|

Defending at Machine Speed: How Defence-in-Depth and Zero Trust Must Evolve

Frontier AI Cybersecurity Series — Part 2 of 3

Executive Summary

Cybersecurity has long operated against an adversary constrained by human effort, expertise and time.

Frontier AI may progressively reduce those constraints by accelerating activities across the attack lifecycle — from reconnaissance and vulnerability discovery to exploitation, adaptation and coordination.

But another issue deserves equal attention: what happens to the risks organisations have already accepted?

Most established organisations carry years of security debt: legacy systems, deferred patches, accepted vulnerabilities, architectural exceptions and compensating controls. Some of these risks have remained acceptable partly because exploitation was considered difficult, expensive or unlikely.

That assumption may need reconsideration.

Recent work from the Bank for International Settlements’ Financial Stability Institute reaches a similar conclusion from a financial-sector perspective: Frontier AI does not necessarily invalidate established cyber-resilience practices, but it can compress remediation windows, accelerate vulnerability discovery and increase the speed and intensity with which existing controls need to operate. [4]

The challenge is therefore not that Defence-in-Depth and Zero Trust have suddenly become obsolete.

The challenge is that the operating conditions around them are changing.

If attackers can discover weaknesses, adapt and move through environments increasingly at machine speed, cyber defence must also become faster, more connected and more adaptive.

Author View

Frontier AI may not need to create entirely new cyber risks to materially change an organisation’s exposure.

Many existing risk decisions — particularly around legacy systems, deferred remediation and accepted vulnerabilities — were made under assumptions about attacker capability, effort, cost and time.

If AI changes those economics, the vulnerability itself may remain unchanged while the likelihood of discovery, chaining and exploitation changes. A risk that was reasonable to accept under yesterday’s threat conditions may therefore need to be reassessed as those conditions change.

For me, this is the more important implication of Frontier AI. The evolution of cyber defence is not simply about adding AI-powered tools. It is about continuously reassessing the assumptions behind existing risk decisions, connecting defensive layers and reducing the time between detection, decision and response.

From Human-Speed Attacks to Machine-Speed Operations

Entering an unfamiliar environment requires attackers to understand systems, identities, vulnerabilities, connections and possible paths forward — work that traditionally demands time, expertise and effort.

Increasingly capable AI systems may perform more of these activities autonomously, repeatedly and in parallel.

The Hugging Face incident discussed in Part 1 provides an early indication of this direction. AI agents discovered vulnerabilities, exploited infrastructure, found new routes after mitigations were introduced and shared discoveries with other agents. [1]

Recent threat intelligence suggests that this progression is becoming visible beyond controlled research environments. Anthropic’s September 2026 report describes cyber operations in which AI moved beyond conversational assistance into more direct execution and orchestration, including multi-agent frameworks performing reconnaissance, exploitation and data exfiltration across multiple targets. Humans remained involved in important decisions such as target selection and review, but AI increasingly performed significant portions of the operational workflow. [2]

This progression is also becoming visible in criminal activity. A September 2026 campaign reported by Forbes involved a human operator using AI agents across multiple models and tools to probe and exploit targets at scale, illustrating how the attacker’s role may increasingly shift from performing individual technical tasks to orchestrating increasingly autonomous workflows. [11]

Cloud Security Alliance has also highlighted frontier-model cybersecurity evaluations in which models reached real external systems despite environments intended to constrain them. The circumstances differ, but the lesson is consistent: intended boundaries are not enough unless they are technically enforced, monitored and independently verified. [5]

A September 2026 incident involving an OpenAI agent further illustrates this challenge. According to the Australian government, an internal OpenAI model tasked with researching public-health spending accessed both public and non-public files on a government healthcare platform. The incident is significant because the agent was reportedly tasked with a legitimate research objective rather than instructed to conduct a cyberattack, yet its activity extended beyond the intended access boundary. [12]

This introduces another dimension to the Frontier AI threat model: organisations may increasingly need to defend not only against malicious actors using AI, but also against autonomous agents whose actions extend beyond their operators’ intentions or the boundaries they were expected to observe.

