to be used and what they would expose, not by a generic severity score.

AI helps here because the ranking has to combine sources no person can merge daily: the scanner’s findings, the asset inventory, threat intelligence about what is being exploited this week, and the business’s own view of which systems carry revenue, safety or customer data. The re-sorted list changes as conditions change. The executive decision is to fund the inventory and the business context, because without them the AI is sorting a list it does not understand.

Defenders’ AI can shorten the loop

The business evidence on the defensive side is encouraging, though it is an association from a survey, not a controlled test. In IBM’s 2026 study, breaches at organizations that used security AI and automation extensively cost an average of 1.93 million dollars less3. The gains come from the same places the loop suggests: faster identification, faster containment and less manual assembly of evidence. The technical frontier points the same way: in a public competition run by the US Defense Advanced Research Projects Agency in 2025, automated systems found and patched software flaws in minutes10. A competition is not a production environment, and a found flaw still has to be fixed, tested and shipped. But it shows that defenders’ tools can, in principle, work at attacker speed on the tasks where speed decides the outcome.

Recommending a response is not taking it

During an incident, AI can collect context, assemble a timeline and recommend containment. Suppose it concludes that a laptop is compromised and recommends isolating it from the network. Isolation is an action with consequences. Applied to one laptop it is prudent. Applied to a thousand on a false alarm, it stops the business as surely as the attacker would have.

Bounded, high-confidence, reversible security actions can run automatically with oversight; broad or hard-to-reverse ones stay recommendations until a person approves.Bounded,confident andeasy to undo?YesYes - reversibleNarrowAI acts; people monitor andcan reverseNoNo - broad or lastingBroadAI recommends; aprofessional approves
Figure 5.10.5 Set the line between acting and recommending by blast radius and reversibility, before the incident.

Every organization therefore decides three things separately: when AI may recommend, when it may act, and when a person must approve. Tightly bounded, high-confidence and reversible actions can run automatically with monitoring and a human override: blocking a domain already confirmed as malicious, isolating one device the evidence clearly shows is compromised, forcing a reset on credentials known to be stolen. Broad, lasting or customer-visible actions, such as locking out many accounts, shutting a production system or cutting a network segment, stay recommendations until a security professional approves. Where that line sits is a statement of risk appetite, and it belongs to the govern function at the center of the loop. The general case for matching autonomy to consequence is made in Agentic AI and Autonomous Actions in Module 06. The security case adds one twist: an AI agent that can isolate devices and reset credentials is itself among the most privileged systems in the building, and it needs the narrowest rights that let it do its job.

Measure the risk removed, not the alerts cleared

A common failure in security AI is a measurement failure. Workload metrics are easy to collect and pleasant to report: alerts closed, share of triage automated, analyst hours saved. Risk metrics are harder: how long attackers stay undetected, how fast incidents are contained, how many past attacks the system catches when real incidents are replayed against it, and how the exposure of critical systems is changing.

Workload metrics such as alerts closed are easy to report; risk metrics such as time to detect and contain show whether security AI reduced risk.Workload metricsAlerts closedShare of triage automatedAnalyst hours savedRisk metricsTime to detect and containPast attacks caught on replayExposure on critical systemsReport both error types next to any time saved.
Figure 5.10.6 Workload metrics say the team is busier or calmer. Risk metrics say whether the organization is safer.

A triage assistant that cuts the alerts needing human review by more than half looks like a win. If it has been quietly discarding one class of alert that mattered, workload goes down and risk goes up, and nothing on the dashboard shows it, because nothing on the dashboard measured detection. The remedy is cheap if it is designed in from the start: test the system against a library of past real incidents before it may suppress anything, report false negatives alongside false positives, and decide in advance where freed analyst time goes, whether threat hunting, security engineering or resilience testing. The goal is a safer organization, not automatically a smaller team.

Speed of detection has a legal edge as well. Several laws now start a clock when a significant incident occurs, and an organization that takes weeks to understand what happened cannot meet a 24-hour or four-day deadline. The lifecycle of an AI incident, and who decides when a clock has started, is the subject of Human Oversight and AI Incidents in Module 06.

