Who Will Win the AI Arms Race?

When AI plays both sides of the field, the advantage goes to whoever can act first

  • In the last two years, AI has evolved from an assistant with limited reach into your workflows to a highly empowered agent with access to your systems, credentials, and tools. 
  • Attackers are using agentic and frontier AI to automate vulnerability discovery and cut down the time defenders have to respond. 
  • To tip the scales towards defenders, organizations need AI that turns telemetry into context, anticipates what’s next, and relieves their SOC. 

A lot can change in two years, and AI may be the most dramatic example the technology world has seen yet. 

We’ve gone from GenAI as an LLM tool to AI agents embedded into our workspaces and search engines in an alarmingly short span of time. There’s no denying the exponential effect it’s had on the velocity, volume, and amplitude at which businesses can operateUnfortunately, the same can be said about attacker activity. 

AI’s potential for harm is no longer up for debate. Attackers are finding vulnerabilities faster, developing exploit paths in minutes, and routinely automating reconnaissance. Much like how it’s woven itself into our everyday life, AI’s become an intrinsic part of an attacker’s operations. Meanwhile, defenders are left with less and less time to intervene

As AI feeds global instability and geopolitical tensions, cybersecurity increasingly becomes a matter of business resilience. With both sides clashing, the best-positioned organizations will strategically employ AI that effectively restores the one advantage defenders are losing the fastest: time.

AI has changed roles—and the playing field

Roughly a year ago, we wrote about AI’s dual nature: how the same technology could become an ally to attackers while simultaneously strengthening defenders. It’s staggering to realize how far beyond that conversation we are now, after just a year.

Because today, AI is already acting on our behalf. 

Where we started 

In 2024, the conversation was mostly about what employees were putting into GenAI tools. This came with security concerns around data exposure, unmanaged AI adoption, and the new data paths employees created. 

Then in 2025, AI wasn’t sitting on the sidelines anymore. Chat assistants embedded into workspaces became more common, and introduced much broader concerns around AI application sprawl, governance, and the security of data moving into and through these systems. 

Where we stand today 

Before, AI largely accessed data. Now, AI agents can access systems, use credentials, and even invoke tools. That kind of action expands risk from What can AI see? to What can AI do? And that distinction matters. It introduces an entirely new dimension to the attack surface: agency. In 2026 alone:

One model’s capabilities were significant enough to give Broadcom and other large enterprises access to frontier AI to conduct their own defensive research, finding previously unknown vulnerabilities before attackers could discover them and chain them together to mount next-level attacks. 

With AI in heavy use on both sides, a paradox has developed.

The AI innovation paradox 

Let’s break it down. Organizations across all industries are adopting AI because it helps them get more done, faster. That same acceleration also benefits attackers. As the value of an organization’s AI tools increase, so does the incentive to attack them—and bring them over to the dark side. 

Who Will Win the AI Arms Race?

While organizations have been busy using AI to process more information, automate repetitive work, and accelerate development, adversaries have started leveraging agentic AI to automate intelligence gathering and vulnerability assessments. This enables them to move through attack operations at a scale that would either be difficult or flat-out impossible for humans alone to achieve.

But the biggest change—and perhaps the most concerning—is speed.

The AI arms race is a race against time 

Cybersecurity has always been a kind of race to see who (attacker or defender) achieves their objective first. The difference now is that the other side has machines running for them. When an attacker can automate hours of work into mere minutes, an analyst manually bouncing between alerts, consoles, and tools is already at a stark disadvantage. Two years ago, attackers needed days or weeks to exploit a newly disclosed vulnerability. Today, they need a day. By 2027, that median time-to-exploit (MTTE) is projected to reach one minute. If the race was on before AI, it’s really on now.

And that has consequences. The faster an attacker can move from discovery to exploitation, the less time defenders have to investigate and stop the attack. The more alerts and telemetry there are to process, the harder it becomes for analysts to know what matters, and the more time they give to attackers.

Where AI was once an optional boost for defenders, it’s now a non-negotiable. 

AI as an attack amplifier

With attackers already using AI to scale complex, multi-chain attacks across domains, agentic AI takes them a step further by enabling autonomous execution throughout each phase of an attack—from reconnaissance and intelligence gathering to discovery and collection. 

