Menu Close

How Is AI Changing the Cybersecurity Battlefield?

Artificial intelligence is making cyber operations faster, more automated and increasingly autonomous. The result may be one of the biggest changes in cybersecurity since the arrival of the internet.

By Open Chronicle Explained

For decades, cybersecurity has largely been a contest between humans assisted by machines.

Attackers searched for vulnerabilities, developed malicious software, stole credentials and attempted to penetrate computer networks. On the other side, security teams monitored systems, investigated suspicious activity and tried to respond before serious damage occurred.

Computers were always central to this struggle.

But humans were usually directing the operation.

Artificial intelligence is beginning to change that relationship.

AI systems can analyse enormous quantities of information, search for patterns, interact with software tools and perform certain tasks continuously. More advanced AI agents can go further: they can plan sequences of actions, choose tools and operate with increasing degrees of autonomy.

That changes something fundamental about cybersecurity.

The battlefield is no longer defined only by what attackers and defenders can do.

It is increasingly defined by how quickly machines can do it.

Speaking with GZERO Media’s Tony Maciulis on the sidelines of the 81st United Nations General Assembly in September 2026, Microsoft Security Executive Vice President Hayete Gallot described AI as “completely changing the physics of cyber.”

The phrase captures the scale of the transformation.

Cybersecurity is entering an era in which machines may increasingly attack, detect, investigate and respond to other machines.

So what exactly is changing?


1. What Has AI Actually Changed?

Cyberattacks are not new.

Phishing, malware, credential theft, software vulnerabilities, espionage and network intrusion existed long before modern artificial intelligence.

AI does not magically invent an entirely different cyber battlefield.

Instead, it changes several important variables:

speed, scale, automation and cost.

A human analyst has limited time.

An AI system can potentially process information continuously.

A human attacker might manually investigate a collection of systems.

Software assisted by AI can analyse much larger quantities of information.

A security analyst might need minutes or hours to investigate an alert.

Automated defensive systems can perform parts of that investigation almost immediately.

Microsoft argues that autonomous systems capable of reasoning, adapting and operating continuously are changing the economics and tempo of cybersecurity. The company says traditional security architectures designed primarily around human actors will struggle to match machine-speed operations.

The objectives of attackers may remain familiar.

What changes is the speed at which those objectives can be pursued.


2. What Is an AI Agent?

Understanding the new cybersecurity environment requires understanding the difference between an ordinary AI assistant and an AI agent.

A conventional chatbot generally waits for a question and generates a response.

An agent can potentially do more.

It may be able to:

observe information,

analyse a situation,

decide what action to take,

select a software tool,

perform an action,

observe the result,

and then decide what to do next.

That creates a loop:

Observe → Analyse → Decide → Act → Observe Again

Microsoft describes AI agents as software systems capable of perceiving their environment, making decisions and taking actions. Some autonomous agents can operate using their own digital identities rather than simply inheriting the identity of a human user.

This is enormously useful.

An agent could monitor infrastructure, analyse software, manage routine workflows or investigate security alerts.

But the same capability introduces a new security problem.

A system that can act can also make mistakes — or be manipulated into taking actions its operator never intended.


3. How Can Attackers Use AI?

The most immediate impact of AI on cybercrime does not necessarily require completely autonomous cyber weapons.

AI can already assist human attackers.

It can accelerate research, analyse information, generate or modify content, improve social-engineering campaigns and help operators iterate more rapidly.

Microsoft reported in April 2026 that threat actors ranging from nation-state groups to cybercriminal organizations were increasingly incorporating AI into their operations. Importantly, Microsoft also cautioned that many observed attacks still involved humans rather than fully autonomous AI systems.

That distinction matters.

There is a major difference between:

a human attacker using AI

and

an AI system independently conducting an entire cyber campaign.

The first is already part of the threat landscape.

The second represents a more advanced degree of autonomy and should not be assumed to describe every AI-enabled attack.

But even human-directed AI can change the economics of cyber operations.

Tasks that once consumed considerable time can become faster.

An attacker can potentially test more possibilities, process more information and adapt more rapidly.

That means organizations may face not necessarily completely new forms of attack, but far greater volumes and faster iterations of familiar ones.


