Artificial intelligence is dramatically reshaping the cybersecurity landscape, primarily by empowering criminals to operate at mass scale and lowering the entry barrier for sophisticated attacks. The Bank of England reported that 86% of companies now consider cyber risk among their top five concerns in late 2025, a rise from 72% in early 2024. A Proofpoint survey of 1,600 chief information security officers (CISOs) revealed that 66% experienced a material loss of sensitive information in the past year, up from 46% in 2024. In India, this figure was 99%. The financial toll of cybercrime is staggering, reaching $10.5 trillion in 2025 and expected to hit $15.6 trillion by 2029. Ransomware payments surged, with the median payment growing by 368% to nearly $60,000 between 2025 and 2026, despite a stagnation in overall payments after 2023.

AI's impact is evident in the increased frequency and speed of attacks. CrowdStrike reported an 89% year-on-year increase in activity by AI-enabled adversaries, with average eCrime breakout times falling to 29 minutes in 2025, a significant drop from 98 minutes in 2020. The fastest intrusion observed took just 27 seconds, and data exfiltration in one instance began only four minutes after initial access. This acceleration allows threat actors to identify and exploit weaknesses at unprecedented speeds, often before defenders can react. CrowdStrike also noted a 42% rise in the exploitation of previously unknown vulnerabilities and increased activity from groups associated with China exploiting publicly disclosed flaws before fixes are applied.

The rapid evolution of AI-driven threats has prompted strong warnings from financial regulators. Andrew Bailey, chair of the Financial Stability Board, highlighted that the cyber risk from frontier AI is the most immediate concern for the global financial system, emphasizing that AI can alter the speed, scale, and economics of attacks. The International Monetary Fund (IMF) concurs, stating that while AI can bolster cyber defenses, it also heightens systemic risk through shared digital infrastructure and machine-speed attack-defense dynamics that outpace human responses. Regulators are particularly worried that AI could accelerate vulnerability discovery, forcing a faster patching cycle that organizations might struggle to keep up with, leading to potential operational and resilience challenges.

Companies like Anthropic have demonstrated AI's power to uncover vulnerabilities. Their Claude Mythos software, withheld from public release, exposed thousands of critical zero-day vulnerabilities in major operating systems and web browsers. Anthropic described Mythos as a security danger, making it available only to vetted organizations like Apple, Microsoft, Broadcom, and Cisco for cybersecurity defenses. This underscores the need for organizations to adapt quickly. As Jadee Hanson, CISO at Vanta, notes, the economics of cybercrime have completely changed, making speed a critical security control. While AI presents challenges, it also offers solutions, helping companies identify fraud and other cybercrimes, as attackers will not cease to use AI to find vulnerabilities.