What happened
Generative artificial intelligence is accelerating the shift in the balance between digital attack and defence. The article brings together warnings from several bodies and consultancies about the growing attack surface, the speed at which flaws can be exploited and the difficulty of keeping traditional controls effective.
The risks mentioned include shadow AI, autonomous agents with excessive privileges, non-human identities and poorly governed integrations. The piece also notes that AI can support defence through continuous monitoring, pattern detection and automated response, but only if there is strict governance, adaptable architectures and security by design.
It adds that the shortage of cybersecurity talent makes the problem worse and that several recent incidents involving AI models have reinforced warnings about misalignment and loss of control. Overall, the message is that AI innovation can no longer be treated separately from security, auditability and operational resilience.
Key points
- Generative AI is speeding up risks and putting traditional defences under pressure.
- ENISA and several consultancies point to new vulnerabilities and faster attacks.
- Shadow AI, autonomous agents and non-human identities expand the attack surface.
- AI can also strengthen defence if governance and security by design are in place.
- The cybersecurity talent shortage is worsening organisations’ exposure.
Why it matters for your organisation
For companies and public administrations, the central message is that adopting AI already brings operational and security risks that require immediate control. Those that do not strengthen governance, monitoring and training may be more exposed to fast-moving incidents that are hard to contain.