The discussion about the threats that AI might pose has taken on an apocalyptic tone: will it extinguish life on Earth? Will it destroy humanity? It won’t, but it poses some far more real dangers to us all—right now, not in some imagined future. In the next couple of years, we are likely to face a new wave of rampant, pervasive cyberattacks and cybercrime.
As the recent series of attacks by AI agents show, we no longer need to speculate about whether AI can conduct cyberattacks. It can. The important question now is what happens when attacks that once required skilled human beings can be conducted by machines, at machine speed and machine scale.
For most of cybersecurity’s history, we have built defenses around an unstated assumption: the attacker is human. A person—or a team—has to inspect a system, find a weakness, exploit it, see what happens and decide what to do next. That takes time. Detection therefore buys time. Defenders spot an intrusion and respond before the attacker gets much further.
Frontier AI attacks that assumption.
An agent does not need to sleep. It can inspect code, probe a network, hit a barrier, devise another approach and try again. Make a thousand copies and they can work against a thousand targets at once. Allow agents to share what they learn and hacking begins to change from a human-scale activity into a machine-scale one.
At Rubrik, we are seeing part of this transformation firsthand. Through our participation in Anthropic’s Project Glasswing, one lesson became clear. AI is not necessarily creating new vulnerabilities. It is collapsing the cost and time required to discover them.
That changes the economics of cybersecurity.
Modern software may contain thousands of small imperfections. Most lead nowhere. A few, combined in the right sequence, open a path through a supposedly secure system. Historically, finding those chains required talented people, lots of time and some luck. Frontier models can increasingly do the searching themselves, discovering paths through complex systems that humans might never find.
This is what makes complacency about the new threat so dangerous.
In 1998 a group of hackers appeared before Congress and warned that the rapidly expanding internet contained vulnerabilities capable of producing enormous disruption. There was no single cyber Armageddon. Instead North Korea crippled Sony Pictures. WannaCry raced through more than 200,000 computers in roughly 150 countries, disrupting hospitals and factories. NotPetya began as a Russian attack on Ukraine and caused about $10 billion in damage worldwide. Ransomware shut down Colonial Pipeline and disrupted fuel supplies across the American east coast.
It would be strange to look at that history and conclude that the warnings were overblown. The catastrophe did not arrive as one spectacular event. Cyber insecurity became a permanent condition.
Now imagine that condition at machine speed.
That is why “Will AI cause Armageddon?” is the wrong question. A hospital whose systems are encrypted, a bank that loses control of its identities, or a company that cannot recover its data doesn’t care much whether civilization remains intact. The question is whether AI can make attacks faster, cheaper, more sophisticated and vastly easier to replicate.
We are beginning to get the answer.
Cyber-defense therefore has to change as well. For years the industry has concentrated on prevention and detection: keep the attacker out and, failing that, spot him quickly. Both remain essential. But when attacks operate at machine speed, detection may no longer buy enough time. Intrusion, exploitation and damage can begin to collapse toward the same instant.
Companies must assume that some attacks will succeed. They need to be able to recover just as fast.
The answer is not less AI. It is more AI on the defensive side: continuously hunting vulnerabilities, watching identities and data, detecting abnormal behavior, patching weaknesses and helping restore compromised systems. Machine-speed attacks require machine-speed defense.
There has always been an asymmetry in cybersecurity. An attacker has to be right once. A defender has to be right every time. AI makes that imbalance more dangerous because attackers do not need permission, compliance reviews or perfect systems. They need only find one opening—and now they can search for it continuously, cheaply and at an enormous scale.
Criminal groups and hostile governments will use this technology. They would be foolish not to.
The first generation of cybersecurity was built to stop human beings sitting at keyboards. That world has ended. The next attack may be launched by thousands of agents, moving at a speed no human team can match.
If the hackers are becoming machines, our defenses must become machines too.