Artificial intelligence is fundamentally changing the cybersecurity landscape, raising the threat level through more numerous, faster, and more potent attacks. The Global Cybersecurity Outlook 2026 by the World Economic Forum highlights that AI introduces additional vectors for more severe incursions. A notable example is Anthropic's Claude Mythos large language model, which, in tests, uncovered thousands of critical zero-day vulnerabilities in every major operating system and web browser. Anthropic withheld Mythos from public release due to its security risks, instead making it available only to vetted organizations like Apple, Microsoft, Broadcom, and Cisco through Project Glasswing to develop defensive measures against similar AI threats.

Cybersecurity teams report a clear increase in AI-enabled adversarial activity, with CrowdStrike observing an 89% year-on-year rise. AI accelerates the speed of attacks dramatically; the average eCrime breakout time decreased to 29 minutes in 2025 from 98 minutes in 2020, with the fastest intrusion recorded at just 27 seconds. In one instance, data exfiltration commenced only four minutes after initial access. This accelerated pace allows threat actors to scan for and exploit weaknesses before defenders can react, leading to a 42% increase in the exploitation of previously unknown vulnerabilities and increased activity from state-sponsored groups exploiting publicly disclosed flaws.

This shift demands that organizations quickly adapt their cybersecurity strategies. As Hanson from the security community notes, the economics of cybercrime have completely changed, making speed a critical security control. Organizations that fail to move quickly enough on AI will have a significant gap in their security posture. The UK's GCHQ Director, Anne Keast-Butler, describes AI as an "unstoppable force" with both offensive and defensive implications, emphasizing the need to reimagine cybersecurity in an AI-driven world. Google has also reported hackers using AI to find and exploit zero-day vulnerabilities that traditional scanners would miss, and observed state-sponsored actors using AI for vulnerability hunting and creating self-rewriting malware to evade detection.