Within Cyber Enablers
Will AI Help Hackers More Than Defenders?
The central dispute is whether automated hacking will outpace AI-enabled patching, monitoring and incident response.
On this page
- Why attackers may gain from speed and scale
- How defensive AI could find and fix weaknesses
- What evidence would show which side is pulling ahead
Page outline Jump by section
Introduction
Whether AI will help hackers more than defenders is one of the most important unresolved questions in debates about AI-enabled catastrophic misuse. The answer matters because cyber capabilities could act as force multipliers for other existential risks, such as theft of dangerous research, disruption of critical infrastructure or compromise of AI development itself. If AI consistently gives attackers the advantage, malicious operations could become dramatically cheaper, faster and more scalable. If it mainly strengthens defence, however, AI may reduce the opportunities for catastrophic cyber misuse despite increasing offensive capabilities.
The current evidence does not support a clear verdict either way. Frontier AI systems are becoming substantially more capable at cybersecurity tasks, but they are improving on both offensive and defensive work. Most researchers therefore describe the balance as uncertain rather than assuming either permanent attacker dominance or inevitable defensive superiority. The outcome is likely to depend less on raw model capability than on how quickly organisations deploy defensive AI, improve software security and adapt operational practices.[aisi.gov.uk]aisi.gov.ukFrontier AI Trends Report by The AI Security Institute (AISIFrontier AI Trends Report by The AI Security Institute (AISI
Why attackers may gain from speed and scale
The strongest argument that AI favours attackers is economic rather than technical. Cyber attackers already succeed because they only need to find one exploitable weakness, while defenders must secure thousands of systems simultaneously. AI can amplify this asymmetry by making many labour-intensive tasks dramatically cheaper.
Rather than inventing entirely new attack methods, AI can automate much of the work that normally consumes human time:
- analysing large codebases for weaknesses
- adapting publicly known exploits to new environments
- generating scripts and malware variants
- searching continuously across huge numbers of internet-facing systems
- coordinating multiple intrusion campaigns simultaneously
This compression of effort matters because sophisticated attacks have traditionally required highly skilled specialists. If AI reduces the expertise and time required, more attackers could perform operations that were previously limited to well-funded criminal groups or governments. The UK’s National Cyber Security Centre (NCSC) warns that frontier AI makes specialist cyber tasks easier to automate, lowering barriers to sophisticated attacks while increasing operational speed.[National Cyber Security Centre]ncsc.gov.ukOpen source on ncsc.gov.uk.
Researchers have also argued that offensive operations may benefit first because attackers can often adopt new technology more quickly than large organisations. Criminal groups generally face fewer procurement rules, regulatory constraints or compatibility requirements than enterprises responsible for legacy infrastructure. This could create a temporary period during which offensive capability grows faster than defensive deployment.[arXiv]arxiv.orgarXiv So K: Frontier AI's Impact on the Cybersecurity LandscapearXiv So K: Frontier AI's Impact on the Cybersecurity Landscape
Within AI doom discussions, this temporary imbalance is important because catastrophic misuse might require only a relatively short window during which offensive capabilities significantly outpace defensive adaptation.
Why defence may ultimately benefit even more
The opposing view is that cybersecurity is fundamentally a defensive engineering problem, and AI could automate many of the tasks that currently overwhelm security teams.
Modern organisations already struggle to:
- review enormous software repositories
- identify vulnerabilities before release
- prioritise thousands of security alerts
- investigate suspicious activity
- deploy patches quickly
- respond consistently across large networks
These activities are particularly well suited to machine assistance because they involve analysing large quantities of code, logs and system information.
Unlike attackers, defenders also possess structural advantages that AI may strengthen. Software vendors can fix one vulnerability once and distribute the correction to millions of users. Security tools can monitor entire organisations continuously rather than protecting only individual systems. AI-assisted code review may prevent vulnerabilities before software is released rather than merely detecting them afterwards.
