No. 11Security
AI versus AI: why cyber defence can no longer keep up without AI
4 min read by LimeByte
In September 2025, the AI company Anthropic uncovered an attack that changed cyber security. A state-sponsored group had manipulated an AI system into attacking around 30 organisations largely on its own – from reconnaissance and exploiting vulnerabilities to extracting data. The AI carried out 80 to 90 percent of the individual steps by itself, at a request rate that would be physically impossible for humans. In a handful of cases, the attackers succeeded.
This is no longer a glimpse of the future. It is the situation in which companies have to protect their IT today.
Attacks at machine speed
AI is not only changing what attacks look like, but above all how fast they come and how many there are. Phishing emails arrive without spelling mistakes and tailored precisely to the recipient. Malicious code is altered slightly for each target so that known signatures miss it. And voices or faces can be faked convincingly: at the engineering firm Arup, an employee in Hong Kong transferred 25 million US dollars after a video call with the supposed chief financial officer – every other participant was a deepfake.
Germany is no exception. According to Bitkom’s Wirtschaftsschutz 2026 study, 82 percent of companies assume that attackers are increasingly using AI. Damage caused by deepfakes doubled within a year from 4 to 8 percent, damage from automated robo calls rose from 3 to 14 percent. At the same time, according to Germany’s Federal Office for Information Security (BSI), an average of 119 new vulnerabilities became known every day in the 2024/25 reporting period – around 24 percent more than the year before.
Why traditional defence alone is no longer enough
No security team can assess 119 new vulnerabilities a day, read millions of log lines by hand or check every suspicious email individually. When attackers hand their work over to machines, the humans on the defending side become the bottleneck. Rules and signatures recognise what has been seen before. Against attacks that reassemble themselves for every target, that is no longer enough.
That is why, in the long run, there is only one effective answer to the misuse of AI: defence that uses AI itself – at least as consistently as the attackers do.
What AI already achieves in defence
The first examples show that this works. In 2025, Google’s AI agent “Big Sleep” found a critical flaw in the SQLite database that was known only to attackers and was about to be exploited. Google describes it as the first time an AI agent has directly foiled an attack. In the AIxCC competition run by the US research agency DARPA, autonomous systems found 54 of 63 planted vulnerabilities, fixed 43 of them on their own and also discovered 18 real, previously unknown flaws – for around 152 US dollars per task.
Anthropic also worked through the attack described above with AI: its own team analysed the enormous amounts of investigation data with the same technology the attackers had misused.
And it pays off. According to IBM’s Cost of a Data Breach Report 2026, a data breach costs 4.99 million US dollars on average, more than ever before. AI-supported attacks cost around one million more. Companies that use AI and automation extensively in their security, on the other hand, contain incidents about two months faster and pay almost two million US dollars less.
AI versus AI does not mean taking people out
AI in defence does not replace experts, it makes them faster. It pre-sorts alerts, spots anomalies in volumes of data no human can survey and suggests measures. The decisions still have to be made by people who know the company.
The basics remain just as important. The BSI warns that known vulnerabilities in systems at the network perimeter are far too often patched late or not at all. The best AI detection is of little help if the door is already open.
What companies should do now
- Know your attack surface and keep it small: record all systems reachable from outside, check them automatically and update them promptly.
- Use AI for detection: monitor email, endpoints and logs with tools that recognise patterns rather than only known signatures.
- Processes against deepfakes: never approve payments or credentials on request alone – confirm them through a second, known channel.
- Secure your own AI: define which AI services may be used with which data, and restrict access to them.
- Test regularly: only those who know their vulnerabilities can close them – before an attacker finds them.
Conclusion
Attackers discovered AI as a tool long ago. Anyone who still relies only on firewalls, signatures and manual work is defending against tomorrow’s attacks with yesterday’s means. The future of cyber security is AI versus AI – steered by people who know what they are doing.
Our free IT security check shows how well your company is prepared today. Or talk to us directly.
Sources: Anthropic, Bitkom, BSI, Google, DARPA, IBM, CNN on Arup