Most cyberattacks are still financially motivated, but the tools behind them have changed faster than most defenses have kept up with. Generative AI has lowered the bar for writing convincing phishing emails and building malware, and attackers using it aren’t building anything custom. They’re taking widely available tools and applying them aggressively, without the constraints a legitimate vendor would build in.
The practical effect shows up in the details that used to give phishing away. Poor grammar, awkward phrasing, generic greetings: these used to be the tells an attentive employee could spot. A language model closes most of that gap in seconds, producing a message that reads like it came from a real colleague, vendor, or executive, tailored to the target’s industry and even referencing details scraped from a public profile or a company website. The same lowered bar applies to malware variants and to scripts used in reconnaissance, letting a less skilled attacker produce something that used to require real technical depth.
That asymmetry is the real problem, and it isn’t new to AI. It’s the oldest imbalance in security: an attacker only has to succeed once, while a defender has to succeed every time. AI narrows the gap in the attacker’s favor by making the “one attempt” cheaper and faster to produce. Where a phishing campaign used to mean writing one message and blasting it to a list, it now means generating dozens of variations, each one plausible, each one testing a slightly different angle, at almost no additional cost. Volume and quality used to be a tradeoff for attackers. AI lets them have both.
On the defense side, AI is genuinely useful in specific places: email filtering, endpoint detection, log correlation, spotting behavior that doesn’t fit a normal pattern. In each of those cases, the value comes from the same basic mechanism, a model trained to recognize what “normal” looks like for a given user, device, or network segment, so it can flag the moment something deviates, whether that’s a login from an unusual location, a process spawning in a way it never has before, or a spike in outbound traffic at an odd hour. That kind of pattern matching at scale is something no team of analysts could do by hand across thousands of endpoints and log sources, which is exactly why it’s become a standard part of any serious detection stack.
But it’s not a replacement for the fundamentals, and a lot of what gets marketed as “AI powered security” is closer to a feature label than a meaningful capability. A model can flag an anomaly. It can’t decide, on its own, whether that anomaly is a false positive, a misconfigured system, or the early stage of a real intrusion, and it can’t make the judgment call about how aggressively to respond without risking disruption to a legitimate business process. That still requires a person who understands the environment, the business, and what normal actually looks like for this specific organization, not just in the abstract.
The organizations holding up best aren’t the ones with the most AI in their stack. They’re the ones with properly trained people, a security team that isn’t stretched too thin to notice what the tools are telling them, and a clear sense of where their actual gaps are. A flood of alerts from an AI-driven tool is only useful if someone has the time and context to act on it. Without that, more automated detection just means a louder, more constant stream of noise for an already overloaded team to triage, and alert fatigue is its own kind of risk.
That’s the same principle behind Managed Detection & Response: the tools flag the anomaly, but a person still has to investigate and act on it. The technology narrows down what deserves attention. The judgment about what to do next, and the accountability for getting it right, still belongs to a human analyst who’s watching continuously and knows the environment well enough to tell a real threat from noise. For an IT Director sizing up a vendor’s “AI powered” claims, the useful question isn’t how much AI is in the product. It’s who is actually looking at what the AI flags, and how quickly.
Related reading: The Weakest Link in Your Defense · Top 7 Cyber Security Trends in 2021