AI is changing both sides of cybersecurity at once. Attackers are using agents to compress operations that once took teams and days into hours or minutes, while defenders are beginning to respond in kind. The result is a shift towards machine-speed security in which humans remain responsible for setting the boundaries, permissions and acceptable level of risk.

The race is no longer running at human speed

Cybersecurity has always been shaped by time. An attacker looks for a weakness, while a defender tries to find it first, patch it, detect its exploitation or contain the damage before an intrusion spreads. Much of modern security has therefore been built around reducing response times through faster detection, faster investigation and faster remediation. Artificial intelligence is beginning to change the scale of that race because the definition of “fast” is moving away from human speed.

Microsoft’s 2026 Digital Defense Report describes an environment in which attack timelines are compressing and increasingly capable tools are becoming available to a wider group of attackers. Nearly 40,000 CVEs were published during the first half of 2026, while AI is accelerating vulnerability discovery and shortening parts of the attack chain that once required lengthy human analysis. This does not necessarily mean that AI has created an entirely new form of cyberattack. Many of the techniques remain familiar: compromised credentials, vulnerable internet-facing systems, malicious code, poor configuration and unpatched software. What is changing is the amount of human effort required to identify those weaknesses, exploit them and move on to the next target.

The attack chain is starting to automate

Anthropic’s September threat intelligence report provides one of the clearest recent examples of that shift. The company documented malicious operations in which AI was being used beyond conventional chatbot assistance, with multi-agent systems carrying out reconnaissance, exploitation and data exfiltration. In some cases, AI-driven processes were also used to modify malicious tools after they had been detected, allowing attackers to test, rebuild and redeploy them with far less manual intervention. The significance lies less in the novelty of the individual techniques than in the degree to which parts of the attack process can now be delegated to systems operating continuously and in parallel.

Google Threat Intelligence Group has observed a similar pattern. In one operation during the second quarter of 2026, attackers compromised a cloud resource and moved from planning to an agent-enabled mass credential-harvesting campaign in less than six hours. The wider implication is that reducing the need for human interaction within an attack can significantly shorten the time available to defenders. Reconnaissance, vulnerability analysis, infrastructure configuration and adaptation of malicious tools all consume resources, and agentic AI can reduce the labour associated with many of those tasks. The attacker still determines the objective, but machines can increasingly carry out much of the work between those decisions.

That changes the economics of cyber operations as much as it changes their speed. Cyberattacks have traditionally been constrained by expertise, manpower and time. The more of the process that can be automated, the cheaper it becomes to scale operations across multiple targets. An attacker who previously required a team to investigate systems, test weaknesses and adjust tooling may increasingly be able to delegate large parts of that process to autonomous or semi-autonomous agents.

Human-led defence begins to hit its limits

The difficulty for defenders is that many security operations centres are still fundamentally organised around human workflows. Software collects signals, systems generate alerts and analysts investigate those alerts before deciding whether something is genuinely malicious and what should happen next. Automation has been part of this process for years, but important decisions have generally remained dependent on human review. That model becomes increasingly difficult to sustain if attackers are operating simultaneously across multiple systems at machine speed.

This helps explain why the idea of the agentic security operations centre has moved so quickly from concept into product strategy. Microsoft introduced an integrated security operations model in September based on people and AI agents sharing the same security context and controls, allowing agents to investigate and act across an environment without waiting for information to move manually between separate tools. CrowdStrike is pursuing a similar approach, using coordinated agents to investigate endpoint, identity, SaaS, cloud and network activity in parallel rather than sequentially. Google has also described the use of agentic systems internally to scan software continuously across hundreds of millions of lines of infrastructure code.

These companies have products to sell, so their claims need to be treated accordingly, but the strategic direction is consistent. Attack automation is beginning to be met with defence automation, not because human analysts are becoming irrelevant, but because there are limits to how quickly human-led processes can operate when the opposing side is increasingly automated.

Speed introduces a new trust problem

This does not mean that cybersecurity is about to become fully autonomous. Even in the attacks documented by Anthropic, humans remained involved in decisions such as target selection and the interpretation of results. The same distinction will matter on the defensive side. Allowing an AI system to identify suspicious behaviour is relatively straightforward. Allowing that same system to disable accounts, isolate production systems, revoke credentials or terminate business processes introduces a much more significant question of authority.

The faster security systems become capable of acting, the clearer the rules around that authority will have to become. Organisations will need to decide what an agent is allowed to do, which systems it can access and under what circumstances it can take action without waiting for human approval. They will also need to determine how an agent proves its identity, how another system establishes that it has not been compromised and how its actions can be reconstructed and audited afterwards.

These questions are already beginning to influence the architecture surrounding AI agents. NVIDIA introduced its Open Agent Safety Platform in September with runtime controls designed to monitor agent behaviour and quarantine agents that move outside defined boundaries. CrowdStrike has meanwhile been developing identity controls specifically for autonomous agents, reflecting the growing recognition that machines acting independently inside an organisation will need identities, permissions and access policies of their own.

That places machine-speed cybersecurity firmly inside the wider digital trust debate. The issue is no longer simply whether an AI system can detect or stop an attack faster than a person. Organisations must also decide how much authority they are prepared to delegate to a machine and how that authority is governed. Speed without control simply creates a different category of risk.

The human role moves upwards

Cybersecurity has gone through similar changes in operating model before. Signature-based antivirus gave way to behavioural detection, networks moved towards continuous monitoring, identity became a security perimeter and cloud infrastructure forced organisations to rethink where systems and data actually lived. Agentic AI is likely to become another of those transitions because it changes both the scale at which attackers can operate and the speed at which defenders must respond.

The most important consequence may therefore be a shift in the role of the human operator. Security professionals will remain central, but their responsibility is likely to move further towards defining policy, setting permissions, determining acceptable risk and intervening when judgement is required. Machines will increasingly detect machines, investigate machines and, in some circumstances, stop machines, while humans determine the conditions under which those actions are acceptable.

The next security question is control

The challenge for organisations is no longer only how quickly they can detect an attack. It is whether they can build defensive systems capable of operating at machine speed while still remaining under meaningful human control. That is likely to become one of the defining cybersecurity questions of the agentic AI era.


Discover more from The Quantum Space

Subscribe to get the latest posts sent to your email.

Leave a Reply

Trending

Discover more from The Quantum Space

Subscribe now to keep reading and get access to the full archive.

Continue reading

Discover more from The Quantum Space

Subscribe now to keep reading and get access to the full archive.

Continue reading