AI in the cyber arms race

When attacks and defence become smarter

AI in the cyber arms race

The use of artificial intelligence is changing the digital threat landscape and is leading to a new cyber arms race between attackers and defenders. While companies use AI to accelerate processes and increase communication and productivity, cybercriminals are also relying on these technologies. The result: attacks are becoming faster, more precise and more professional.

In this article, we show how the AI threat landscape is developing and how we, as an IT systems house, support small and medium-sized companies in strengthening their IT security accordingly.

For decision-makers, it is important to assess AI in the cyber arms race realistically: there is no reason to panic, but it would be wrong to rely blindly on outdated protection mechanisms.

How is AI changing the cyber threat?

Examples of threats that are amplified by AI

ASSESSMENT
The German Federal Office for Information Security (BSI) points out in its current assessment from 2026 that the rapid development of powerful AI systems is also changing the cyber threat landscape. AI can help attackers identify and analyse vulnerabilities more quickly, automate attack steps and derive exploitable attack paths from them. At the same time, AI reduces the time required and, in some cases, the technical entry barriers for offensive cyber activities.

For companies, this development is evident in the following areas, among others:

  • Phishing is becoming linguistically more convincing, more context-related and more personalised.
  • Information about companies, employees and possible attack surfaces can be gathered more quickly and evaluated.
  • AI-supported calls and deception attempts using deepfakes are on the rise.
  • The generation and modification of malicious code is becoming easier with the help of large language models .
  • Deepfakes are increasing
  • AI can further support the automation and scaling of cyberattacks.

AI is therefore not only amplifying already known attack methods. Advances in powerful AI models now also show that more complex technical attack steps can, under certain conditions, be carried out largely autonomously and linked together across longer sequences.

During an internal security test by OpenAI, protection mechanisms had been deliberately reduced in order to test the cyber capabilities of the models. In the process, they found a previously unknown vulnerability, reached the open internet and compromised parts of Hugging Face’s production infrastructure. Using further vulnerabilities, stolen credentials and elevated permissions, they moved between different systems.

The incident was not an autonomously planned criminal attack: the test objective and the evaluation environment had been defined by humans. However, the models found the way to the open internet and into Hugging Face’s infrastructure on their own.

In the meantime, further AI incidents have also come to light – including in connection with models from Anthropic.

Widespread use of fully autonomous AI attackers is not to be expected at present. However, developments are clearly moving in the direction of more autonomous cyber operations.

For companies, this means: they must respond without lapsing into actionism.

The AI cyber arms race is raising the demands on prevention, detection and response speed. The basic principles of good IT security do not change as a result. However, their consistent implementation is becoming ever more important.

What does this mean for cyber defence?

With increasing automation on the attackers’ side, the requirements for defence are changing too. Against this background, the BSI recommends giving “cyber security the highest priority”.

When attacks become more automated and faster, an equally structured and continuous defence is needed. Today, IT security is not a single product but an interplay of technology, monitoring and professional experience.

Purely reactive IT security is no longer sufficient in the AI cyber arms race. Companies must detect anomalies as early as possible, establish connections between individual events and be prepared for specific incidents.

The AI incidents also show that it is not only conventional end devices and servers that need to be considered. Interfaces, data processing procedures, cloud services, technical accounts and AI agents can also be part of the attack surface.

As an IT systems house, we therefore concentrate on the areas of the security architecture that we can actively influence through proactive IT security and maintenance.

Cyber security deserves the highest priority in order to hold your own in the race.

How we support SMEs in the cyber arms race

With our proactive IT support, we focus on identifying and assessing security-relevant developments at an early stage and deriving measures where necessary. This is not about absolute security – nobody can guarantee that. What matters is transparency, response speed and controllable risks.

Typical components of our work include:

  • Consistent, controlled, automated patch and vulnerability management
  • Operation and support of modern security solutions, such as next-generation firewalls, endpoint and e-mail security for attack detection
  • Automated reading of log files in order to evaluate events on the end devices (clients)
  • Continuous monitoring of security-relevant systems
  • Ongoing adjustment of the scripts for the automated analysis procedures
  • Professional assessment and prioritisation of anomalies
  • Avoidance of administration rights in normal everyday work
  • Regular review of access rights and security-critical interfaces
  • Regular IT check-ups to assess the existing security architecture and its resilience
Examples of where artificial intelligence is used in IT security

AI and automation help us to recognise patterns, evaluate large volumes of data and filter out relevant events more quickly. However, the decision as to which alert is actually critical and how to respond to it remains a professional task.