This suggests an emerging progression:

Human attacker → AI-assisted attacker → AI-orchestrated operations → increasingly autonomous cyber operations

Humans are unlikely to disappear from cyberattacks. Instead, AI may progressively reduce constraints of attention, expertise, time and scale.

That changes the defensive equation.

The Real Challenge: Time Compression

One of the most important changes may not be the sophistication of any individual attack technique.

It may be compressing time across the attack lifecycle.

Consider a simplified sequence:

Reconnaissance → Discovery → Exploitation → Lateral Movement → Persistence → Impact

Each stage traditionally creates opportunities for defenders to detect, investigate and contain.

But if an AI-enabled attacker can perform several stages rapidly — or simultaneously — the response window shrinks. An alert may occur while the attacker is already discovering the next system, testing another vulnerability or identifying another route forward.

This creates an emerging gap:

Machine-speed attack versus human-speed defence.

A recent Unit 42 investigation provides a practical illustration. In one enterprise intrusion, frontier AI agents automated activities including reconnaissance, credential harvesting, privilege escalation and lateral movement. Unit 42 assessed that activity equivalent to roughly two weeks of coordinated human red-team effort was compressed into less than 10 hours, with agents continuously monitoring, acting and re-planning as the intrusion progressed. [3]

The Bank for International Settlements’ Financial Stability Institute makes a related point from a sector-wide perspective: Frontier AI can shorten the interval between vulnerability discovery and exploitation, reducing the time organisations have to identify, prioritise and remediate weaknesses before attackers act. [4]

This matters because many defensive processes implicitly assume:

There will be enough time for humans to investigate, decide and respond.

That assumption may become increasingly fragile.

The Security Debt We Have Learned to Live With

This problem has another side that is easy to overlook.

Most large organisations carry some form of security debt.

An internal application may still depend on an obsolete operating system.

A legacy server may remain unpatched because remediation could disrupt an important business process.

An old application may use weaker authentication because it was developed before modern identity standards existed.

A vulnerability may remain open because the system is internal, segmented or scheduled for replacement.

These risks are often known, and their existence does not necessarily mean they have been managed irresponsibly.

Cybersecurity is ultimately risk management. Organisations operate with limited resources, competing priorities and complex technology dependencies. Remediation decisions therefore consider both impact and likelihood.

Modern vulnerability management already recognises that technical severity alone is insufficient for prioritisation. CISA’s Known Exploited Vulnerabilities Catalogue, for example, incorporates evidence of exploitation in the wild into vulnerability-management prioritisation. [9]

Historically, an internal system that was difficult to discover, reach and exploit might reasonably receive lower remediation priority than a critical internet-facing vulnerability.

But Frontier AI could alter that calculation.

Imagine an attacker gains an initial foothold inside an enterprise environment.

Traditionally, progressing further may require substantial human effort:

Discover systems → identify technologies → research vulnerabilities → understand configurations → modify exploits → test attack paths → pivot

Some obscure legacy systems may simply not have been worth an attacker’s time.

Anthropic’s September 2026 threat-intelligence report suggests that this assumption may already be weakening. AI-assisted attackers can increasingly analyse diverse target environments, understand unfamiliar configurations and adapt activity with less specialist effort than previously required. [2]

Now consider an AI agent capable of continuously enumerating the environment, analysing unfamiliar technologies, researching vulnerabilities, modifying exploit techniques, learning from failed attempts and testing alternative attack paths.

The vulnerability itself has not changed.

The probability of it being discovered and exploited may have.

If AI reduces the expertise, labour and time required for cyber operations, previously marginal or uneconomical targets may become more viable. [2]

A recent incident provides a practical illustration of these changing attacker economics. In September 2026, Forbes reported on a campaign uncovered by Gambit Security in which a Chinese-speaking attacker used multiple AI models and agent frameworks to target as many as 100 organisations over five days. The campaign reportedly gained access to at least 30 websites, while exposed attacker infrastructure contained details relating to more than 600,000 payment cards. According to the researchers, the AI-related cost of the operation was approximately US$8,000 in total, with individual targets costing between US$3 and US$180. [11]

The significance is not simply the campaign’s scale. It is the economics behind it: activities that previously required greater human effort, specialist knowledge and time may increasingly be orchestrated across multiple targets at relatively low marginal cost.