The AI Security Institute explicitly describes cyber capability as inherently dual-use. Its evaluations examine both offensive activities, such as vulnerability exploitation, and defensive applications, including identifying weaknesses before attackers can exploit them. The Institute’s published findings therefore caution against assuming that improved offensive benchmarks automatically translate into greater real-world attacker advantage.[aisi.gov.uk]aisi.gov.ukFrontier AI Trends Report by The AI Security Institute (AISIFrontier AI Trends Report by The AI Security Institute (AISI
In principle, AI could also shorten the interval between vulnerability discovery and remediation enough to offset much of the offensive acceleration.
The timing problem may matter more than the capability gap
One of the most important emerging ideas is that AI may compress time rather than permanently favour either side.
Suppose both attackers and defenders become twice as productive.
Attackers could discover vulnerabilities much sooner after software is released.
Defenders could also identify and patch those vulnerabilities more quickly.
The decisive question becomes whether organisations can deploy fixes before attackers exploit them.
The NCSC has increasingly framed the challenge this way. Organisations with strong cyber hygiene, rapid patch management and automated security operations may benefit substantially from defensive AI. Those with slow patching cycles, outdated infrastructure or poor visibility may instead experience an increasing volume of successful attacks because AI reduces the time available to react.[National Cyber Security Centre]ncsc.gov.ukOpen source on ncsc.gov.uk.
In other words, AI may transform cybersecurity into a race against time rather than fundamentally changing who possesses greater technical capability.
What existing evidence actually shows
Current evidence is more nuanced than either optimistic or pessimistic headlines often suggest.
First, frontier models are genuinely becoming much better at cybersecurity tasks. The AI Security Institute reports rapid improvements across apprentice-, journeyman- and expert-level cyber evaluations, with leading systems beginning to solve problems previously beyond earlier models.[aisi.gov.uk]aisi.gov.ukFrontier AI Trends Report by The AI Security Institute (AISIFrontier AI Trends Report by The AI Security Institute (AISI
Second, realistic cyber evaluations still reveal substantial limitations. Recent work using enterprise-scale cyber ranges found that even leading frontier models completed only a minority of realistic end-to-end intrusion tasks without additional guidance. Success rates improved when models received hints, indicating that current systems remain far from fully autonomous attackers operating reliably in complex environments.[arXiv]arxiv.orgAgentCyberRange: Benchmarking Frontier AI Systems in Realistic Cyber RangesJune 12, 2026…
Third, experimental comparisons between attack and defence have not produced a decisive winner. One controlled study of autonomous AI agents in capture-the-flag competitions found that defensive agents achieved higher success rates under simplified conditions. However, when realistic operational constraints such as maintaining service availability were introduced, the apparent defensive advantage largely disappeared. The authors concluded that the balance depends heavily on how real-world defensive requirements are modelled.[arXiv]arxiv.orgarXiv Cybersecurity AI: Evaluating Agentic Cybersecurity in Attack/Defense CTFsCybersecurity AI: Evaluating Agentic Cybersecurity in Attack/Defense CTFsOctober 20, 2025…
Taken together, these findings suggest that both optimistic claims (“defence will easily win”) and pessimistic claims (“attackers inevitably dominate”) currently go beyond the available evidence.
Why AI doom discussions often emphasise offence
Even if AI eventually benefits defenders overall, existential-risk researchers often pay disproportionate attention to offensive capability.
This reflects the nature of catastrophic risk rather than ordinary cybersecurity.
A single successful intrusion could potentially enable:
- theft of highly sensitive biological research
- compromise of frontier AI development environments
- theft of model weights
- disruption of emergency or critical infrastructure during wider crises
- coordinated attacks that support another catastrophic misuse pathway
Because these scenarios depend on relatively rare but extremely consequential failures, even a modest temporary offensive advantage could have outsized importance.
From this perspective, the key question is not whether attackers become stronger on average, but whether AI occasionally enables attacks that previously lay beyond practical reach.
What evidence would show which side is pulling ahead
Several observable trends would help determine whether AI is ultimately favouring attackers or defenders.
