For years, cybersecurity has operated at human speed.

Security teams manually reviewed code. Penetration testers searched for weaknesses. Vulnerabilities were discovered slowly, often after systems had already been deployed into production.

That model is rapidly becoming obsolete.

A new generation of AI systems is now capable of identifying vulnerabilities at a scale and speed previously impossible for human teams alone. And the implications for governments, critical infrastructure, and public trust are profound.

This is no longer a future problem.

It is happening now.

The Firefox moment that should alarm policymakers

In April 2026, Mozilla revealed that Anthropic’s advanced AI model, Claude Mythos Preview, helped identify and fix 271 security vulnerabilities in Firefox 150 during an early evaluation. Some vulnerabilities had reportedly existed undetected for years. [The Zero days are numbered]

Mozilla described the results as transformative. Previous AI systems often produced noisy or low-quality outputs. Mythos was different. It could analyse broad codebases, reason across systems, and uncover deeply hidden flaws that traditional methods had missed. [Mozilla says Anthropic's Mythos Preview and other AI models helped it identify and ship 423 Firefox security bug fixes in just one month]

This matters because many of these vulnerabilities were effectively zero-day vulnerabilities: flaws unknown to developers and security teams before discovery.

Historically, finding zero-days required elite human expertise and significant time.

Now AI can do it continuously.

That changes the equation entirely.

AI is now both the attacker and the defender

At the same time Anthropic was limiting access to Mythos because of safety concerns, OpenAI launched its own cybersecurity initiative, Daybreak, alongside specialised defensive cyber models such as GPT-5.4-Cyber. [Trusted access for the next era of cyber defense]

The purpose is clear:

  • automate vulnerability detection
  • accelerate patching
  • assist defenders operating at machine speed

OpenAI describes these systems as tools to help security teams find and fix weaknesses before adversaries exploit them.

This is the beginning of an AI-vs-AI cybersecurity landscape.

On one side:

  • AI systems discovering vulnerabilities
  • generating exploit pathways
  • scaling attacks

On the other:

  • AI systems defending infrastructure
  • validating fixes
  • monitoring threats continuously

The organisations that fail to adopt AI defensively may soon find themselves competing against machine-speed adversaries using human-speed processes.

That is not a sustainable position.

Governments are uniquely vulnerable

This shift presents a particular challenge for governments.

Public sector systems often contain:

  • identity records
  • financial information
  • health data
  • infrastructure controls
  • classified operational systems

Many also rely on ageing legacy infrastructure never designed for an environment where vulnerabilities could be discovered automatically at scale.

At the same time, governments frequently face:

  • slow procurement cycles
  • fragmented governance
  • siloed data environments
  • limited AI capability uplift
  • high barriers to technological change

This creates a dangerous asymmetry.

While adversaries accelerate using frontier AI systems, many public institutions are still relying on periodic audits, manual testing, and reactive security models.

The gap between attacker capability and defender capability is widening rapidly.

The governance dilemma

The answer is not reckless AI adoption.

Governments must balance:

  • security acceleration
  • data governance
  • privacy obligations
  • model oversight
  • sovereign risk management

But caution cannot become paralysis.

The same technologies capable of introducing risk may also become essential defensive infrastructure.

This means governments should urgently explore:

  • AI-assisted vulnerability detection
  • continuous security monitoring
  • secure sovereign AI environments
  • modernised cyber governance frameworks
  • workforce capability uplift in AI-enabled security operations

Because the uncomfortable reality is this:

If frontier AI systems can already identify vulnerabilities that human teams missed for years, then adversaries will inevitably gain access to similar capabilities.

Some already have.

The narrowing window

Anthropic itself warned there may only be a limited window before comparable capabilities become widely available. [Anthropic’s Mythos found thousands of zero-day vulnerabilities. The Fed chair called the banks.]

That warning should not be ignored.

Cybersecurity is no longer simply about protecting systems from human attackers.

It is increasingly about whether institutions can defend themselves in a world where machines autonomously discover weaknesses faster than organisations can respond.

The question governments should now be asking is not:

“Should we adopt AI in cybersecurity?”

It is:

“How quickly can we do it responsibly before our adversaries move faster than we can?”

Because in this new era, the greatest risk may not be adopting AI too quickly.

It may be adopting it too slowly.


Make sure to share your own thoughts with the author by leaving a comment below