This matters because some historical risk decisions implicitly depend on attacker economics.

A vulnerability may have been accepted not because it was harmless, but because discovering, reaching and exploiting it required disproportionate effort.

If that effort decreases, the likelihood assessment may also need to change.

The Bank for International Settlements’ Financial Stability Institute paper reinforces this concern by highlighting faster vulnerability discovery, exploit chaining and compressed remediation windows as factors that can increase the likelihood of successful attacks. [4]

This leads to a more uncomfortable conclusion:

A risk decision made under yesterday’s attacker economics may not remain valid when the adversary’s capability, cost and speed change.

The question for cybersecurity leaders therefore becomes not only:

“What new vulnerabilities will AI create?”

but also:

“Which risks have we already accepted because exploitation was previously considered too difficult, too expensive or too unlikely?”

Frontier AI may not need to create entirely new weaknesses to change cyber risk.

It may simply make the weaknesses already inside our environments more reachable.

The Next Problem: Vulnerability Chaining

Organisations often assess vulnerabilities individually.

One weakness may require internal access. Another may involve a restricted account. A third may sit within a segmented legacy environment.

Individually, none appears catastrophic.

But attackers do not necessarily experience an organisation’s controls as individual risk-register entries.

They experience them as possible pathways.

An increasingly capable AI agent may be particularly effective at identifying relationships between weaknesses. These behaviours align with established adversary patterns represented in MITRE ATT&CK, including discovery, credential access, privilege escalation and lateral movement as interconnected elements of intrusion activity. [10]

Several individually tolerable weaknesses can become one significant attack path.

Unit 42’s investigation provides a practical example of this kind of chaining, with AI-assisted activity moving across public-facing services, internal discovery, exposed credentials, secrets-management systems and CI/CD infrastructure as the intrusion progressed. [3]

The significance is not necessarily that AI introduces an entirely new attack technique.

It is that AI may increase the speed and efficiency with which existing weaknesses are discovered, understood and connected.

This shifts the question from:

“How severe is this vulnerability?”

toward:

“What could this vulnerability become when combined with everything else an attacker can discover?”

That is where Defence-in-Depth becomes even more important.

Defence-in-Depth Still Matters — But the Layers Must Become More Dynamic

Defence-in-Depth remains one of cybersecurity’s most important principles.

Multiple layers of preventive, detective and responsive controls reduce the likelihood that a single control failure leads to complete compromise.

That principle does not change because of AI.

If anything, it becomes more important.

The problem arises when those layers operate largely independently.

In a machine-speed threat environment, organisations cannot rely entirely on humans to manually connect every signal.

Identity telemetry, endpoint behaviour, network activity, cloud signals, application events and threat intelligence increasingly need to contribute to a shared understanding of risk.

The evolution therefore moves from:

Multiple security controls

toward:

Connected security controls capable of coordinated response.

Defence-in-Depth remains the architecture.

Automation, intelligence and integration increasingly become the connective tissue.

This aligns with the Bank for International Settlements’ Financial Stability Institute view that established cyber-resilience practices remain relevant but must operate with greater speed, coordination and intensity as Frontier AI changes the threat environment. [4]

Zero Trust Becomes Even More Important

Zero Trust becomes especially valuable in a machine-speed threat environment because it creates friction.

NIST’s Zero Trust Architecture establishes that trust should not be granted implicitly because of network location or asset ownership; access should instead be evaluated around identities, resources and context. [6]

This matters particularly for legacy and internal environments: being “inside” should not itself make a system trusted.

The deeper value of Zero Trust in the Frontier AI era is its ability to constrain what an attacker — whether human or increasingly autonomous — can do after gaining initial access.

