The good news? AI gives cyber defenders some of the best discovery tooling they’ve ever had. The bad news? It gives attackers the same capability. This duality has left CISOs managing AI on two simultaneous fronts. Outside the organization, attackers are using AI to make phishing more convincing, automate reconnaissance and compress the time between vulnerability disclosure and exploitation. The OpenAI/Hugging Face and JADEPUFFER incidents exposed the risk of autonomous agents carrying out end-to-end attacks without human direction. Inside the organization, employees are adopting AI tools faster than security teams can govern them, and sensitive data is flowing into consumer AI platforms where it is not protected. As a CISO myself, I’m noticing that when it comes to AI, the temptation is to try to secure everything, everywhere, all at once. That’s impossible. The CISOs who will pull ahead take a “Risk-First” approach, treating AI the same way they treat every other security challenge: as a business risk. The risk you already own You’ve likely seen the headlines about AI helping threat actors strengthen their attacks. And that’s certainly true: AI is helping attackers scale social engineering, accelerate research and rapidly develop exploits and malicious tools. Those capabilities will continue to improve. But your exposure may be greater from your business’s own adoption. We know employees are already using generative AI at work, but it’s problematic when done through personal accounts that operate outside enterprise controls. According to Verizon’s latest DBIR, the share of employees who are regular AI users on corporate devices tripled to 45% last year, up from 15%. Further, roughly two-thirds of AI users on corporate devices used personal accounts outside of enterprise controls. That increases the risk that sensitive information is being uploaded to unsecured LLMs, unbeknownst to security teams. Furthermore, employees’ own AI agents are beginning to execute tasks with minimal human oversight. In April 2026 at the SaaS company PocketOS, a well-known AI coding agent hit a credential mismatch during a routine task and decided to fix it by deleting a cloud storage volume. It went looking for an API token, found one in an unrelated file whose permissions weren’t scoped to that action, and deleted the production database and all volume-level backups in a single API call. Another concern is shared agentic systems, which many companies have deployed for productivity. By their nature, internal assistants and copilots need broad reach across systems and data to be useful, which means the platform wrapping the model becomes a high-value target. Even if a CISO feels confident in their data privacy controls and agent actions, there is a commonly overlooked but simple risk: usage-based billing. As token-based pricing for AI tools becomes standard, API keys and credentials tied to billing accounts become vulnerable. The Resilience Risk Operations Center (ROC) has already observed stolen API tokens being abused to run up AI bills for extremely significant losses. This puts a premium on basic cost-control measures to counter the emerging threat. External risk from threat actors The OpenAI/Hugging Face incident brought AI-native and agentic attacks to the top of the news cycle. The attack, carried out by AI models that escaped an isolated testing environment, alerted the security world to the reality of agent-driven attacks, even if the telling carried some marketing puffery. Resilience’s claims data shows that AI-native attacks aren’t leading to financial losses yet, but security teams should prepare for a future of attacks carried out largely by AI, especially as open-weight models catch up. This spring, Google’s Threat Intelligence Group (GTIG) reported the first zero-day it believes was developed with AI: a two-factor-authentication bypass for a widely used open-source admin tool, written in Python, that a known cybercrime group planned to use in a mass-exploitation run. The incident illustrated the acceleration and enhancement of threats with the help of AI. Even more concerning is the extensive use of Agentic AI to conduct cyber operations instead of just aiding with specific tasks. Agentic penetration-testing tools are proliferating on the defensive side; AWS even released its own this year, a step toward commoditization. I believe these are a necessary investment for security teams to continuously and proactively identify flaws, because the same capability is already being pointed at real targets. During a recent offensive engagement, researchers from CodeWall deployed an autonomous agent against McKinsey’s proprietary AI ecosystem. Within two hours, the agent successfully leveraged a SQL-injection vulnerability via unsecured APIs to gain full read-write privileges over the production environment. While the consultancy quickly remediated the flaw and reported no signs of data exfiltration, the incident underscores
AI threats are everywhere. A risk-first CISO decides what to prioritize
The good news? AI gives cyber defenders some of the best discovery tooling they’ve ever had. The bad news? It gives attackers the same capability. This duality has left CISOs managing AI on two simultaneous fronts. Outside the organization, attackers are using AI to make phishing more convincing, au
Source: CSO Online