AI vs. AI? The cybersecurity race has entered a new phase
In August, we wrote that artificial intelligence no longer necessarily follows only the path that has been predetermined for it. The Hugging Face incident and similar cases at Anthropic demonstrated that a sufficiently advanced AI agent can independently seek new solutions if an obstacle hinders it from achieving its designated goal. At the time, we were primarily discussing a new risk scenario. Since then, this scenario has become much more tangible.
AI is no longer just an assistant
One of the most significant developments in recent weeks is that AI developers themselves are attributing increasingly robust cybersecurity capabilities to their models. In September, OpenAI rated GPT-6 Astra as a model with “Critical” cybersecurity capabilities based on its own security framework. With the right tools and access, such a system may be capable of identifying previously unknown vulnerabilities and devising ways to exploit them without requiring a human to define every step. This is an important milestone.
For the role of artificial intelligence in cybersecurity thus moves beyond the realm of simple assistance toward autonomous problem-solving. And this is not just a possibility—it is also a security issue.
In September, another incident demonstrated what this could mean in practice. An OpenAI agent was originally tasked with collecting public health statistics from the Australian Medicare system. When it could not access the desired information through normal channels, it sought an alternative route and ultimately gained unauthorized access to part of the system’s infrastructure. According to investigations so far, personal Medicare data was not compromised, but the security lesson is clear nonetheless: the agent was not instructed to hack the system; it was simply given a goal, encountered an obstacle, and then sought another way. This is precisely the pattern of behavior we discussed in August, primarily in the context of test environments. Now we’ve seen it in actual government infrastructure as well.
In September, Anthropic also reported several incidents in which Claude models gained unauthorized access to real external systems. These various incidents all point to the same issue: the greater the capabilities, toolset, and access an autonomous system is given, the more important it becomes to precisely define what it can—and cannot—do to achieve its designated goal.
It is no coincidence that in mid-September, OpenAI introduced a dedicated framework for recording and publishing unexpected or concerning model behaviors.
The problem is therefore no longer theoretical. Leading AI developers are increasingly treating it as a distinct area of security.
Meanwhile, the attacker’s perspective is also changing
However, there is an even more important change. So far, we’ve mainly discussed what might happen if an AI agent begins to operate in a way that deviates from the developer’s intent. On the attacker’s side, the situation is simpler: the attacker sets an attack objective for the system from the outset.
In early October, during an investigation into a series of attacks targeting several financial institutions in South Korea, investigators found evidence that may point to the use of AI-based automated attack tools. The investigation is still ongoing, so it would be premature to draw definitive conclusions about the exact role of AI. However, the direction is clear.
A properly configured AI system could potentially be capable of:
- scanning infrastructure and searching for vulnerabilities;
- testing multiple attack vectors simultaneously;
- change strategy in case of failure;
- repeat these steps continuously and at high speed.
In this case, it is no longer simply the attack itself that accelerates. The attacker’s capabilities become scalable.

AI vs. AI?
This directly affects the operations of SOCs as well. Automation on the attacker’s side can result not only in more attacks but also in shorter decision-making cycles. An attacker AI may be capable of executing, in a matter of minutes or even seconds, a series of investigative and decision-making steps that previously required extensive work by human operators.
On the defensive side, however, many organizations still follow the same process:
- an alert is received;
- the analyst searches for data;
- gathers context from other systems;
- verifies the user and the affected host;
- searches for threat intelligence;
- correlates the events;
- and then determines whether it is a genuine attack or a false alarm.
The real bottleneck, therefore, is increasingly less about the number of alerts and more about the investigative capacity required for each individual alert.
However, the answer is not to unleash autonomous defensive AI against autonomous offensive AI. The events of recent months demonstrate precisely the risks posed by overly broad permissions and unchecked autonomy. Rather, what is needed is for the speed of defensive analysis to approach that of machines, while critical decisions remain under human control.
Automated speed, human control
The PULZARIS Analyst Agent is also built on this principle. It does not generate yet another alert, but rather accelerates the investigative work behind existing SIEM alerts:
- collects relevant evidence,
- builds context,
- correlates events,
- supplements the investigation with threat intelligence data,
- assesses the risk,
- and then prepares a decision-ready Investigation Brief for the analyst.
In this way, AI can take over a significant portion of the repetitive, data-intensive investigative work, while validation, risk assessment, and the approval of response measures remain in human hands. This is not a technological compromise, but a fundamental security principle.
Based on the events of recent months, the question is less and less whether AI will appear in cybersecurity. It is already present in vulnerability research, the attacker’s toolkit, and the operations of SOCs. The next competition will therefore be decided not merely by who has the more powerful AI model, but also by who can use it more quickly, in a more controlled manner, and more responsibly.
Speed can be automated. Decisions must remain human.