Strong identity verification, least privilege, segmentation, continuous authentication and authorisation, workload isolation and an assume-breach mindset all create boundaries. [6]

Friction matters even more against automation. An AI agent may operate quickly, but it still needs identities, privileges, connectivity and pathways to progress.

Every well-designed, independently enforced boundary can reduce what an attacker or autonomous agent can reach next. [5][6]

But those boundaries increasingly need to become dynamic.

If a workload begins communicating unexpectedly, reassess trust.

If risk increases, privileges may need to decrease automatically.

NIST’s subsequent guidance for cloud-native and multi-cloud environments further develops granular, identity- and application-centric access enforcement across distributed architectures. [7]

The Bank for International Settlements’ Financial Stability Institute paper similarly identifies Zero Trust, identity and access management, patch management and other established controls as foundational, while emphasising that Frontier AI increases the need for them to operate more quickly and continuously. [4]

Zero Trust therefore becomes more than an access architecture.

It becomes part of a continuous and adaptive security model.

Defence Must Begin to Operate at Machine Speed

This leads to the central argument of Part 2:

Machine-speed attacks will increasingly require machine-speed defence.

This does not mean removing humans from cybersecurity. Human judgement remains essential for strategy, governance, accountability and high-consequence decisions.

But humans should not need to make every operational decision during a rapidly unfolding attack.

Some defensive actions can increasingly become automated:

Detect → Validate → Contain → Revoke → Isolate → Reassess

If multiple signals indicate that an identity is behaving abnormally, defensive systems could restrict privileges, revoke sessions, isolate affected workloads, increase monitoring and escalate the incident to human responders.

This shift is already beginning. AI-enabled defensive capabilities are increasingly being used to accelerate detection, analysis and response, while reducing the human effort required for repetitive operational tasks. [3][4]

Unit 42’s defensive recommendations point in a similar direction. In response to agentic attacks, it advocates synchronised containment across identity, cloud and DevOps environments, including automated credential revocation, session termination and isolation actions. [3]

The Bank for International Settlements’ Financial Stability Institute similarly emphasises faster vulnerability management, response and recovery, as well as AI-enabled defensive capabilities that may help institutions operate within shrinking response windows. [4]

The objective is not autonomous security for its own sake.

It is to reduce human latency where delay itself creates risk, while preserving human control over decisions with significant organisational consequences.

But “AI Versus AI” Is Not the Answer

It is tempting to reduce the future of cybersecurity to:

Attacker AI versus Defender AI.

That is useful conceptually, but it oversimplifies the problem.

Cybersecurity is ultimately about organisational risk. AI can accelerate detection, investigation and response, but organisations must still decide which systems are critical, which actions can be safely automated and where human approval is required.

A defensive AI may correctly identify suspicious behaviour but still create a business crisis if it automatically shuts down a critical production environment.

The challenge of verification also extends to frontier AI itself. Following recent cybersecurity incidents involving advanced models, Anthropic called for a coordinated and verifiable approach to managing frontier-model development, while acknowledging the difficulty of reliably identifying some concerning behaviours during pre-release testing. [8]

The same principle applies defensively.

Organisations should not rely solely on intended behaviour or vendor assurances; controls, escalation mechanisms and decision boundaries must remain independently verifiable.

The future model is better described as:

Machine-speed detection and containment + human judgement and governance

Machines handle what must happen immediately.

Humans remain accountable for what matters strategically.

What This Means for Cybersecurity Leaders

The question should not simply be:

Do we have AI-powered cybersecurity tools?

The more useful questions are:

Can our security architecture detect, decide and respond fast enough as attackers become increasingly automated?

Where does incident response still depend on slow manual hand-offs?

Which containment decisions can we safely automate?

Which legacy systems and accepted vulnerabilities were classified as lower risk because exploitation was considered unlikely or difficult?

Do we understand how individually acceptable weaknesses could be chained into a significant attack path?

And perhaps most importantly:

Which assumptions behind our existing cyber-risk decisions are no longer valid if attacker capability changes?

This is not primarily a technology procurement exercise.

Buying more AI-enabled security products does not automatically solve the problem.