Evidence suggesting attackers are gaining would include:
- steadily shrinking time between vulnerability disclosure and widespread exploitation
- increasing numbers of successful attacks requiring little human expertise
- autonomous AI agents completing realistic intrusion campaigns with minimal supervision
- persistent growth in compromise rates despite widespread deployment of defensive AI
Evidence suggesting defenders are pulling ahead would include:
- significantly faster vulnerability discovery before public release
- dramatic reductions in software defects through AI-assisted development
- automated patch deployment becoming substantially quicker than attacker adaptation
- measurable declines in successful compromises despite improving offensive AI
Some of these indicators are already being tracked by government evaluation programmes and experimental cyber benchmarks, but none yet demonstrates a decisive long-term advantage for either side.[arXiv]arxiv.orgA Framework for Evaluating Emerging Cyberattack Capabilities of AIMarch 14, 2025…
The current balance of evidence
The most defensible conclusion today is that AI is increasing cyber capability on both sides faster than researchers can confidently predict its long-term strategic effects.
There are credible reasons to expect attackers to benefit initially. Offensive operations often scale well through automation, criminal groups can adopt new tools rapidly, and defenders must secure far larger and more complex environments.
There are equally credible reasons to expect defence to recover much of that advantage over time. Software vendors can distribute fixes globally, defensive monitoring naturally benefits from automation, and AI-assisted software engineering may reduce the number of exploitable vulnerabilities entering production in the first place.
For debates about AI doom, this uncertainty is itself significant. Existential-risk arguments involving cyber capabilities generally do not require attackers to enjoy a permanent advantage. Instead, they depend on whether there are periods in which offensive AI improves faster than defensive deployment, creating temporary opportunities for catastrophic misuse before institutions adapt. At present, available evidence supports treating that possibility as plausible but unproven, making continued evaluation of both offensive and defensive AI capabilities an important part of understanding future existential risk.[arxiv.org]arxiv.orgarXiv So K: Frontier AI's Impact on the Cybersecurity LandscapearXiv So K: Frontier AI's Impact on the Cybersecurity Landscape
Amazon book picks
Further Reading
Books and field guides related to Will AI Help Hackers More Than Defenders?. Use these as the next step if you want deeper reading beyond the article.
The Fifth Domain
An urgent new warning from two bestselling security experts--and a gripping inside look at how governments, firms, and ordinary citizens...
The Perfect Weapon
From Russia’s tampering with the US election to the WannaCry hack that temporarily crippled Britain’s NHS, cyber has become the weapon of...
Click Here to Kill Everybody
A world of "smart" devices means the Internet can kill people. We need to act. Now. Everything is a computer. Ovens are computers that ma...
This is how They Tell Me the World Ends
WINNER OF THE FT & McKINSEY BUSINESS BOOK OF THE YEAR AWARD 2021The instant New York Times bestsellerA Financial Times and The Times Book...
eBay marketplace picks
Marketplace Samples
Live-tested eBay searches with available results related to this page.
Selected fromcybersecurity poster oneBay.co.uk.
Endnotes
1.
Source: aisi.gov.uk
Title: Frontier AI Trends Report by The AI Security Institute (AISI)
Link:https://www.aisi.gov.uk/frontier-ai-trends-report
2.
Source: arxiv.org
Title: arXiv So K: Frontier AI’s Impact on the Cybersecurity Landscape
Link:https://arxiv.org/abs/2504.05408
3.
Source: ncsc.gov.uk
Link:https://www.ncsc.gov.uk/frontier-ai
4.
Source: aisi.gov.uk
Title: aisi frontier ai trends report 2025
Link:https://www.aisi.gov.uk/research/aisi-frontier-ai-trends-report-2025
5.
Source: arxiv.org
Link:https://arxiv.org/abs/2606.14295
Source snippet
AgentCyberRange: Benchmarking Frontier AI Systems in Realistic Cyber RangesJune 12, 2026...
Published: June 12, 2026
6.
Source: arxiv.org
Title: arXiv Cybersecurity AI: Evaluating Agentic Cybersecurity in Attack/Defense CTFs
Link:https://arxiv.org/abs/2510.17521
Source snippet
Cybersecurity AI: Evaluating Agentic Cybersecurity in Attack/Defense CTFsOctober 20, 2025...
Published: October 20, 2025
7.
Source: arxiv.org
Link:https://arxiv.org/abs/2503.11917
Source snippet
A Framework for Evaluating Emerging Cyberattack Capabilities of AIMarch 14, 2025...
Published: March 14, 2025
8.
