AI-powered threats: the next generation
AI-powered threats: the next generation
On 22 April 2026, I joined Sarah Armstrong-Smith and Glenn Wilkinson at teissAmsterdam 2026 for a panel discussion on the next generation of AI-powered threats.
My starting point was that AI is not fundamentally changing why attackers attack. It is removing friction from how they do it.
AI does not necessarily make attackers smarter. It makes them faster, cheaper and harder to ignore.
Attack at machine speed
AI can improve the speed, scale, precision and persistence of existing attack techniques. More convincing phishing, faster malware adaptation and a lower barrier to entry are obvious examples.
The more important issue, however, is the growing asymmetry between attackers and defenders.
Many organisations still depend heavily on manual analysis, manual decision-making and controls that change relatively slowly. Attackers are increasingly able to automate parts of discovery, adaptation and exploitation.
The challenge is therefore not simply that attackers have AI. It is that defenders cannot continue to operate exclusively at human speed in an increasingly automated threat environment.
AI expands the attack surface
Once AI becomes part of software delivery, customer interaction, internal workflows and employee productivity, the attack surface changes with it.
We need to think beyond infrastructure and applications. Models, prompts, memory, connectors, plugins, data flows and business process logic all become part of the environment we need to understand and protect.
Every AI capability you deploy creates new trust relationships that need to be defended.
That also means AI security cannot be reduced to securing the model itself.
Shadow AI may be the first incident
Not every AI incident will begin with a sophisticated adversary.
Employees are already experimenting with AI tools because they help them work faster. In many organisations, meaningful risk may first emerge from well-intentioned people combining the wrong tool, the wrong data and the wrong integration.
The first AI incident may therefore look less like a cyberattack and more like productivity.
This is why blanket bans are unlikely to provide lasting control. Security needs visibility into how AI is actually being used and needs to provide safe ways to experiment.
From static assurance to continuous validation
AI-enabled systems can change quickly. Their context changes, integrations change, models change and the actions they are allowed to perform can change.
A point-in-time review therefore tells us less and less about how the system will behave tomorrow.
Security leaders need to continuously validate what AI systems can access, what they are allowed to do, how they respond to manipulation and whether the controls around them still work after change.
If AI security is only reviewed once a year, the assurance is already out of date.

For me, that was the main takeaway from the discussion: AI accelerates both opportunity and threat. Our security models need to become equally adaptive.