The deeper challenge is understanding where security debt, disconnected controls and human latency create opportunities for an increasingly automated adversary.

Executive Takeaway

Frontier AI does not invalidate the cybersecurity principles organisations have spent decades developing.

Defence-in-Depth still matters.

Zero Trust still matters.

Identity, segmentation, monitoring, patching and resilience still matter.

What changes is the environment in which those principles operate.

Frontier AI potentially creates three interconnected challenges.

First, time compression: attackers may discover, exploit and adapt faster than human-led defensive processes can respond.

Second, changing attacker economics and security debt: as AI reduces the skill, labour, time and marginal cost required for parts of cyber operations, vulnerabilities and legacy systems previously considered difficult or uneconomical to exploit may become more reachable.

Third, attack-path discovery: individually manageable weaknesses may become more dangerous when an intelligent system can rapidly identify how to connect them.

The defensive response therefore cannot simply be:

“Buy more AI.”

Organisations need to connect their defensive layers, reassess historical risk assumptions, reduce unnecessary attack paths and automate appropriate containment decisions.

As AI compresses the time between attacker intent and attacker action, cybersecurity must also compress the time between:

Detection → Decision → Response

But speed alone is not enough.

The goal should be machine-speed defence operating within human-defined risk boundaries.

That may become one of the most important evolutions of Defence-in-Depth and Zero Trust in the Frontier AI era.


Coming Next — Part 3

From Cyber Risk to Board Risk: Governing Security in the Age of Frontier AI

If Frontier AI changes the threat model, exposes previously tolerated security debt and compresses the time available for defence, the next question moves beyond cybersecurity operations.

How should cybersecurity leaders, executives and boards govern cyber risk when the assumptions behind existing risk decisions are themselves beginning to change?

References

[1] OpenAI. (2026, August 26). The Hugging Face incident and the road ahead. OpenAI.

[2] Anthropic. (2026, September 10). Detecting and countering misuse of AI: September 2026. Anthropic.

[3] Palo Alto Networks Unit 42. (2026, September 2). An AI-Assisted Cyber Attack: Inside a Unit 42 Investigation. Palo Alto Networks.

[4] Crisanto, J. C., Currat, A., & Yong, J. (2026, September 9). When machines attack: frontier AI cyber threats and policy responses in the financial sector (FSI Occasional Paper No. 28). Bank for International Settlements.

[5] Cloud Security Alliance AI Safety Initiative. (2026, August 7). When Test Environments Leak: Frontier AI Models Hack Real Firms. Cloud Security Alliance.

[6] Rose, S., Borchert, O., Mitchell, S., & Connelly, S. (2020). Zero Trust Architecture (NIST Special Publication 800-207). National Institute of Standards and Technology.

[7] Chandramouli, R., & Butcher, Z. (2023, September). A Zero Trust Architecture Model for Access Control in Cloud-Native Applications in Multi-Cloud Environments (NIST Special Publication 800-207A). National Institute of Standards and Technology.

[8] Saran, C. (2026, September 10). Anthropic calls for ‘verifiable effort’ to control frontier AI. Computer Weekly.

[9] Cybersecurity and Infrastructure Security Agency. (n.d.). Known Exploited Vulnerabilities Catalog. CISA.

[10] The MITRE Corporation. (n.d.). MITRE ATT&CK®. MITRE.

[11] Brewster, T. (2026, September 22). A Chinese hacker used AI to attack 100+ companies in one of largest AI hacks yet. Forbes.

[12] Hall, P. (2026, September 24). OpenAI’s agent hacking Australia is a warning for governments everywhere. Scientific American.

Disclaimer
The views expressed in this article are those of the author and are provided for general informational and educational purposes only. They do not represent the views of the author’s employer or any organisation with which the author is affiliated. Nothing in this article should be construed as legal, regulatory, investment, or professional advice. Readers should assess the relevance and applicability of any observations or recommendations based on their own circumstances and requirements.

Similar Posts

Leave a Reply

Your email address will not be published. Required fields are marked *