Source: ncsc.gov.uk
Title: Supporting AI adoption for UK cyber defence | National Cyber Security Centre
Link:https://www.ncsc.gov.uk/blogs/supporting-ai-adoption-for-uk-cyber-defence
9.
Source: ncsc.gov.uk
Link:https://www.ncsc.gov.uk/blogs/why-cyber-defenders-need-to-be-ready-for-frontier-ai
10.
Source: GOV.UK
Title: www.gov.uk A I Security Institute – Frontier AI Trends report factsheet
Link:https://www.gov.uk/government/publications/ai-security-institute-frontier-ai-trends-report-factsheet
11.
Source: GOV.UK
Title: www.gov.uk A I Security Institute – Frontier AI Trends report factsheet
Link:https://www.gov.uk/government/publications/ai-security-institute-frontier-ai-trends-report-factsheet/ai-security-institute-frontier-ai-trends-report-factsheet
12.
Source: GOV.UK
Link:https://www.gov.uk/government/news/inaugural-report-pioneered-by-ai-security-institute-gives-clearest-picture-yet-of-capabilities-of-most-advanced-ai
13.
Source: GOV.UK
Title: www.gov.uk Frontier AI: capabilities and risks – discussion paper
Link:https://www.gov.uk/government/publications/frontier-ai-capabilities-and-risks-discussion-paper/frontier-ai-capabilities-and-risks-discussion-paper
14.
Source: aisi.gov.uk
Link:https://www.aisi.gov.uk/blog/5-key-findings-from-our-first-frontier-ai-trends-report
15.
Source: aisi.gov.uk
Link:https://www.aisi.gov.uk/research
16.
Source: aisi.gov.uk
Link:https://www.aisi.gov.uk/blog
17.
Source: aisi.gov.uk
Title: Frontier AI Trends Report PDF
Link:https://www.aisi.gov.uk/frontier-ai-trends-report/pdf
Additional References
18.
Source: microsoft.com
Link:https://www.microsoft.com/en-us/security/blog/2026/05/12/defense-at-ai-speed-microsofts-new-multi-model-agentic-security-system-finds-16-new-vulnerabilities/
Source snippet
The Patch Tuesday cohort and the StorageDrive are forward-looking signals. Two retrospective benchmarks tell us how the system performs a...
19.
Source: csis.org
Title: Making AI Work for Cyber Defenders: A Strategy for Strengthening U.S
Link:https://www.csis.org/analysis/making-ai-work-cyber-defenders-strategy-strengthening-us-cybersecurity
Source snippet
CybersecurityJuly 15, 2026 — MAKING AI WORK FOR CYBER DEFENDERS: A STRATEGY FOR STRENGTHENING U.S. CYBERSECURITY Image: Photo: Michael Tr...
Published: July 15, 2026
20.
Source: youtube.com
Title: Who Will Win the Software Vulnerability Race? Five Scenarios
Link:https://www.youtube.com/watch?v=s-MTy4bJ9oc
Source snippet
If AI Writes Malware AND Detects It... Who Actually Wins?...
21.
Source: youtube.com
Title: Why AI is Accelerating Both Attackers and Defenders
Link:https://www.youtube.com/watch?v=mx9b9cVwrRY
Source snippet
Who Will Win the Software Vulnerability Race? Five Scenarios...
22.
Source: rusi.org
Link:https://www.rusi.org/explore-our-research/publications/commentary/ai-enabled-vulnerability-discovery-reshaping-national-cyber-defence
23.
Source: mdpi.com
Link:https://www.mdpi.com/2504-4990/8/1/19
24.
Source: weforum.org
Link:https://www.weforum.org/press/2026/05/new-report-shows-how-ai-gives-cybersecurity-[competitive
25.
Source: cyberdefenders.org
Link:https://cyberdefenders.org/cybersecurity-glossary/frontier-ai/
26.
Source: cnas.org
Link:https://www.cnas.org/press/press-release/new-cnas-report-examines-how-emerging-ai-capabilities-could-disrupt-the-cyber-offense-defense-balance
27.
Source: cset.georgetown.edu
Link:https://cset.georgetown.edu/publication/the-impact-of-ai-on-the-cyber-offense-defense-balance-and-the-character-of-cyber-conflict/



