Much of the commentary on AI and security falls into two camps. One says automated tooling will overwhelm defenders. The other says it will finally let them keep up. Having spent the past year in working sessions with the cyber employer council, my view is that both are partly right, and that the practitioners doing best are the ones who have stopped waiting to find out which.
What has genuinely changed
The most noticeable shift is in volume and polish. Phishing that once gave itself away through clumsy language now reads convincingly, in any language, tailored to its target. Reconnaissance that took days can be largely automated. Council members also report attempts to exploit AI systems directly, from manipulating inputs to extracting information a model was never meant to reveal.
- Social engineering at scale, with far fewer of the signals staff were trained to spot.
- Faster discovery of known weaknesses across large, poorly inventoried estates.
- New components in the attack surface: models, their data and the integrations around them.
- Automated tooling that lowers the skill required to mount a credible attack.
What has not
For all that, the fundamentals hold. The incidents discussed in council were still, overwhelmingly, about unpatched systems, excessive privileges, weak identity controls and alerts nobody acted on. AI makes those weaknesses quicker to find and exploit. It does not make them new.
The attacker’s tools got better. The doors they walk through are mostly the same ones we have been failing to close for a decade.
Defenders, meanwhile, are using the same tooling to triage alerts, summarise logs and draft detection rules. That is genuinely useful. It also carries the risk every AI-assisted workflow carries: output that sounds right and is not. A confident summary of an incident that misses the key indicator is worse than no summary at all.
What it means for practitioners
The Cyber Security standard has not added a separate AI capability area, and the council was deliberate about that. Instead, AI shows up across the existing six. Threat identification now includes AI components in scope. Secure architecture covers how models and their integrations are isolated. Security culture includes helping staff recognise attacks that no longer look amateurish.
In assessment, candidates increasingly bring AI-related evidence to the professional discussion, and assessors look for what they always have: honest ranking of risk, sound decisions under pressure and a clear account of what the candidate actually did. Using automated tooling in a response is fine. Being unable to explain how you verified what it told you is not.
My advice to anyone building a security career now is to become fluent in these tools without becoming dependent on them. The practitioners who will be most valued are those who can use automation to move faster and still know, from first principles, when it has got something wrong.