TL;DR:
Frontier AI does not fundamentally rewrite cybersecurity. Traditional cybersecurity principles and controls have not become irrelevant, but they remain as important as ever.
The important question, is not whether AI changes everything. It is where, by how much, and under what conditions. Frontier AI changes the operating tempo, economics, and potentially the scale of cyber operations. At the same time, when AI systems become actors inside enterprise environments, they expand the security boundary, and force us to rethink what constitutes a normal behavior, appropriate authority and anomalous activity. The article explores these dimensions, primarily from the defender's perspective. It also examines the growing set of AI-driven cybersecurity solutions emerging in the market. Rather than assuming that these solutions will solve the problem, the article uses them as a starting point to surface some open questions about how cybersecurity should operate when frontier AI enters the loop.
Frontier AI is impacting cybersecurity in both directions: Offense and Defense. On the offensive side, attackers are already using AI to accelerate activities such as reconnaissance, social engineering, malware generation, and vulnerability research[1]. The significance of frontier AI is not that it suddenly enables entirely new attack categories, but it reduces the time, effort, and expertise required to perform parts of existing cyber kill chain. Further, recent evaluations and real world incidents reported by UK AISI[2] and OpenAI[3] indicates that frontier AI models are increasingly capable of carrying out multi-step cyber operations. While fully autonomous end-to-end attacks are not yet routine, the trajectory is increasingly plausible for this to happen in near future. Recently, OpenAI have announced that their latest model Astra meets Critical cybersecurity capability threshold under their Preparedness Framework, and existing benchmarks are saturating[4]. On the defensive side, AI is increasingly being embedded into cybersecurity operations to accelerate threat detection, alert triage, incident investigation, etc. AI-native SOC and agentic security solutions are already emerging, and established players are incorporating AI in their workflows to stay relevant. This creates an interesting symmetry. The same underlying advances in AI that can help attacker to analyse a target can help defender to analyse its cyber posture, investigate, and mitigate attacks.
But there is an important distinction between adding AI to cybersecurity, and changing how cybersecurity operates because of AI. It is important to understand where AI changes the operating characteristics of cybersecurity, and where putting an AI system inside the loop creates a new security boundary altogether.
Let us assume that an attacker want to compromise an organisation. They still need some combinations of: an initial access path; an exploitable vulnerability; a way to execute code; lateral movement; confidential information access; and eventually some mechanism for data exfiltration. The vocab may update, but underlying principle remain same. A phishing email generated by an LLM is still phishing. A vulnerability discovered by AI model is still a vulnerability. An attacker who shall use agents to move through enterprise still needs the permissions, network reachability, and system interfaces that make the movement possible.
The cybersecurity community has spent decades developing controls around identity, privilege, network boundaries, role based access, etc. Those controls do not become obsolete because LLM is involved. Strategies like defense-in-depth, zero-trust are highly relevant in this age. Existing enterprise cybersecurity, risk management, frameworks and standards such as NIST Cybersecurity Framework (CSF) 2.0[5], ISO/IEC 27001, CIS controls[6], and MITRE ATT&CK[7] remain directly applicable to enterprise environments.
The important point is not that these principles have limited applicability. It is that the entities to which they must now be applied are expanding.
An attacker traditionally has a human bottleneck. Someone has to understand the target; find relevant information, generate malicious payloads, troubleshoot failures, execute, and do this repeatedly. A capable model can assist with most of the steps. Tasks that previously required skilled human operators can increasingly be delegated to models, allowing attackers to run more reconnaissance, vulnerability discovery, social engineering, and malware development etc. in parallel. Running these attacks is also getting cheaper, not harder[8]. While there are current limitations of these models in attack scenarios such as processing time, multi-step execution challenges, inconsistent results, soon these bottlenecks may get addressed with continous advancements.
AI may initially matter less in area for inventing new attack techniques, and more because it lowers the expertise, time, and effort required to execute existing techniques.
At the same time, AI introduces something that conventional cybersecurity didn't have to deal with at this scale: the AI system itself becomes part of the attack surface. Once an organisation deploys AI into business workflows, security boundaries no longer exist only around applications, endpoints, networks and identities. An enterprise AI system is not just a model, and can't be seen in isolation. It is interconnected system involving models, prompts or instructions, user inputs, skills, retrieval systems, tools, APIs, plugins, external services, agent memory, etc. Each interaction creates another boundary across which data, and trust can flow. This becomes particularly significant when AI is embedded into cybersecurity systems themselves. AI may increasingly sit inside a SOC analysing alerts, querying threat intelligence, investigating incidents, generating detections, interacting with security tools, or recommending and even executing remediation. This means defenders are not only using AI to defend the enterprise; they are also introducing AI into the machinery responsible for defending it.
This broader view is increasingly reflected in emerging AI-security guidance. Frameworks such as NIST AI Risk Management Framework[9], OWASP GenAI Security Project[10], MITRE ATLAS[11], and emerging AI-specific cybersecurity guidance from organisations such as UK AI Security Institute are beginning to address these risks at the system and lifecycle level.
These efforts complement, rather than replace, conventional cybersecurity frameworks: the challenge is increasingly to understand how existing security principles apply when models, data, agents and AI-enabled workflows become part of the enterprise environment.
