Artificial intelligence is fundamentally changing the economics and speed of cyber risk, lowering the cost, skill, and time required to find vulnerabilities, build attacks, and operate them at scale. At the same time, the same technology is strengthening cyber defence through faster detection, sharper prioritisation and improved fraud response, according to the report Mastercard Resilience at Machine Speed.
As AI compresses the attack cycle, the report highlights that the critical advantage for organisations is increasingly their ability to turn visibility into action before risk spreads.
The shift is already visible across the cybersecurity landscape. Frontier models are now up to 90 times faster at finding zero-day vulnerabilities than previous-generation models. At the same time, AI is strengthening the defence cycle: the patch window for the highest-risk, actively exploited vulnerabilities has reduced from 14 days to three; AI can now identify up to 86% of AI-planted vulnerabilities, up from 37%; and embedding AI into decisioning has improved scam and impersonation detection by up to 300%.
However, faster technology alone does not automatically create resilience. Remediation, governance, ownership, and recovery still depend on operational execution, human oversight, and clear accountability. The report highlights that organisations need to pair AI-enabled defence with stronger governance, cross-functional coordination and rehearsed recovery capabilities.
The report also identifies a growing convergence between cyber and fraud, driven by the manipulation of trust. Deepfakes, voice cloning, synthetic identities and executive impersonation are putting increasing pressure on onboarding, authentication, account recovery and payment authorisation. Organisations can incur losses even when payment rails and monitoring systems operate as intended if they incorrectly trust a customer, employee, or third party.
For India, this is particularly significant given the scale and interconnectedness of the country’s digital ecosystem. CERT-In handled roughly 2.9 million incidents in 2025, a 44% year-on-year increase, while RBI-reported fraud crossed approximately ₹360 billion in FY2025. Mastercard’s Cyber Insights also found that observed cyber activity is concentrated across the Technology, Public and Financial sectors.
This convergence is also exposing gaps between organisational functions. Cyber, fraud, risk and operations can continue to work through separate tools, workflows and reporting structures, creating gaps that AI-enabled deception can exploit. The report highlights the need for closer integration across these functions to detect and respond to emerging risks more effectively.
As organisations respond to this changing threat landscape, Mastercard’s research identifies three priorities for leaders: defend at machine speed, build resilience beyond prevention, and strengthen governance around live decisions and accountability. This means using AI to detect, prioritise and respond faster, while designing for containment, recovery, third-party disruption and business continuity.
The report reinforces that AI can become a stronger defence capability, but its impact ultimately depends on how effectively organisations execute against the risks they identify.
As AI continues to accelerate both attack and defence, the ability to maintain digital trust will increasingly depend on how quickly organisations can detect risk, make informed decisions, contain disruption and recover.