AI vs AI cyber battle is taking root as frontier models reshape enterprise defence

AI vs AI cyber battle is taking root as frontier models reshape enterprise defence

Speed, resilience and human judgement are becoming vital as attackers leverage the same AI capabilities as defenders.

By on

Artificial intelligence is now transforming cybersecurity into an AI-versus-AI contest, where both attackers and defenders are increasingly using sophisticated models to gain the upper hand. As frontier AI models help to discover new vulnerabilities at the same time, they are also generating new exploits. To stay ahead, enterprises must move from simply adding more security tools or expanding security teams.

Sharing his insights on this ongoing AI tussle with iTNews Asia, Paul Tan, Executive Vice President at Ensign InfoSecurity, said the organisations that succeed will likely be those that combine AI with human expertise to respond faster than their adversaries.

"The reality is that we are now entering an AI-versus-AI environment. It is not a choice, you have to use it, but it is available to both the defenders as well as the attackers," he said.

Tan pointed out that the cyber security landscape has long been an asymmetric battle where attackers need only exploit a single weakness, while defenders have the onerous task of securing every potential entry point. While AI has supported cyber analytics and detection for years, he said the latest generation of frontier models has further and dramatically accelerated both the speed and sophistication of attacks.

Following Ensign's own testing of both Western and Chinese frontier models, Tan said the company found they could rapidly identify weaknesses and chain together exploits with minimal resources, reducing both the cost and expertise required for cyberattacks.

"The cost of conducting such attacks will certainly be cheaper. We do expect that the volume of such attacks will increase significantly," he warned.

Defenders still have an edge if they use AI differently

While attackers are moving quickly, Tan argues defenders are not without advantages.

Unlike threat actors, enterprises possess deep knowledge of their own environments, systems and configurations. When combined with AI, that institutional knowledge enables organisations to detect subtle behavioural anomalies that external attackers cannot easily anticipate.

However, defenders also face constraints that attackers do not.

The advantage will go to whichever side can operate better and faster. Defenders have enterprise-wide considerations about business availability, audit considerations and change requests. Attackers have no such considerations.

- Paul Tan, Executive Vice President at Ensign InfoSecurity

Security operations need to evolve, not be rebuilt

The emergence of AI-driven attacks is forcing organisations to rethink how SOCs operate.

Traditional SOCs rely on predefined playbooks that prescribe fixed responses to known alerts. Agentic AI, however, can analyse multiple sources of information, formulate hypotheses and recommend response actions based on context rather than static rules.

For Tan, this represents an evolution of the operating model rather than a replacement of existing security investments. He believes enterprises should stop evaluating cybersecurity investments based on the number of tools deployed or the size of security teams. Instead, organisations should measure security through operational outcomes including the time to detect, contain and recover.

"We don't need to throw away previous investments," he advised. Instead, organisations should gradually layer AI capabilities onto existing security architectures while modernising workflows and response procedures.

Rather than evaluating SOC effectiveness through analyst headcount, event volumes or the number of deployed tools, Tan recommends that organisations focus on operational outcomes such as time to detect, time to contain and time to recover.

Human judgement is still more valuable

Despite rapid advances in automation, Tan believes AI will complement rather than replace cybersecurity professionals. Agentic systems can investigate incidents, correlate evidence and recommend actions, but they still lack the contextual understanding required for critical operational and ethical decisions.

Tan also warned that AI models themselves also introduce new risks. Guardrails based purely on prompts remain insufficient, he cautioned, while AI systems can also become biased or manipulated over time.

He expects future cybersecurity practitioners to move beyond routine alert triage towards higher-value work such as threat hunting, incident response, AI governance and response strategy. "Every cybersecurity practitioner will need to have the AI skill sets. They will need to be part investigator, part supervisor and part quality controller."

Be prepared for the next phase of AI-driven attacks

Given the speed of AI-driven attacks, Tan believes organisations should increasingly assume that breaches will occur. Taking an "assumed breach" position represents a more mature security posture, he said.

Many incident response playbooks still assume humans manually investigate alerts before action is taken, assumptions that may no longer hold in AI-driven environments. "If organisations start thinking about these issues after an incident has happened, it will already be too late," he warned.

Looking ahead, Tan expects powerful frontier models to become widely accessible within months rather than years, enabling more threat actors to automate vulnerability discovery and exploit development. That makes foundational cyber hygiene more important than ever.

Organisations need to accelerate patching of internet-facing systems, gain better visibility of critical assets and modernise incident response playbooks. Equally important is developing AI literacy across cybersecurity teams so analysts can understand, challenge and validate AI-generated recommendations.

Ultimately, Tan believes the winners in cybersecurity's next chapter will not simply be those with the most advanced AI, but those that combine automation with human judgement most effectively.

"AI changes the weightage of people, process and technology, but the fundamental principles remain the same," he added.

To reach the editorial team on your feedback, story ideas and pitches, contact them here.
© iTnews Asia
Tags:

Most Read Articles