Story: the video call that cost 25 million

Early in 2024 a finance employee in the Hong Kong office of Arup, the British design and engineering firm behind the Sydney Opera House, received a message that appeared to come from the company’s chief financial officer in the United Kingdom. It asked for a secret transaction. The employee suspected a phishing email, which was exactly the right instinct11.

Then came a video call. The chief financial officer was on it, along with other colleagues the employee recognized. They looked right and sounded right. According to Hong Kong police, every other person on the call was a deepfake. Reassured, the employee made fifteen transfers, a total of 200 million Hong Kong dollars, about 25.6 million US dollars12. The fraud came to light only when the employee later checked with head office11. In May, Arup confirmed that “fake voices and images were used”, and said that none of its internal systems had been compromised13.

A deepfake video call led to fifteen transfers worth about 25.6 million US dollars, with no internal systems compromised.15TransfersAfter one video call~25.6MUS dollars paid out200 million Hong Kong dollars0Systems compromisedThe payment process wasthe targetSource: Fortune, citing Arup and Hong Kong police · 2024-05
Figure 5.10.7 No server was breached and no alert fired. The attack went through a payment process and one person’s trust.

Notice what was attacked. Not a server, not a firewall, not a password. The target was a payment process and the trust a careful person placed in familiar faces on a screen. No security tool raised an alarm, because nothing technical was broken. Arup’s chief information officer said at the time that attacks of every kind, including invoice fraud, voice spoofing on messaging apps and deepfakes, were “rising sharply” in number and sophistication13.

Out-of-band callback, two-person approval and treating secrecy as a warning would have stopped the deepfake fraud.Verify out of bandCall back on a number youalready holdTwo-person approvalSecond approver who wasnot on the callSecrecy is a warningThank people whoslow downDetection tools are one signal; the process is the control.
Figure 5.10.8 Three process controls would have stopped the transfers, whatever the attacker’s AI could fake.

What would have stopped it was not a better firewall. It was three plain controls. Any unusual payment request is confirmed out of band, by calling the requester back on a number already on file rather than one supplied in the request. Large or unusual transfers need a second approver who was not part of the conversation. And “keep this confidential and move fast” is treated as the signature of fraud, with staff thanked rather than blamed for slowing it down. Tools that detect synthetic voice and video exist and will improve, and they are worth using as one more signal. But the attacker also had AI, and needed only a process that trusted a face. A callback rule works whatever the attacker’s model can fake, and an executive can introduce it in an afternoon.

What this means for leaders

Four lessons follow. First, assume the attacker has AI now, and expect it to make familiar attacks cheaper, faster and more convincing rather than exotic. Second, fund defensive AI where your loop is slowest, usually triage, investigation and the ranking of vulnerabilities, and fund the asset inventory and business context that make its judgments meaningful. Third, write down which actions AI may take alone and which need a person, before the next incident forces the decision. Fourth, judge every security AI investment by the risk it removes, measured against real past incidents, and reinforce the human processes, such as payments, access changes and supplier bank details, that no detection tool protects.

Check yourself

  1. Attackers might start using AI once the technology matures.
  2. Most AI-assisted attacks use techniques defenders already know.
  3. An anomaly flagged by security AI is evidence of an attack.
  4. Fixing every vulnerability with a high severity score is the most efficient way to reduce risk.
  5. The Arup fraud succeeded because attackers broke into the firm’s systems.
  6. A security AI that halves analyst workload has proven its value.

Reflection: follow the money and the access

What comes next

Security AI works best when it can draw on what the organization already knows: past incidents, system owners, policies and context. Much of that knowledge exists but is scattered, out of date or impossible to find when it is needed. The next chapter, AI in Knowledge Management, looks at how AI can turn that scattered information into knowledge people can trust.

Laws referenced

General Data Protection Regulation · EU

Regulation (EU) 2016/679

Personal data is any information relating to an identified or identifiable person, directly or indirectly, including by an identifier such as an online ID (Art. 4(1)). Lawful basis and purpose limitation (Arts. 5-6); processing special-category data, including biometric data used to identify a person, health data and data revealing ethnicity, is prohibited unless a specific exception applies (Art. 9); data protection by design and by default (Art. 25); processors such as AI vendors may act only under a written contract with required terms and sufficient guarantees (Art. 28); transparency to data subjects (Arts. 13-14); right not to be subject to a decision based solely on automated processing with legal or similarly significant effects (Art. 22); breach notification to the supervisory authority within 72 hours (Art. 33) and to individuals without undue delay when the risk is high (Art. 34); data protection impact assessment for high-risk processing (Art. 35). Fines up to EUR 20 million or 4% of global turnover.

