AI is transforming the way many businesses work. Some 97% of executives claim they have deployed agents in the past year, with over half (57%) of their staff already using them, according to one study. But it’s also helping to supercharge the cybercrime economy. CrowdStrike claims AI-enabled adversary activity increased 89% last year.

In many of these cases, it’s not creating entirely new categories of risk. Rather, AI offers threat groups powerful ways to scale and accelerate their attacks. Network defenders are increasingly overwhelmed. And as more of their adversaries adopt agentic tools, the imbalance could worsen.

Against this backdrop, compliance, risk management and security operations (SecOps) teams all have an important role to play.

Collapsing the Window

CrowdStrike’s recently published 2026 Threat Hunting Report is instructive. It explains how frontier AI is helping to close the historic window between vulnerability discovery and exploitation. It’s not necessarily about finding novel flaws; although AI can do that too. This is about empowering hackers to jump on the latest discoveries and generate proof-of-concept (PoC) exploits and attack paths at speed and scale.

“By chaining activity across identity, cloud, SaaS, endpoint, and perimeter infrastructure, adversaries can establish footholds, escalate privileges, exfiltrate data, or launch disruptive attacks before defenders can connect the signals and respond,” notes the report.

The findings are stark. Between January and June, 88% of vulnerability exploitations seen by CrowdStrike involving a public PoC were carried out within 48 hours of that PoC’s release. In some cases, such as Chinese groups Vault Panda and Genesis Panda, attacks were launched within 24 hours of public disclosure.

A relatively small but growing number of new vulnerabilities are in AI servers and related software: sometimes helping attackers to mine cryptocurrency, harvest sensitive configuration
information, or even access AI models themselves.

CrowdStrike also notes that AI model access techniques (of which vulnerability exploitation is one) accounted for 16% of total MITRE ATLAS techniques observed during the past 12 months. This speaks to the reality of today’s threat landscape. AI is both a powerful technology to be wielded for attacks, and a target in its own right. As CrowdStrike says: “AI is now a tool, a target, and a force multiplier for adversaries.”

Drowning in CVEs

The question is whether AI can also be a force multiplier for network defenders, because things are only just getting started. Reports suggest that over 48,000 CVEs were published in 2025, a 20% annual increase. In June, the figure was around 7400 – almost double the June 2025 figure. The rate of change is only going to increase.

On the one hand, this should be good news for network defenders, because the more security updates are available, the more opportunities there are to improve the resilience of IT systems. But patches are no good if there are so many that network defenders can’t reasonably prioritise, test and then deploy them. It might make their job harder, at least in the short term.

Mapping Out a Response

For KnowBe4 CISO advisor, Erich Kron, getting the basics right should be the first port of call for security teams.

“Organisations should ensure that they have a good process in place to test patches or mitigations quickly and a plan to rapidly apply them,” he tells IO (formerly ISMS.online). “Organisations should also ensure they have an accurate inventory of all devices on the network, including installed software and versions, to allow for quickly triaging potential vulnerabilities by severity as it relates to their specific organisation.”

Black Duck senior R&D manager, Christopher Jess, agrees that inventory is essential, especially in an open-source world, and that risk management must be continuous, with teams establishing clear risk thresholds to immediately trigger remediation.

“Businesses need to remove as much manual latency as possible from vulnerability detection, prioritisation and remediation,” he tells IO. “That means continuously discovering assets and dependencies, scanning code and open source throughout the SDLC, automatically correlating new vulnerability intelligence against what is actually deployed, and prioritising issues according to exploitability and business impact rather than simply producing ever-longer lists of CVEs.”

Given the growing gulf in velocity and capability between attackers and defenders, continuous monitoring becomes a must have, adds Deborah Galea, cybersecurity expert at Filigran.

“Periodic, reactive risk reviews are no longer sufficient. Organisations need continuous, real-time, proactive threat monitoring that finds exposures before they can be exploited. The focus should be on real risk, not theoretical risk: vulnerabilities actually being exploited in the wild, and threats being observed against organisations of similar size, industry, and geography,” she tells IO.

“Live threat intelligence sharing is increasingly critical too, as it shrinks the gap between when an attack first surfaces in the wild and when defences can respond, letting organisations act on risks emerging in their suppliers, peers, or industry before those risks reach them.”

Compliance Plays its Part

There’s an important role in all this for compliance as well as security operations teams, argues Oliver Simonnet lead cybersecurity researcher at CultureAI.

“Compliance and governance functions should prioritise assessing whether policies and procedures are actually being followed to help reduce the impact of internal AI use and external exposure,” he explains to IO.

“Risk management will need to increase its capability to assess, detect and resolve security issues, whether AI-related or traditional, in order to maximise the technical resilience of the business. Vendor oversight procedures should also routinely review vendor agreements, practices, and terms to ensure their data and general risk exposure remain known and understood.”

Compliance can also help by ensuring there’s clear accountability, third-party oversight and measurable implementation and testing plans, Simmonet adds. “If organisations are developing and testing tools with integrated AI technologies internally, they should be treated as privileged, high-risk infrastructure, with strong visibility, logging, patching, access controls, and containment features,” he says.

Perhaps above all, CISOs must not let this fall down the agenda. AI is here to stay and its impact on vulnerability research and exploitation is uncontested. CVE volumes are exploding. Open-source models are becoming more powerful with each new release. As Simmonet argues: “organisations should be trying to get ahead of the curve now, rather than considering the risk of AI something to solve later.”

Expand Your Knowledge

Blog: The NVD Pullback Should Prompt A Resilience Approach To Vulnerability Management

Blog: Moving From ‘Keep Them Out’ to ‘Keep the Business Running’

Podcast: Phishing for Trouble S2 E5: You’re Compliant. Are You Resilient?