Express Computer
Home  »  Guest Blogs  »  How AI is rewriting the cyber resilience playbook

How AI is rewriting the cyber resilience playbook

0 14

By Bikash Barai, Founder & CEO, FireCompass

In July 2026, OpenAI disclosed that its AI models had exploited a zero-day vulnerability to escape an isolated evaluation environment, reached the open internet and broke into Hugging Face’s production systems autonomously. Days later, Anthropic disclosed three cases where its Claude models had gained unauthorised access to the systems of real organisations during evaluations.

Both companies disclosed these incidents themselves, and that detail matters. Even the labs building frontier AI could not fully contain their own agents and discovered the problem only because they were looking for it.

For years, cyber resilience followed a familiar model: prevent, respond and recover. AI breaks that model. It compresses the time between discovery, exploitation and impact, while also giving defenders new ways to observe, test and respond continuously. Resilience must now adapt while attacks are still evolving.

AI as a Force Multiplier: for Attackers and Defenders
AI does not need to invent new attacks to transform cybersecurity. Its biggest impact is the industrialisation of existing techniques: researching targets, generating convincing social-engineering messages, testing multiple attack paths and adapting based on the response.

Sophistication that was once scarce and expensive can now be delivered at machine speed and industrial scale. Less-skilled attackers gain access to advanced capabilities, while experienced attackers can multiply their reach.

The pressure is also increasing from within. Around 30 to 50 per cent of new enterprise code is now AI-generated, while an estimated 2.7 million cybersecurity roles remain unfilled globally. Organisations built around periodic assessments and manually coordinated responses are structurally too slow against attacks that continuously learn and adapt.

Resilience Against AI: Defending at Machine Speed
The same force multiplication is available to defenders. AI can correlate weak signals, assist investigations, simulate attacker behaviour and test whether a weakness is genuinely exploitable.

The advantage will not necessarily go to the side with the more powerful model. It will go to the side that embeds AI into a better operating model with strong data, clear objectives, guardrails, feedback loops and the authority to act quickly.

Machine-speed defence does not mean removing humans. It means automating areas where delay creates risk, while preserving human judgement for high-impact decisions.

AI also creates a new category of risk, one that the OpenAI and Anthropic incidents make clear. Agents can read sensitive data, generate code, call APIs, use credentials and take actions across multiple systems. A compromised or manipulated agent is not merely another vulnerable application. It can become an active participant in an attack.

Governing AI is therefore no longer only a compliance exercise. It is now a core resilience function.

Three Shifts in Cyber Resilience

First, identity controls must extend to AI agents. Every agent should have a defined purpose, minimum necessary access and clear limits on what it can do independently.

Second, organisations must protect the complete AI decision chain, not just the model, but also the data, prompts, memory, tools, integrations and downstream actions.

Third, containment must become faster and more automated. Human-speed response is inadequate when an attack can explore several paths simultaneously.

Recovery changes too. Earlier, recovery meant restoring systems and data. Leaders must now also ask whether data was poisoned, instructions were altered, memory was compromised and whether automated decisions can still be trusted.

Resilience Using AI: From Periodic Assurance to Continuous Adaptation
Traditional resilience programmes are periodic: audits, penetration tests and drills conducted at scheduled intervals. They are valuable, but they provide snapshots.

AI enables a continuous resilience loop: discover what has changed, test whether controls still work, validate which exposures are genuinely exploitable, contain high-risk activity and learn from the outcome.

The result is not another vulnerability list. It is evidence of whether a real attacker can reach a critical business system.

When elite offensive capability costs less than a single hire, continuous validation stops being a luxury. It becomes the baseline, one component of a broader system covering detection, containment, recovery and business continuity.

A Cyber-Resilience Agenda for Leaders
Move from annual readiness to continuous validation. Extend Zero Trust principles to AI agents. Build machine-speed containment with human oversight. Measure resilience through business outcomes—the time required to identify a viable attack path, contain it, restore critical operations and re-establish trust.

In the AI era, resilience will be defined by an organisation’s ability to sense change, absorb disruption and adapt faster than the attacker.

The question is no longer whether you will be tested by AI. It is whether the first AI to test you will be yours or theirs.

Leave A Reply

Your email address will not be published.