AI is profoundly altering the cybersecurity landscape, making attacks more frequent, rapid, and automated. According to CrowdStrike, AI-enabled adversarial activity surged by 89% year-on-year. The average eCrime breakout time plummeted to 29 minutes in 2025 from 98 minutes in 2020, with the quickest intrusion recorded at just 27 seconds. Financial implications are severe; cybercrime costs reached $10.5 trillion in 2025 and are projected to hit $15.6 trillion by 2029. Ransomware payments also saw a significant increase of 368% between 2025 and 2026, averaging nearly $60,000 per incident.

AI allows threat actors to identify and exploit vulnerabilities with unprecedented speed. CrowdStrike observed a 42% increase in the exploitation of previously unknown vulnerabilities. A prime example of AI's power is Anthropic's Claude Mythos software, which detected thousands of critical zero-day vulnerabilities across major operating systems and web browsers. Anthropic categorized Mythos as a security risk and chose not to release it publicly, instead creating Project Glasswing to collaborate with vetted organizations like Apple and Microsoft to develop defenses. This highlights AI's dual impact: empowering criminals to operate at a mass scale and lowering the barrier to entry for sophisticated attacks.

The rapidly evolving threat environment is overwhelming many organizations. A Proofpoint survey of 1,600 chief information security officers revealed that 66% experienced a material loss of sensitive information in the past year, up from 46% in 2024. In India, this figure rose to 99%. Common vulnerabilities include the illegitimate use of legitimate identities, supply chain breaches, and exploits via internet-enabled interfaces. Financial institutions, such as JPMorgan Chase, Lloyds Banking Group, and Santander, are intensifying their defense efforts, with Lloyds developing an AI tool called Global Correlation Engine to identify threats.

Experts emphasize that speed is now a critical security control. Katie Moussouris, founder and CEO of Luta Security, noted that AI is becoming adept at vulnerability identification, to the point where even security professionals must use it to remain competitive. Vyacheslav Zholudev, co-founder of Sumsub, described the situation as a cat-and-mouse game, with AI enabling new types of fraud that can temporarily outpace detection systems. Nick Calver of Palo Alto Networks observed that the time to find and exploit vulnerabilities is drastically decreasing, a sentiment echoed by Patrick Opet, CISO at JPMorgan, who stated that more is changing faster than ever before.