For decades, cybersecurity has been defined by a familiar imbalance: attackers innovate, defenders respond. Every new attack technique creates the need for a corresponding security capability, keeping the industry in a constant cycle of adaptation. Artificial intelligence, however, is changing the pace and scale of that contest.
AI is now being adopted on both sides of the cybersecurity equation. Defenders are using it to analyse threats, automate security operations and strengthen their ability to respond, while attackers are using increasingly sophisticated capabilities to automate attacks, create convincing deception and potentially operate with far less human intervention. The result is a new cyber arms race in which the ability to deploy AI effectively could become as important as the technology itself.

For Avinash Advani, Founder and CEO of CyberKnight, this shift is not entirely unexpected. The cybersecurity industry had been experimenting with AI well before generative AI became mainstream. What has changed is the acceleration brought about by ChatGPT and the emergence of large language models and agentic AI.
“Everybody knew. Everyone perceived and predicted that AI was going to be a big part of defence in the future,” Advani says. “But the acceleration happened with ChatGPT.”
The significance of this acceleration is that AI is no longer simply another technology being incorporated into cybersecurity products. It is increasingly influencing how attacks are developed and executed, while simultaneously changing how organisations defend against them.
AI enters the offensive
The offensive use of AI has evolved rapidly. While automation has been part of cyberattacks for years through mechanisms such as bots and botnets, the emergence of generative and agentic AI introduces a different level of capability.
One of the most visible examples is the use of AI to create convincing digital deception. Emails, videos, text and voice recordings can increasingly be generated in ways that make them difficult to distinguish from legitimate communications. For organisations and individuals, this creates a new challenge: the very channels through which trust is established can become instruments of attack.
“When AI can create an email, or a video, or a text file, or a voice note that is identical to reality, it’s very scary,” Advani says.
The concern extends beyond deceptive content. Advani points to the emergence of agentic AI ransomware as an indication of where AI-enabled attacks could be heading. He refers to the detection of an AI capability that could autonomously progress through multiple stages of a ransomware campaign, from initiating and spreading through an environment to compromising systems and extracting data.
“I’m just envisioning an AI that can cover the entire attack cycle, the attack life cycle of a ransomware attack from beginning to end without any human intervention,” he says.
The significance of this development lies in the potential shift from AI assisting an attacker with individual tasks to AI independently managing an entire attack lifecycle.
The defence race accelerates
The same technology that is expanding the offensive capabilities available to attackers is also transforming cyber defence.
Advani traces the early adoption of AI in cyber defence to around 2018–2019, when cybersecurity vendors began developing AI capabilities for areas such as security operations and network detection and response. CyberKnight itself onboarded an AI-based security operations centre technology in its early days, at a time when the market was still learning how to understand the technology.
“It was way ahead of its time,” Advani recalls. “The market wasn’t ready, so it was a lot of education that happened.”
The arrival of ChatGPT changed that dynamic. AI moved from being an emerging capability within specialised cybersecurity products to becoming one of the industry’s central areas of discussion. Today, Advani says, virtually every cybersecurity vendor is introducing some form of AI functionality.
However, he sees a clear distinction between vendors adding AI simply to remain relevant and those using it to develop genuinely new security capabilities. “Today, all the features coming out around AI by most vendors, most not all, are just to be able to stay current,” he says. The vendors that are ahead, in his view, are those using AI to address specific security challenges rather than simply adding AI functionality to existing products.
The catch-up challenge
The growing adoption of AI on the defensive side does not eliminate the traditional imbalance between attackers and defenders. Advani considers that imbalance fundamental to the cybersecurity industry.
“There has never been a time since the beginning of cyber attacks where attackers were not ahead of defence,” he says. “That’s why we are in business.”
What has changed is the potential scale and speed of the attacks that organisations must contend with. In Advani’s assessment, the defences currently deployed by organisations are not sufficient to deal with today’s threat landscape.
“Today’s defences capable of handling today’s attacks? Definitely not. No way. No chance,” he says.