4. Why Does Speed Change the Cyber Battlefield?

Imagine that an attacker discovers a vulnerability.

In a traditional environment, several steps might follow.

The vulnerability must be understood.

An exploit may need to be developed.

Targets must be identified.

The attack must be executed.

Defenders must notice unusual activity.

Security analysts must investigate.

Finally, someone must decide how to respond.

Every step consumes time.

Artificial intelligence can compress parts of that timeline.

Microsoft said in April 2026 that advanced AI models were demonstrating an ability to discover vulnerabilities and combine weaknesses in ways that could significantly shorten the interval between vulnerability discovery and potential exploitation.

This creates a critical concept in modern cybersecurity:

the response window.

If attacks accelerate while defensive decisions remain slow, attackers gain more time inside the network.

The faster attacks become, the more valuable rapid detection and containment become.

That is why the cybersecurity contest is increasingly moving from human speed toward machine speed.


5. Can AI Defend Against AI?

This leads to an obvious question.

If attackers can use AI, how can defenders keep up?

Increasingly, the answer may be:

with AI.

Modern organizations can generate enormous quantities of security information.

Authentication attempts.

Network traffic.

Application logs.

Cloud activity.

Endpoint behaviour.

Email events.

Identity changes.

Software vulnerabilities.

No human security team can manually examine every event in real time.

AI can help analyse these signals and identify relationships that deserve attention.

It can also assist with investigation, prioritisation and, under carefully defined conditions, response.

Microsoft is already developing agent-based defensive systems. Its Project Perception architecture, announced in 2026, uses specialized agents performing different security roles, including systems designed to identify weaknesses, investigate threats and help harden environments.

The concept creates a defensive loop:

Detect → Analyse → Investigate → Decide → Respond → Learn

The objective is not simply to produce more alerts.

It is to reduce the time between discovering a threat and doing something about it.


6. The Security Operations Centre Is Changing

The Security Operations Centre — usually called the SOC — has traditionally been the command centre of organizational cybersecurity.

Analysts monitor dashboards.

Security systems generate alerts.

Investigators determine which alerts represent genuine threats.

Incidents are escalated.

Responses are coordinated.

But this model has a fundamental limitation.

Humans have limited attention.

A large organization can generate extraordinary quantities of security telemetry.

AI agents introduce the possibility of continuously investigating some of this activity before a human analyst becomes involved.

Microsoft’s emerging model for an agentic SOC envisions people and agents operating through the same security environment. Machines provide continuous speed and scale, while people establish priorities, apply judgment and determine important outcomes.

That changes the role of the analyst.

Instead of manually performing every stage of an investigation, security professionals may increasingly supervise automated investigations and intervene where judgment, ambiguity or significant consequences require human authority.


7. But AI Agents Create Their Own Security Problem

There is an important paradox.

The same AI agents that can make organizations more productive can also create new vulnerabilities.

Consider an AI agent connected to a company’s internal systems.

It might have permission to:

read documents,

search databases,

send emails,

access cloud services,

update records,

run software tools,

or trigger business processes.

That makes the agent useful.

It also means that compromising or manipulating the agent could have consequences beyond simply generating an incorrect answer.

Microsoft security researchers describe this transition as AI moving from reading to acting. When agents can execute tools and modify systems, vulnerabilities affecting those agents can potentially result in real actions.

This creates a new attack surface.

Organizations therefore need to secure not only their employees and computers.

They increasingly need to secure their AI workforce as well.


8. Why Identity Becomes Critical

One of the most important questions in cybersecurity has always been:

Who are you?

The next question is:

What are you allowed to do?

These questions become even more important when autonomous software begins operating inside organizations.

Every important AI agent may need a clearly defined identity.

Security systems must know:

which agent is acting,

what permissions it possesses,

what systems it can access,

what information it can retrieve,

what actions it can perform,

and whether its behaviour is consistent with its intended role.

Microsoft’s security architecture for AI therefore extends identity controls to non-human agents and workloads.

This reflects a broader cybersecurity principle known as least privilege.

An agent should receive only the permissions necessary to perform its task.

An AI assistant that schedules meetings probably does not need access to financial infrastructure.

