If you’re not using AI to attack your own systems, your adversaries will
AI agents are increasingly capable of carrying out cyber-attacks, creating risks both as external tools for criminals and as internal systems with privileged access. The article argues that organisations should use AI-driven red teaming to test their own defences, because adversaries are likely to deploy similar technology regardless.
Experts warn that agents create new data-integration routes and expanding numbers of non-human identities that can evade static security controls. Matt Hartman, formerly acting head of cyber at CISA, says organisations should treat every agent as a privileged identity and strengthen phishing-resistant authentication, behavioural monitoring and zero-trust practices; he says AI can now find and exploit vulnerabilities in seconds rather than days.
- AI agents are becoming powerful tools for cyber-attacks.
- Organisations should use AI red teams to find weaknesses first.
- Treat AI agents as privileged identities with strict controls.
New here? Start with this
Artificial intelligence agents are software systems that can carry out tasks with limited human direction, including searching for information, using tools and making a series of decisions. In cyber security, the same capabilities can be used to identify weak points in computer systems, test whether defences work and, potentially, carry out attacks more quickly.
Organisations already use “red teams” — specialists who try to break into their own systems in controlled conditions — to uncover problems before criminals do. AI-driven red teaming applies automated agents to this work, allowing tests to be repeated more widely and rapidly, though it also raises questions about how much access those agents should receive.
A growing concern is that companies are connecting AI systems to internal data and services, giving them digital identities and permissions. Security experts argue that these identities need controls similar to those for staff accounts, such as stronger sign-ins, close monitoring for unusual behaviour and limits on what each system can access.
Both sides, in good faith
The strongest fair case each way — we don't pick a winner.
The case for
Using AI-driven red teaming can help organisations discover weaknesses at machine speed before criminals exploit them, particularly as attackers adopt agents that can probe systems continuously and at scale. Supporters argue that treating defensive AI as a controlled, audited extension of security testing is a prudent way to protect customers, critical services and sensitive data while improving zero-trust and identity safeguards.
The case against
Critics may argue that introducing autonomous attack-capable agents into live environments creates risks of its own, including unintended disruption, excessive data access and the normalisation of tools that could be misused or escape intended controls. They contend that organisations should first strengthen basic security hygiene, human oversight and clear accountability, rather than relying on increasingly complex systems whose behaviour and supply-chain risks may be difficult to assess.