The challenge is not limited to technology. Geopolitical developments, economic conditions and competing investment priorities all influence how much organisations can allocate to cybersecurity. While AI-specific budget lines are increasingly appearing, Advani believes investment has not yet fully caught up with the requirement to defend against AI-enabled threats.
The double-edged AI challenge
For organisations, this creates a distinct challenge: AI needs to be treated both as a technology that requires protection and as a capability that can strengthen cybersecurity.
Advani believes organisations should begin by defining why they are adopting AI and identifying the specific use cases they intend to address. They then need to determine how those use cases will be implemented, whether through on-premises, hybrid or SaaS environments, while taking local regulatory requirements into consideration.
The next priority is securing the AI environment itself. This includes governance, data privacy, data leakage, hallucinations and vulnerabilities associated with AI systems.
Only after these foundations are established can organisations consider how AI can be applied to cybersecurity. This creates two distinct but connected security requirements.
“There’s two parts to it,” Advani explains. “How you can use AI either agentic or generative for cybersecurity, and two, how do you secure against agentic AI attacks?”
The AI arms race therefore creates a dual responsibility: organisations must protect the AI they deploy while also using AI to strengthen their wider security posture.
Moving beyond the AI feature race
This dual requirement is also shaping CyberKnight’s approach. Rather than focusing simply on adding AI capabilities to its portfolio, the company has developed what Advani describes as an AI blueprint to help organisations navigate the different stages of AI adoption and security.
The blueprint begins with defining AI use cases and determining how they should be implemented in the context of cybersecurity and local regulations. It then addresses the architecture and technologies required, followed by governance and security around the AI environment, including the data being used.
The framework also considers how AI can be applied directly to cybersecurity through capabilities such as AI-driven security operations and offensive security. Its final component focuses on securing agentic AI, an area CyberKnight is currently exploring as it develops the next capabilities within its portfolio.
AI becomes the new normal
Despite the current intensity surrounding AI, Advani does not expect the technology itself to remain a differentiator indefinitely. As AI becomes embedded across products and industries, simply having AI capabilities will no longer distinguish one technology or cybersecurity vendor from another.
“AI is so core and fundamental that it’s going to become a feature, a natural feature set for any vendor,” he says. “AI will no longer be a differentiator. It will just be a new normal.”
That evolution will also change the industry’s conversation around AI. Rather than being treated as a standalone innovation, it will become part of established cybersecurity frameworks, products and strategies.
“It’s a part of the framework. It’s part of the strategy,” Advani says.
The road to autonomous AI
The more consequential question, however, lies further ahead. Advani describes the evolution of AI as a journey from today’s chatbot and intelligent search capabilities towards increasingly autonomous systems.
That progression introduces questions that extend beyond conventional cybersecurity. As AI systems become capable of making decisions and taking actions with less human intervention, the industry will need to consider not only how to use these capabilities but also how to establish effective guardrails around them.
“Will Terminator ever happen?” Advani asks. “The question is, no one knows.”
While he believes the assumption is that appropriate safeguards will be established, he argues that the industry needs to engage more seriously with the possibility of unintended consequences before autonomous AI becomes widespread.
For Advani, this remains one of the less developed conversations around AI. The technology may still be a couple of years away from fully autonomous operation, but the implications warrant consideration now rather than after the technology has matured.
No room to stand still
The cybersecurity industry is therefore entering a phase in which AI will increasingly shape both sides of the cyber battlefield. Attackers are gaining new capabilities to automate and scale their operations, while defenders are turning to AI to analyse threats, strengthen security operations and respond more effectively.
The long-term outcome of this race will depend not simply on who adopts AI first, but on how effectively organisations integrate it into their broader security strategies and governance frameworks.
For Advani, the direction of travel is already clear. “We’re in the right place at the right time,” he says. “From an AI perspective, this is where the industry is heading.”
His conclusion is equally direct: “Anyone that doesn’t jump on the AI bandwagon will be left behind.”






Discussion about this post