AI Is Compressing the Cybersecurity Timeline. Security Teams Are Racing to Keep Up.
Artificial intelligence is speeding up both attack and defence at the same time. The organisations that survive the shift may not be the best-defended. They may simply be the fastest to act.

Key points
- Anthropic, OpenAI, and DeepSeek each released major AI model advances in recent months, pushing capabilities that security teams and criminals can both use.
- Security work that once took specialist analysts weeks, such as finding software flaws or mapping attack paths, can now be done in hours or days.
- Chief information security officers, the executives responsible for an organisation's digital safety, have shifted their main question from "Can AI help?" to "How fast can we deploy it?"
- The bottleneck in security operations is no longer finding threats. It is acting on what you already know, quickly enough to matter.
- AI can expand what a small analyst team can investigate, but only if the system is trained on the specific environment it is protecting.
For years the big question in cybersecurity boardrooms was whether artificial intelligence could actually do useful security work. Could it sift through thousands of alerts? Could it be trusted with anything important? Most organisations treated AI as a future project, interesting but not urgent.
That framing has quietly collapsed.
Security executives speaking with CSO Online now describe a different pressure. They are not asking whether AI works. They are asking how much time they have left before falling behind.
The catalyst is a run of high-profile model releases. Anthropic's Project Glasswing and its Mythos model, OpenAI's Daybreak system, and advances from the Chinese AI lab DeepSeek have each demonstrated that AI can now reason through problems that previously required years of specialist training. Finding weaknesses in software, mapping how an attacker could move through a network, crafting convincing fake messages to trick employees: all of these tasks are becoming faster and cheaper for anyone with access to capable AI.
How does this affect ordinary people and the organisations that serve them?
When criminals work faster, the window between a break-in and real damage shrinks. A flaw in a hospital's booking system or a retailer's payment platform that might once have taken attackers weeks to discover and exploit could now be found and used within days. That means the cost of slow patching, untrained staff, or delayed responses rises sharply.
Inside security teams, the change is already visible. Security operations centres, the teams of analysts who monitor for intrusions around the clock, were built on a simple idea: alerts arrive, humans investigate. Hiring more analysts was how you handled more alerts.
AI changes that equation. An investigation that requires an analyst to check dozens of systems, across employee devices, email, cloud storage, and network logs, can now run in minutes rather than hours. The analyst's job shifts from doing the investigation to directing it, checking its results, and hunting for threats the automated system might miss.
The risk in moving fast is moving blind. A system that treats every organisation's network as identical will produce results nobody can verify. The teams seeing the best outcomes are those that tune their AI tools to their own specific environment before trusting the output.
For employees at any organisation, the practical implication is straightforward. Phishing emails, where criminals send fake messages to trick staff into handing over passwords or clicking malicious links, are becoming harder to spot because AI can now personalise them at scale. Scepticism about unexpected messages asking for credentials or urgent action is more important than ever.
Security teams are not losing this race yet. But the margin for slow decisions is getting smaller.