A customer-service agent probably should not be able to modify security policies.

A research agent may need to read documents but not delete them.

Limiting permissions limits the potential blast radius when something goes wrong.


9. What Happens If an AI Agent Is Manipulated?

This is one of the most important emerging problems.

AI systems interpret information.

But information can sometimes contain instructions designed to manipulate how an AI system behaves.

One example is prompt injection.

Suppose an AI agent reads an external document, email or webpage containing malicious instructions intended not for a human reader but for the AI system itself.

If the agent cannot distinguish trusted instructions from hostile content, an attacker may attempt to influence its behaviour.

The consequences become more serious when the agent can use tools.

A manipulated chatbot might produce a misleading answer.

A manipulated autonomous agent could potentially attempt an unauthorized action within the permissions available to it.

This is why securing AI agents requires more than securing the underlying model.

Microsoft researchers argue that autonomous systems need layers of protection including restricted permissions, agent identities, runtime monitoring, architectural containment and defined human escalation paths.

The challenge is therefore not simply:

Can the AI reason correctly?

It is also:

What happens if it reasons incorrectly?


10. Why Network Isolation Still Matters

Artificial intelligence may be changing cybersecurity, but many of the oldest security principles remain extremely important.

One of them is isolation.

Imagine a company as a building.

A badly designed building has one enormous room.

Once an intruder enters, everything is accessible.

A more secure building contains separate rooms, locked doors and controlled areas.

Computer networks can follow the same principle.

This is called segmentation.

Sensitive systems can be separated from ordinary infrastructure.

Access can be restricted.

Critical environments can require additional authentication.

AI agents can be confined to particular systems.

The objective is not necessarily to guarantee that nothing will ever be compromised.

That is unrealistic.

The objective is to prevent one compromise from automatically becoming a compromise of everything.


11. The AI Attacker vs AI Defender Cycle

Cybersecurity has always been an evolutionary contest.

An attacker develops a technique.

Defenders learn how to detect it.

Attackers modify the technique.

Defenders develop another countermeasure.

Artificial intelligence may accelerate this cycle dramatically.

The emerging contest can be represented simply:

AI-assisted attack

↓

AI detection

↓

Automated investigation

↓

Defensive response

↓

Attacker adaptation

↓

New defensive model

↓

Cycle repeats

Neither side gains a permanent technological advantage.

Every successful defensive technique creates an incentive to find another route around it.

Every new attack creates information defenders can use to improve detection.

AI therefore does not end the cybersecurity contest.

It may make the contest move much faster.


12. Could Cyberattacks Become Fully Autonomous?

This is where the discussion becomes more uncertain.

It is technically possible to imagine highly autonomous cyber systems capable of receiving an objective, searching for opportunities, selecting tools, adapting to obstacles and continuing without constant human direction.

But it is important not to confuse that possibility with the current state of every cyberattack.

Microsoft’s own threat reporting has emphasized that many AI-enabled attacks still involve humans in the loop.

Autonomy is better understood as a spectrum.

At one end:

Human → tool → human decision → tool

Further along:

Human → AI assistant → human approval → action

Then:

Human → AI agent → multiple autonomous tasks → human supervision

And potentially:

Objective → autonomous agent → sustained operation

Different systems already occupy different points along this spectrum.

The critical security question is therefore not simply whether AI is autonomous.

It is:

How much autonomy has been delegated, and what controls surround it?


13. Why Human Oversight Still Matters

Machine speed does not eliminate the need for human judgment.

It changes where human judgment is most valuable.

Machines are exceptionally useful for processing large quantities of information and performing repeatable tasks.

Humans remain important when decisions involve ambiguity, competing priorities, legal consequences, ethical considerations or potentially irreversible actions.

A cybersecurity system might automatically block suspicious network traffic.

But should an AI independently shut down an entire hospital network?

Should it disable thousands of employee accounts?

Should it isolate critical national infrastructure?

Should it launch a response against infrastructure believed to belong to an attacker?

The consequences become progressively more serious.

The more consequential the decision, the stronger the case for explicit governance and human authority.

Microsoft describes its emerging security model as one in which agents provide continuous execution at scale while humans retain responsibility for priorities, judgment and strategic outcomes.

