Security leaders are stuck in decision paralysis over AI-enabled cyberattacks

Axios
Published

The short version

  • Why it matters: Those leaders are still trying to size up how autonomous cyberattacks will affect their businesses at a time when they need to be taking bold action and mobilizing quickly…
  • The big picture: Companies have only a short window before AI models capable of end-to-end autonomous cyberattacks land in the hands of malicious attackers. But four months after Anthropic…
  • State of play: Ever since Anthropic rang the alarm on Mythos' abilities, security leaders have been wrestling with an increasingly complex security and regulatory landscape. OpenAI started…
  • Between the lines: Many companies are struggling to make decisions because security teams are stuck defining their AI governance strategies…
  • Reality check: Security leaders don't need to buy into frontier AI labs' promises of a silver bullet for defending against autonomous cyberattacks, Snehal Antani…

The story

Many security leaders at major companies, flush with expanded budgets to fend off AI-powered cyberattacks, are experiencing a level of decision fatigue that's freezing them in their tracks.

Why it matters: Those leaders are still trying to size up how autonomous cyberattacks will affect their businesses at a time when they need to be taking bold action and mobilizing quickly, experts told Axios.


The big picture: Companies have only a short window before AI models capable of end-to-end autonomous cyberattacks land in the hands of malicious attackers.

  • But four months after Anthropic released Mythos Preview to prepare for what's to come, many companies are still debating where to put their money and which controls to prioritize.

State of play: Ever since Anthropic rang the alarm on Mythos' abilities, security leaders have been wrestling with an increasingly complex security and regulatory landscape.

  • OpenAI started rolling out similarly powerful models to vetted cyber defenders, and the release of open-weight models like Kimi K3 and GLM-5.2 has raised fears about hackers' access to cyber-capable AI models.
  • Meanwhile, OpenAI's models colluded to hack Hugging Face, and Anthropic and Meta have shared stories about their models breaching third-party websites during safety tests.

Threat level: CrowdStrike observed an 89% surge in attacks using AI to "scale operations, accelerate tradecraft, and directly target AI infrastructure" in the last year, according to its annual threat hunting report.

Between the lines: Many companies are struggling to make decisions because security teams are stuck defining their AI governance strategies, including what constitutes AI risk and how they can responsibly deploy the technology, Nicole Carignan, senior vice president of security and AI strategy at Darktrace, told Axios.

  • These leaders are also stuck in a loop of constant education and research, she added, as new capabilities keep emerging from frontier and open-weight model maintainers.

Case in point: Evan Peña, co-founder and chief offensive security officer at Armadin, told Axios that he's seeing security leaders who are overwhelmed by the sheer number of products they could invest in to prepare for autonomous cyberattacks.

  • Many executives have been given new budgets and board buy-in and are debating whether to pour that money into attack simulation tools, vulnerability discovery, penetration testing or bug bounties.
  • Sherrod DeGrippo, vice president of threat intelligence at Palo Alto Networks' Unit 42, told Axios that she's heard from companies that are "grappling with all of these questions," including agent permissions, identity, logging and accountability.

Reality check: Security leaders don't need to buy into frontier AI labs' promises of a silver bullet for defending against autonomous cyberattacks, Snehal Antani, CEO and co-founder of Horizon3.ai, told Axios.

  • Instead, companies can start by doubling down on the fundamentals, including threat detection, incident response, security assessments and remediation.
  • "The frontier labs are setting the expectation that they have some AI easy button that is going to solve the problem," Antani said. "That does not exist, it is not possible."

The bottom line: Organizations have to start acting to shore up their defenses now before they get all of the answers they want about what AI risk looks like.

  • "We've got to figure out how we're going to deal with that," DeGrippo said. "There is work to be done."

Go deeper: Companies don't need advanced AI to defend against AI-powered hacks

Read the full story at AxiosOriginal

Related Markets

All Markets
View full chart →
View Full Chart
View full chart →
View Full Chart

Market data may be delayed. Not financial advice.

Powered by Gab AI

The Story At A Glance

Reading this article now — analysis appears below

Reading the article

💡 AI analysis provides alternative perspectives on current events

More to read

Recent stories from across the outlets Alto indexes.

Questions Alto can answer

From this story — each link opens a live data page or a tool already filled in.

  1. What is $100 from 1990 worth today?CPI-adjusted dollars — result on the next page
  2. Where does a $75,000 household income rank nationally?Census percentile — national and state
  3. What's Alto covering on the Tech & AI desk?Latest headlines on this beat

All toolsAll topicsSource directoryStory timelinesHeadline comparisonSearchMost read

From Gab Shop

Official merchandise. Every order funds free speech infrastructure.

Shop all products

Install Alto on your phone

Add Alto to your home screen for breaking news — no app store, no account.

  1. Step 1Open alto.gab.com in SafariMust be Safari — not Chrome or in-app browsers
  2. Step 2Tap the Share buttonSquare with an arrow, at the bottom of Safari
  3. Step 3Tap "More"If you don’t see Add to Home Screen yet
  4. Step 4Tap "Add to Home Screen"Scroll the share sheet if you need to
  5. Step 5Tap "Add"Alto appears on your home screen like any other app.
gab

Talk Big Tech Where Big Tech Can't Reach

AI, surveillance, and censorship, covered by the people the platforms removed first.

What Makes Gab Different

We're not just another social network. We're a platform built on principles that matter.

Freedom of Speech & Reach

All First Amendment protected speech is welcome. No algorithmic throttling or shadow banning.

Family-Friendly Platform

We maintain a clean environment. Explicit adult content is strictly prohibited.

Western Nations Only

Third-world IPs are blocked. No scammers, no spam farms. Built for Western civilization.

Funded By Users

Our users are our investors and customers. You're not the product being sold.

Battle Tested

A decade of standing strong. Banned from app stores, banks—and still here.

American Owned & Operated

We reject foreign censorship demands. Built by Americans, for free people.

Support Alto & Gab

Alto is funded entirely by readers like you. Your donation helps us continue delivering curated news from a right-wing Christian Nationalist perspective, powered by Gab AI.