AI Is a Force Multiplier for Defenders and Attackers Both, Says Check Point CTO
Jonathan Zanger says every AI platform his team examined over the past year had serious security flaws. The fix isn't to avoid AI. It's to build security in from the start.

Key points
- Check Point Software CTO Jonathan Zanger told CSO Spain that his company found serious security vulnerabilities in every AI platform it examined during the past year.
- Check Point now runs roughly 300 automated AI instances that continuously probe and test its own products alongside human red teams.
- Zanger says AI has let smaller criminal groups run phishing campaigns, meaning fake-email scams, with far less skill than before.
- AI systems are harder to protect than traditional software because their behavior isn't fully predictable.
- Zanger's headline recommendation: treat security as a first step in any AI project, not an afterthought.
Check Point Software Technologies CTO Jonathan Zanger spoke with CSO Spain at the company's Engage 2026 conference in Paris last week. The conversation kept returning to one tension: the same AI technology making defenders faster is doing the same for criminals.
Does AI actually help attackers more than it helps defenders?
Not necessarily, but it's closer than the industry likes to admit. Zanger was direct about the upside for criminals. AI has lowered the skill bar for phishing campaigns, scams where criminals send fake emails to trick people into handing over passwords or money. Groups that previously lacked the technical know-how to mount large-scale attacks can now do so, and more people are entering offensive hacking as a result.
On the defender side, Check Point has used AI to scale work that once depended entirely on scarce human experts. Its internal red teams, whose job is to attack Check Point's own products to find weaknesses before criminals do, now work alongside roughly 300 AI software agents running around the clock. Those teams, Zanger said, operate about 20 times more efficiently than before. We've tracked Check Point's expanding AI posture across 11 stories since 8 June, including a red-team experiment that pushed a booby-trapped skill past every security scanner to 26,000 AI agents.
The uncomfortable counterpoint: Check Point found serious vulnerabilities in every AI platform it studied over the past year, and in all major AI development tools. Zanger didn't single out specific vendors. His point was structural. Innovation moves faster than security, and checks get left for later. Don't assume a product is safe because the company behind it has a good reputation.
Should you worry about how AI connects to your systems?
Yes, and for two reasons. First, AI isn't deterministic the way older business software was. Traditional software gave predictable outputs for predictable inputs, which made it easier to monitor. AI understands natural language and handles ambiguous requests, so its behavior can vary in ways no one anticipated. Writing rules that reliably catch bad behavior is genuinely harder.
Second, AI tools are only as useful as the company data they can reach, so businesses tend to connect them to as many internal systems as possible. Every new connection is a door. More doors mean more ways in for an attacker.
Zanger's answer to both problems is prevention rather than reaction. When an automated attack can cause real damage in seconds, spotting it afterward is often too late. AI-based systems that simulate attacker behavior and hunt for weaknesses before criminals find them are, in his view, the right model.
What does this mean for ordinary users?
Phishing is still the sharpest edge of this threat. AI makes fake emails more convincing and far more numerous. If an unexpected message asks you to hand over credentials or approve a payment, verify it through a separate channel before doing anything. That advice isn't new, but the volume of well-crafted attempts is, and that changes the odds.



