Frontier AI models are moving fast. Fast enough that even seasoned executives feel like the ground is shifting under their feet. New names, new benchmarks, bold claims. It's easy to get caught between hype and fear.
This blog cuts through the noise to unpack what AI can actually do today, what it can't, and what that means for your organisation.
What's AI doing now that it couldn't do six months ago?
Six months ago, frontier AI models were clever assistants. That's no longer an accurate description.
The biggest change is reliability across multi-step tasks. Current models can plan, reason through problems, and refine outputs without constant human steering. In software development and security analysis, AI can now follow a logical chain and produce genuinely usable results rather than rough drafts that need heavy rework.
AI has also moved beyond text generation. It can interact with tools, query systems, and orchestrate simple workflows, making it part of operational processes rather than a support layer sitting alongside them. Its ability to work across text, images, and structured data has improved to the point where it can interpret complex inputs and produce integrated outputs.
From a security perspective, the most significant advance is speed. AI is getting materially better at spotting patterns and identifying potential vulnerabilities in code and configurations, compressing tasks that previously required hours of manual effort into minutes. Overall, AI is moving into the core of how work gets done, not just enhancing it at the edges.
Breaking the hype: what AI can't do
Despite rapid progress, many of the boldest claims about AI don't hold up under scrutiny.
AI cannot replace human workers in any meaningful sense. It lacks context, judgement, and accountability. It can assist and accelerate, but it still depends heavily on human direction and oversight. Claims of full autonomy are similarly overstated. AI can follow structured workflows, but it doesn't independently define goals or understand broader business priorities. What looks like autonomy is usually carefully designed guardrails doing their job.
Accuracy remains a real limitation. Models are improving, but they still produce confident but incorrect outputs, particularly in ambiguous situations. Blind trust is risky in any context. In high-stakes environments, it's dangerous.
And while AI is making certain types of cyber activity faster, it hasn't made systems universally easy to compromise. Real-world constraints still apply. AI acts as a force multiplier for attackers, not a skeleton key.
The risk isn't an all-powerful AI. It's organisations misjudging where the limits actually sit.
What risks does this create for your organisation?
As AI capability advances, the threat profile is shifting in ways that demand a practical response.
Attack timelines are compressing
Vulnerabilities are being discovered and exploited faster. The window between patch availability and active exploitation is shrinking from months to hours. Organisations still running monthly patch cycles are operating on a timeline that no longer matches the threat.
The barrier to entry for attackers is dropping
Less-skilled actors can now use AI to generate phishing campaigns, automate reconnaissance, and write exploit code. This is commoditising attacks. What used to require specialist skill can now be assembled and executed by almost anyone.
Social engineering is harder to spot
AI-generated emails, voice cloning, and deepfake interactions are improving in realism. Traditional awareness training was designed for an era when phishing emails had spelling mistakes and odd formatting. That era is over.
Shadow AI is creating data leakage risks from the inside
Staff experimenting with AI tools may be exposing sensitive data or creating compliance issues without realising it. With AI being embedded into core application features, people may not even recognise when they're using it, let alone understand the risks.
Over-reliance on AI outputs is becoming its own vulnerability. When teams trust AI-generated code, security configurations, or financial analysis without verification, mistakes propagate quickly. As models become more fluent and confident in their delivery, the risk of inaccuracies going unnoticed grows.
What you can do about it
The fundamentals of security still hold. AI operates in humanistic ways; it just executes at machine speed. That speed of execution is the core threat, and addressing it means doing the things you're already doing, but faster and with less tolerance for gaps.
Defence in depth needs to be treated as non-negotiable. No single control is sufficient. Endpoint security, network controls, identity and access management, application security, and cloud security all need to be functioning and overlapping. AI compresses attack timelines, and layered defences buy you the detection and response time that a single point of failure won't.
Automated patching should be treated as a security control. With AI accelerating vulnerability discovery, patch delays are becoming a primary source of exposure. Prioritise internet-facing and critical systems, reduce approval bottlenecks for routine updates, and start measuring patch latency as an exposure metric.
Behavioural monitoring matters more than signature-based detection. AI-driven attacks may look legitimate on the surface; they'll use valid credentials, follow normal workflows, and avoid obvious indicators of compromise. Focus on what's abnormal: unusual login patterns, unexpected privilege escalation, anomalous processes or traffic. The patterns are there if you're looking for them.
Zero trust and micro-segmentation assume a breach and design for containment. Strict identity verification for every request, least-privilege access, and network segmentation to limit lateral movement. If an attacker gets in, the objective is to make the blast radius as small as possible.
Incident response needs to be practiced as well as documented. Speed matters more than perfection, and improvements identified during a response should be implemented iteratively. Your IR process should be cross-functional, supported by automation where possible, and your tabletop exercises should now include AI-assisted attack scenarios as standard.
What to take away from this
AI isn't going to break everything overnight, but treating it as business-as-usual would be a mistake. The disruption isn't any single capability but the pace at which improvements are compounding. And AI is not a one-sided advantage. The same capabilities that are making attackers faster and more scalable are available to defenders too. The organisations that use AI to strengthen detection, automate response, and close exposure gaps will be better positioned than those still debating whether AI is a real threat.
Don't get distracted by hype and instead focus on operational impact. Prioritise speed across patching, detection, and response. Assume attackers are already using AI, even if your organisation isn't. And lean into your vendors. They most likely have deeper pockets to develop AI-augmented defences than you do. Use that.
The report isn't surfacing new risks. It's confirming that the threat has already shifted. Whether your defences have kept pace is a conversation worth having, honestly.
2 Jul 2026