Interview with our managing director

Interview with an IT security expert on the topic of AI in the cyber arms race

5 questions for Manuel Luckey

We are seeing a significant increase in quality, speed and preparation. Phishing and social engineering in particular are becoming more professional and more personalised.

The cases in July 2026 also show that AI can now take on more complex technical tasks as well. For SMEs, however, the human attacker who uses AI to process more targets faster and more precisely remains the main concern.

Part of our work consists of analysing security-relevant events, for example firewall alerts, login events, endpoint notifications and anomalies in network traffic.

AI-supported and automated evaluations help us to process large volumes of data and identify relevant events more quickly. We then examine these in their respective context.

Not every alert is critical.

Worth watching are, for example, unusual login times, repeated failed attempts, deviations from normal user behaviour, new administrative permissions or conspicuous network traffic.

We always assess the overall picture: Which systems are affected? What impact is possible? How high is the specific risk? Only then do we decide on how to proceed.

Many successful cyberattacks exploit known security vulnerabilities for which updates already exist. This is exactly where patch management comes in, i.e. the central control of software updates.

Our automated patch management ensures that security updates are rolled out promptly, in a controlled and traceable manner, without unnecessarily disrupting ongoing operations. This considerably reduces the attack surface and creates transparency about the current security status.

Patch management is therefore not a side task, but a central component of our proactive IT support.

The current AI incidents show: patch management alone is not enough. If a previously unknown vulnerability is exploited, further layers of protection must take effect.

AI does not replace a solid IT foundation. For SMEs, patch management, multi-factor authentication, tested backups, endpoint protection, network segmentation, monitoring and clear access rights remain decisive.

AI-supported solutions can help to detect anomalies more quickly, prioritise events and respond automatically in clearly defined, low-risk cases.

In-house AI agents should only be given the permissions they need for their specific task. Critical actions or those that are difficult to reverse, such as deleting or publishing data, changes to access rights or financial transactions, should generally require human approval.

IT security remains an ongoing process. This includes regular employee training, as AI makes phishing and social engineering more convincing, as well as proactive support with clear responsibilities, continuous monitoring and defined response paths.

For SMEs in particular, it makes sense to think of IT security holistically. That means technically, organisationally and in human terms.
A structured support approach with clearly calculable services not only provides protection but also predictability.

Conclusion

AI IS CHANGING THE PLAYING FIELD OF ATTACK AND DEFENCE AND
THE CYBER ARMS RACE IS ALREADY IN FULL SWING

Artificial intelligence is making cyberattacks faster, more targeted and harder to detect. Phishing and other deception attempts are becoming more convincing, malware is easier to create and vulnerabilities can be identified and exploited more quickly. The incidents that came to light in July 2026 also show: AI models with high computing and analytical power can, under certain conditions, already carry out complex attacks largely autonomously.

The threat landscape is therefore not changing explosively, but it is changing significantly. For companies, the time pressure in particular is increasing, as attacks can be prepared more quickly, automated and directed at a larger number of targets.

At the same time, AI can also strengthen defence, for example through AI-supported anomaly detection and faster evaluation of large volumes of data. In addition, automated and audit-proof backups as well as structured response processes help to limit the impact of successful attacks and to respond more quickly. The fact that the unusual activities were detected and stopped by the security teams and that Hugging Face used its own models for the investigation also demonstrates the potential of modern tools for defence and illustrates the core of the cyber arms race: more powerful attack tools meet more powerful defence tools.

This is exactly where strategy and implementation matter. Small and medium-sized companies too can significantly strengthen their IT security – through a clear security strategy, regular employee awareness training and proactive IT support that consistently uses AI and automation and continuously monitors systems. There is no such thing as absolute security. What matters is identifying risks early, acting quickly and continuously developing your own security architecture.

Because in a world of the AI cyber arms race, in which both sides are becoming more intelligent, one thing counts above all: being prepared and responding faster at the decisive moment.

IT SECURITY STATUS CHECK

How well positioned is your company right now?

With our free IT security status check, you receive an initial assessment of your existing security architecture and can see in which areas there is a concrete need for action.



 

Let your cyber security become smarter too.

MCL Computer-Spezialisten.de GmbH