AI continues to dominate headlines, with new stories regularly highlighting impressive breakthroughs, including increasingly sophisticated cyberattacks. While these developments deserve attention, it is equally important to step back and assess the broader picture for both cybersecurity professionals and business leaders.
AI undoubtedly introduces new capabilities and genuine security risks. However, both should be assessed objectively and grounded in reality rather than shaped by marketing narratives or sensational headlines.
To understand AI’s true impact on cybersecurity, three important considerations should always be kept in mind.
1. The Context
Headlines often focus on outcomes rather than the conditions that made those outcomes possible. In many cases, the capability described is theoretical or has only been demonstrated under highly controlled conditions designed to showcase AI at its best.
When an AI system demonstrates a notable capability, important questions frequently remain unanswered:
- What environment was it operating in?
- What data was available to it?
- What instructions or human guidance did it receive?
- How much time, iteration, or manual intervention was required?
Without this context, it can be difficult to determine whether a demonstration represents a realistic scenario or simply what is technically possible under ideal conditions.
2. The Market
AI is one of the most heavily marketed technologies in the world. Vendors, media outlets, and commentators all have incentives to emphasise both its capabilities and its risks.
As a result, public perception can become distorted, with extraordinary examples receiving far more attention than practical limitations or everyday reality. Recognising this dynamic helps maintain healthy scepticism and separate genuine cybersecurity developments from the momentum created by the AI market itself.
3. The Economics
Even where an AI capability has been genuinely demonstrated, a separate question remains: is it practical to deploy in the real world?
This is particularly relevant when considering malicious actors, who, like any organisation, are generally influenced by return on investment.
The most capable AI models are operated by leading vendors on infrastructure built at enormous scale, and these providers also implement safeguards designed to limit misuse. Attackers seeking to leverage these advanced capabilities must therefore operate within the constraints of the platform, balancing costs, restrictions, and potential benefit.
Those who instead self-host and use open-source models to avoid such safeguards face their own trade-offs. Infrastructure costs, operational complexity, ongoing maintenance, and capability limitations all influence the practicality of self-hosted AI.
Even in autonomous AI or defensive use cases, these constraints do not disappear. In some cases, they become even more significant.
Ultimately, demonstrating a capability and deploying it at scale are not the same thing. Cost, accessibility, scalability, and operational constraints all influence whether AI is adopted in practice.
A Balanced Assessment
None of this suggests that AI is not changing cybersecurity. It clearly is.
AI’s greatest current impact is its ability to accelerate existing activities and surface risk. It is already being used to enhance phishing, malware development, vulnerability research, and defensive security operations, while also creating new attack and exposure paths.
Through natural language interfaces, AI lowers the barrier to entry for less experienced users while increasing the speed and efficiency of more capable attackers and defenders alike. These are genuine developments that organisations should understand and prepare for.
Applying AI in Cybersecurity
The most important takeaway for cybersecurity professionals and business leaders is that understanding AI requires more than assessing stated capability alone. Whether a capability is beneficial or represents a potential threat, considerations such as context, market dynamics, and economics all influence how it translates into real-world outcomes.
When these factors are understood, organisations also have the foundation for effective AI risk management. Together, they help inform the likelihood of AI-related risks occurring and the potential impact they may have on the organisation.
AI’s role in cybersecurity should be evaluated like any other technology: not by what it might theoretically do, but by how it is practically implemented, the risks it introduces, and how well it aligns with organisational requirements and objectives.