The cybersecurity market is responding to the AI shift, but it is important to distinguish genuine capability changes from terminology shifts. Security Operations Centre (SOC) solutions exist in the market for enterprise defense, and AI/ ML is not new to these solutions. Products such as Endpoint Detection and Response (EDR)/ XDR, Security Information and Event Management (SIEM), Security Orchestration, Automation, and Response (SOAR) have been using ML, behavioral analytics, anomaly detection, automation for years. What is changing now is increasing use of Gen AI and agentic AI capabilities with the advent of these frontier AI models. The underlying utility of these models is real: an AI system capable of investigating an alert, gather context, reasons across data sources, recommend and execute actions. But the label "AI SOC" should not itself be treated as evidence of fundamentally new capability. Security vendors are increasingly using terms as AI SOC, Agentic SOC, or autonomous SOC to describe products that range from existing security platforms with AI assistant to systems capable of more autonomous operations. The useful question is not whether a product uses AI, but what AI actually do, what level of autonomy it has, what data and systems it can access, and whether it produces measurable improvements in security operations. Within this market, established vendors have a structural advantage as they have deep integrations with security telemetry, endpoints, identities, networks, etc. This gives them ability to connect AI reasoning with real data points. At the same time, a different class of AI SOC companies have emerged which operates as outer layer rather than replacing underlying security stack. AI agents sitting on top of existing solution infrastructure is different from AI system that fundamentally changes how telemetry is analysed, investigated and acted upon. The market will likely contain both for few years atleast.
A second layer is emerging from the frontier AI labs themselves. Their models are surely enabler for AI SOC vendors. However, there are indications of these companies entering the cyber space directly in near future. Improvements in general capabilities in frontier models such as coding, reasoning, planning, tool use and long-horizon task execution are transferring well into cybersecurity tasks. Now, we see both OpenAI and Anthropic treating cyber as important area with programs like Daybreak[12] and Glasswing[13] announced. Anthropic's Claude Code Security solution[14], and OpenAI's codex security[15] are examples of their cybersecurity offerings for code security and vulnerability discovery area.
There is also another market direction that deals with very important area: securing AI itself. As organisations deploy models and agents into business and security workflows, the security boundary expands beyond the model to include prompts and instructions, retrieval systems, data sources, tools, APIs, identities, permissions, memory and surrounding infrastructure. This creates demand for capabilities such as AI interaction monitoring, agent security, identity and privilege controls, protection of model and retrieval pipelines, and detection of attacks against AI-enabled workflows. Solutions such as AI Detection and Response (AIDR) are being promoted. Whether AIDR becomes a durable standalone category or is eventually absorbed into existing SIEM, XDR, AI SOC platforms is still uncertain. The important development is that organisations are beginning to treat AI systems themselves as security-relevant infrastructure, rather than merely as another application of AI-enabled detection.
Taken together, the market is therefore developing along several interacting layers. Cybersecurity products are using AI; increasingly capable general-purpose and cyber-specific models are providing cybersecurity intelligence; AI-native companies are building new operational workflows around those capabilities; and a new security layer is emerging to protect AI systems themselves. These layers may probably converge over time, but it is too early to know exactly where the boundaries will settle.
Frontier AI is likely to accelerate both cyber attacks and defense, but it doesn't invalidate the core principles of cybersecurity. Identity and Access Management, Role based access control, least privilege, network segmentation, zero trust, multi-factor authentication, logging, and threat monitoring, etc. remain fundamental. Defenders should absolutely use AI, but AI should complement rather than replace these controls. Recent incident of UK AISI is a useful reminder that existing controls and human oversight can still limit the impact of capable AI systems.
At the same time, the security boundary has expanded. The model, its data and context, memory, tools, model supply chain, inference infrastructure, identities, and surrounding applications all form part of the environment that needs to be secured. A capable model with tightly bounded permissions may have limited impact, while a less capable model connected to sensitive data and powerful tools can create significant risk. Cyber ranges and realistic evaluations will therefore become increasingly important for testing both AI offensive capabilities and AI-driven defenses under conditions that better resemble real environments.
The growing AI-security market should also be viewed with some skepticism. AI SOC, autonomous triage, agentic security, and similar terminology does not by itself tell us whether a solution improves security. We should evaluate impact rather than terminology: What problem does it solve? What does it improve over existing approaches? What permissions and autonomy does it require? What happens when it is wrong or manipulated? And does it improve outcomes enough to justify its cost and additional attack surface? The AI hype cycle should not distract organizations from basic security investments that may still provide greater value.
This leaves several open questions: How should security budgets balance AI-driven capabilities against traditional controls? How much autonomy should security agents receive? How should we define identity, least privilege, and normal behavior for AI agents? And what assumptions about attacker capability or defensive advantage need to be challenged as frontier models improve? We may not have definitive answers yet. But as frontier AI capabilities and AI infrastructure continue to advance, the safer approach is to adopt the technology while keeping security-first principles at the center.
Use AI. Secure the AI. Secure the environment around the AI. And do not let the excitement around AI become an excuse to neglect basic cybersecurity.