We’re already seeing it in action. In February of 2026, LAMEHUG malware deployed an embedded large language model (LLM) designed to automate intelligence collection. A few months later in July, JADEPUFFER became the first agentic ransomware capable of performing automated extortion. The robots haven’t taken over yet, but they’re working on it. 

It’s hard not to imagine what the next months of 2026 may reveal.

How Frontier AI changes everything as we know it

Welcome to the next evolution in the arms race: Frontier AI. These increasingly capable models can analyze software, discover vulnerabilities, uncover previously unknown zero-days, and tenaciously chain multiple less-severe vulnerabilities into working exploit paths. And it all happens at a scale that’s impossible for humans to replicate—or even defend against without help.

This leaves us with a new baseline: 

  • Higher volumes of vulnerability discovery
  • Faster analysis of potential attack paths
  • More automated exploit chaining
  • A potential time-to-exploit under one day 

What this means for organizations

As the volume of credible vulnerabilities rises, the time between disclosure and exploitation will shrink even further, putting pressure on one of the most familiar defense strategies in vulnerability management: prioritization. 

For many organizations, defense strategies are likely to shift towards improving patching velocity. But while IT teams work to accelerate patching, security teams must shore up the rest of the defense stack. Because even the speediest patching process isn’t enough.  

The more attackers use AI to remove labor and hasten their exploits, the more defenders need AI that can reduce the cognitive load and “turn back the clock”. 

It’s not all bad news  

AI’s dual nature means defenders can already put AI to work and turn mountains of telemetry into usable context, accelerate investigations, and take action before the attack chain moves on.

Defenders need not wait for effective protections to come along. With the right AI-enabled tools, they can:

With Symantec CBX, the AI advantage belongs to you 

Symantec CBX’s cross-domain visibility makes all this possible. Native telemetry across endpoints, network, and data is automatically correlated and interpreted, giving analysts a unified view of activity across their environment. AI reconstructs and visualizes complete attack chains so defenders can spend less time stitching together evidence and more time acting on it.

With AI-powered capabilities at its core, CBX delivers meaningful help to security operations so teams can cut alert fatigue, speed up investigations, reduce their SIEM costs, and make sense of complex attack activity without requiring an army of senior experts. Integrated AI-powered tools like Threat Tracer gives analysts a relationship view of the full attack chain, while Incident Prediction—trained on more than 500,000 attack chains—anticipates the next four to five moves an attacker is likely to make. And finally, defenders get the context and foresight they’ve been waiting for. 

That’s what AI should look like in the hands of defenders. Technology that empowers analysts to make better-informed decisions and helps teams reach outcomes that once required far more resources. 

See how CBX puts predictive AI to work for defendersWatch the CBX Fest encore session on Incident Prediction to see how SOCs can move from reacting to anticipating what’s next or connect with your in-region experts to see what CBX can do for your team.

Want to explore more ways AI levels the playing field for defenders? Read 8 Ways AI is Easing Stress in the SOC

Q&A: Agentic Vs Frontier AI 

What is agentic AI?

Agentic AI can act on behalf of a user or system rather than simply generating information. In cybersecurity, AI agents can access systems, use credentials, invoke tools, and automate steps across an attack. That expands the risk from what AI can see to what it can do, giving attackers new ways to automate reconnaissance, discovery, collection, and other phases of an attack.

What is frontier AI?

Frontier AI refers to increasingly capable AI models that can perform more complex analysis and problem-solving at a scale previous models couldn’t match. In cybersecurity, these models can analyze software, discover vulnerabilities, identify potential zero-days, and chain multiple lower-severity vulnerabilities into working exploit paths. Their ability to perform this work at a scale humans cannot easily achieve means it could further shrink the time between vulnerability discovery and exploitation.

How can agentic and frontier AI help security teams?

These technologies can also give defenders more speed and capacity. AI can help security teams analyze complex telemetry, accelerate investigations, predict an attacker’s next moves, generate response plans, and automate specialized tasks. The goal isn’t just to match attacker speed, but to give defenders the context and foresight they need to understand an attack and act before it progresses.

You might also enjoy

Upcoming Events

See what's next

Threat Updates

Get the latest