  • 2018-05-25 — Applies

Last verified 2026-10-08 · official text

Worker consultation on workplace technology · EU member states

AI Act Art. 26(7); national co-determination law, e.g. Germany BetrVG s.87(1) no. 6, Netherlands WOR art. 27

Introducing systems that can monitor or assess employees usually requires informing or obtaining the consent of works councils or employee representatives, depending on the country. Plan this before a pilot, not after.

Last verified 2026-10-06

NIS2 Directive · EU

Directive (EU) 2022/2555

Cybersecurity risk management for essential and important entities. Significant incidents: early warning within 24 hours, incident notification within 72 hours, final report within one month. Management bodies are accountable.

  • 2024-10-18 — Applies through national law

Last verified 2026-10-06 · official text

Digital Operational Resilience Act (DORA) · EU (financial sector)

Regulation (EU) 2022/2554

Banks, insurers, investment firms and other financial entities must manage ICT risk, report major ICT incidents, test their resilience and manage ICT third-party risk: keep a register of ICT service contracts, include required contract terms (exit, audit, incident support) and plan for provider failure. Critical ICT third-party providers, which can include cloud and AI service providers, fall under direct EU oversight.

  • 2025-01-17 — Applies

Last verified 2026-10-08 · official text

EU Cyber Resilience Act · EU

Regulation (EU) 2024/2847

Products with digital elements sold in the EU, including software and AI-enabled products, must meet essential cybersecurity requirements across their life: secure by design, vulnerability handling and security updates, a software bill of materials, and reporting of exploited vulnerabilities. Code written with AI assistance is covered like any other code in the product.

  • 2024-12-10 — Entered into force
  • 2026-09-11 — Manufacturers must report actively exploited vulnerabilities and severe incidents
  • 2027-12-11 — Main obligations apply

Last verified 2026-10-08 · official text

SEC cybersecurity incident disclosure · US - listed companies

Form 8-K Item 1.05 (SEC rule adopted July 2023)

Listed companies disclose a material cybersecurity incident within four business days of determining that it is material. AI-related breaches are included.

Last verified 2026-10-06

References

  1. Anthropic. Disrupting the first reported AI-orchestrated cyber espionage campaign. Anthropic. 2025.
  2. National Institute of Standards and Technology. The NIST Cybersecurity Framework (CSF) 2.0. NIST. 2024.
  3. IBM X-Force. AI-powered adversaries and the enterprise risk challenge: Preparing for the new reality. IBM Think. 2026.
  4. Verizon Business. 2026 Data Breach Investigations Report, Executive Summary. Verizon. 2026.
  5. Federal Bureau of Investigation, Internet Crime Complaint Center. 2025 IC3 Annual Report. FBI. 2026.
  6. OWASP Foundation. OWASP Top 10 for LLM Applications 2025. OWASP GenAI Security Project. 2024.
  7. National Institute of Standards and Technology. Adversarial Machine Learning: A Taxonomy and Terminology of Attacks and Mitigations, NIST AI 100-2 E2025. NIST. 2025.
  8. Jerry Gamblin. 2025 CVE Data Review. jerrygamblin.com. 2026.
  9. Cyentia Institute and FIRST. A Visual Exploration of Exploitation in the Wild. Cyentia Institute. 2024.
  10. DARPA. AI Cyber Challenge marks pivotal inflection point for cyber defense. Defense Advanced Research Projects Agency. 2025.
  11. CNN. Finance worker pays out $25 million after video call with deepfake 'chief financial officer'. CNN. 2024.
  12. Fortune. A deepfake 'CFO' tricked British design firm Arup in $25 million fraud. Fortune. 2024.
  13. CNN. Arup revealed as victim of $25 million deepfake scam involving Hong Kong employee. CNN. 2024.

Further reading

Sources last verified 2026-10-08.