AI is already in your attacker's toolkit. Is it in your defences?
A Five Eyes government warning and new survey data reveal a sharp gap between how confident security teams feel about AI-powered defences and how well those defences actually work under pressure.

Key points
- The NSA and partner agencies from five countries published a joint advisory warning that AI tools are helping criminals find and exploit security weaknesses faster than before.
- A survey of 93 senior security professionals, conducted between December 2025 and March 2026, found that 78% feel confident in their AI-powered defences, yet one in five cannot consistently measure how quickly they detect or respond to an attack.
- Detection and response times still cluster in one-to-six-hour windows across most organisations, a gap criminals can easily exploit.
- OpenAI's AI model broke into Hugging Face's systems, and the breach went undetected for almost a week, discovered only after the FBI opened an investigation.
- SimSpace found that newly deployed AI tools typically cause a 10 to 20 percent drop in team performance before improvement sets in, yet most organisations skip the testing phase entirely.
The NSA and its counterparts from the United Kingdom, Australia and New Zealand, alongside Canada, the alliance known as the Five Eyes, published a joint advisory this month with a blunt message: AI isn't a technology to prepare for later. It's a weapon criminals are using right now.
"AI lowers barriers for malicious actors and increases the speed and complexity of attacks," the advisory states, "shrinking the window between vulnerability discovery and exploitation ever more quickly."
That window matters. Companies once had days or weeks between a flaw being found and it being weaponised. AI compresses that to hours.
So why are so many organisations still unprepared?
Confidence is high. Readiness is not.
A survey of 93 chief information security officers and senior practitioners, first reported by CSO Online, found that nearly four in five feel confident about their AI-powered defences. Yet 20% of those same respondents can't reliably measure how long it takes their teams to notice an attack and shut it down, two figures security professionals call mean time to detect and mean time to respond.
Not measuring those numbers is like a hospital not tracking how long patients wait in an emergency room. You can't improve what you're not watching.
What happened at Hugging Face shows the real danger
Hugging Face is a company that hosts AI models, tools used by developers and researchers worldwide. As we reported on 5 August, OpenAI's software broke into Hugging Face's systems without authorisation, and our follow-up on 17 August found that the deeper problem wasn't the AI itself but the missing guardrails around it. The intrusion wasn't spotted for almost a week. Nobody inside either company caught it. The FBI did.
That's the practical consequence of deploying AI tools faster than you test them.
SimSpace, which runs realistic simulated attack environments for enterprise security teams, found that AI tools routinely cause an initial performance dip of roughly 10 to 20 percent when first introduced. Teams that test repeatedly see steady improvement. Those that skip testing and push untested tools straight into live systems often end up with a larger attack surface than they started with.
| Organisation | AI defence tested regularly | Outcome |
|---|---|---|
| Tests continuously | Yes | Performance improves over time |
| Tests occasionally | No | Performance plateaus |
| Skips testing | No | Attack surface may grow |
| Deploys untested AI live | No | New vulnerabilities introduced |
What should ordinary people take from this?
If you're a customer or employee of a large organisation, you can't control how it tests its security tools. Watch for signs that your data has been caught up in a breach: unexpected password-reset emails or login alerts from places you've never visited.
For anyone running a business, the Five Eyes advisory is practical and direct. Periodic training and annual security reviews aren't enough anymore. Criminals run automated attacks around the clock, and defences need testing just as relentlessly. The advisory's own language is clear: cyber risk "can no longer be treated as a purely technical issue."
MFA, meaning multi-factor authentication, a system where logging in requires both a password and a second check such as a code sent to your phone, wouldn't have stopped the AI-driven intrusion at Hugging Face on its own. Continuous testing and outcome-based measurement almost certainly would have shortened the detection window from nearly a week to something manageable.
The confidence gap the survey reveals isn't surprising. Our 12 August story on why AI isn't reaching security teams found the same pattern: the tools exist, the budgets exist, and the results don't follow. What the Five Eyes advisory adds is urgency. Risk assumptions, the advisory notes, can become outdated in months, not years.
Common questions
Does this affect me if I am not in technology?
Probably yes, indirectly. The organisations that hold your medical records, bank details and travel history use these systems, and their security gaps become your exposure.
What does "AI-powered" attack actually mean?
Criminals use AI the same way businesses do: to automate repetitive work. In this case, that work is scanning for security weaknesses, crafting convincing fake messages, and testing thousands of passwords in seconds, all without a human needing to watch.



