There is a quiet shift happening in cybersecurity.

It’s not loud. It’s not headline-grabbing in the way major breaches are.

But it is far more consequential.

Artificial intelligence is no longer just a tool in cybersecurity.

It is now both the attacker and the defender.

From human-scale security to machine-scale discovery

For decades, cybersecurity has been limited by human capacity.

Security teams run tests. Analysts review code. Vulnerabilities are discovered slowly, often under pressure, and usually after systems are already in production.

That model is breaking.

Recent research from Anthropic, in collaboration with Mozilla, showed that AI systems can identify critical vulnerabilities in widely used software like Firefox in a matter of days, not months. (Anthropic, 2025).

In broader testing, these systems uncovered over 100 issues, including high-severity flaws that could have been exploited if left undetected (The Decoder, 2025).

This is not incremental improvement.

This is a shift from human-scale security to machine-scale discovery.

Mythos and the rise of AI vulnerability hunters

Anthropic’s more advanced systems, such as the unreleased “Mythos”, take this even further.

These models are capable of identifying zero-day vulnerabilities, dramatically accelerating a process that has historically relied on highly specialised human expertise (Washington Post, 2026).

An AI model can:

  • analyse vast codebases continuously
  • identify subtle, non-obvious flaws
  • test multiple exploit pathways simultaneously

This changes the economics of cyber risk.

Vulnerability discovery is no longer scarce.

It is becoming abundant.

OpenAI and the race to defend

At the same time, OpenAI and others are moving in the opposite direction.

Their focus is on building AI systems specifically designed for defensive cybersecurity, including vulnerability detection and reverse engineering capabilities (Times of India, 2026).

The goal is clear.

If attackers can operate at machine speed, defenders must do the same.

This is the beginning of an AI vs AI security landscape.

The growing asymmetry

This creates a new and uncomfortable asymmetry.

Organisations that adopt AI for defence will:

  • identify vulnerabilities earlier
  • reduce exposure windows
  • respond faster to emerging threats

Those that do not will face adversaries with:

  • near-unlimited testing capability
  • automated exploit generation
  • continuous attack surfaces

The gap is no longer incremental.

It is exponential.

Why governments are uniquely exposed

For governments, the stakes are significantly higher.

Public sector systems store:

  • identity data
  • financial records
  • health information
  • infrastructure controls

Yet adoption of AI in cybersecurity remains uneven, often constrained by procurement complexity, legacy systems, and fragmented governance.

At the same time, threat capability is accelerating.

This mismatch is where the real risk lies.

The evidence is already here

There is increasing evidence that attackers are already using AI to enhance cyber operations.

Recent reporting highlights AI-assisted breaches targeting government systems and large-scale leaks of citizen data (TechRadar, 2026).

This is not a future scenario.

It is already happening.

A narrowing window to act

The policy challenge is not simply to adopt AI, but to do so responsibly and at pace.

This includes:

  • embedding AI-assisted vulnerability detection into development lifecycles
  • shifting from periodic audits to continuous monitoring
  • establishing governance frameworks for safe AI use
  • investing in workforce capability

Cybersecurity is now a strategic capability.

Not just a technical one.

The uncomfortable question

There is one question that cuts through the complexity:

If an AI system can find a critical vulnerability in your systems today… who finds it first?

Your team?

Or someone else’s?

Because in this new reality, that answer may determine the scale, speed, and impact of the next breach.

And the window to act is closing.


Make sure to share your own thoughts with the author by leaving a comment below