The future cybersecurity professional may therefore spend less time examining individual alerts and more time deciding what machines are permitted to do.


14. Why Traditional Cybersecurity Still Matters

There is a temptation whenever a transformative technology arrives to assume that everything that came before it becomes obsolete.

Cybersecurity does not work that way.

AI cannot compensate for an organization that ignores basic security.

Weak passwords remain dangerous.

Unpatched software remains dangerous.

Excessive permissions remain dangerous.

Poorly protected identities remain dangerous.

Flat networks remain dangerous.

Missing backups remain dangerous.

Unmonitored systems remain dangerous.

In fact, autonomous agents can amplify weaknesses because software capable of acting quickly can also propagate mistakes quickly.

Microsoft’s research on autonomous agents stresses defense in depth: identity, least privilege, architectural containment, monitoring and deterministic escalation mechanisms remain central to controlling autonomous systems.

AI therefore does not replace cybersecurity fundamentals.

It makes them more important.


15. What Does the New Cybersecurity Battlefield Look Like?

The emerging environment contains several interacting layers.

At the bottom are the systems that organizations have always needed to protect:

devices, networks, applications, cloud infrastructure, identities and data.

Above them increasingly sit AI agents capable of interacting with those systems.

Security platforms monitor both.

Defensive AI analyses signals and searches for threats.

Automated systems may respond to certain incidents.

Human operators supervise the environment and make higher-level decisions.

On the other side are attackers who may themselves be using AI to increase speed, automate tasks and analyse potential targets.

The result is no longer simply:

Hacker vs Security Analyst

It increasingly looks like:

Human + AI vs Human + AI

And eventually, parts of the battlefield may involve:

Machine vs Machine — supervised by humans.


What? How? Why?

What is AI changing in cybersecurity?

AI is increasing the speed, scale and automation of both cyber operations and cyber defence. AI agents can analyse information, use tools and perform certain tasks continuously, allowing activities that once required repeated human intervention to become increasingly automated.

How can attackers use AI?

AI can assist with research, information analysis, social engineering, software analysis and the automation of parts of cyber operations. Current evidence still shows significant human involvement in many AI-enabled attacks, so AI assistance should not automatically be described as fully autonomous warfare.

How can defenders use AI?

Defensive systems can analyse large volumes of security signals, identify suspicious patterns, investigate incidents, discover vulnerabilities and automate appropriate responses.

Why can’t humans simply monitor everything?

Because modern digital environments generate enormous quantities of information, while AI-enabled operations can act continuously and at machine speed. Human attention does not scale at the same rate.

Does AI replace traditional cybersecurity?

No.

Identity management, least privilege, software security, network segmentation, monitoring, patching, backups and resilience remain fundamental.

Will AI replace cybersecurity professionals?

The more likely transformation is a change in their role.

AI can increasingly perform continuous analysis and routine investigation, while humans remain responsible for strategy, governance, judgment and high-consequence decisions.


The Machine-Speed Security Era

Cybersecurity has always been a race.

A vulnerability appears.

Someone discovers it.

Someone exploits it.

Someone detects the attack.

Someone builds a defence.

Then the cycle begins again.

Artificial intelligence does not change that fundamental dynamic.

It changes the clock.

Processes that once depended on hours of human work can increasingly be accelerated or partially automated. Agents can operate continuously. Defensive systems can analyse signals almost instantly. Vulnerability research can be accelerated. Attack campaigns can potentially scale more quickly.

That is what makes the emerging AI cybersecurity era different.

The defining question may no longer be simply:

Who has the better tools?

It may increasingly become:

Who can detect, understand and respond first?

The cybersecurity battlefield is moving toward machine speed.

The challenge for humans will be making sure that, as machines become faster and more autonomous, we remain the ones deciding the rules under which they operate.


 

Related Reporting

The conversation behind this explainer

This explainer was inspired by GZERO Media’s September 27, 2026
interview with Microsoft Security Executive Vice President
Hayete Gallot, conducted by
Tony Maciulis during the
81st United Nations General Assembly.

Gallot discussed the growing role of autonomous agents,
machine-speed defence and the continuing importance of
cybersecurity fundamentals as artificial intelligence transforms
the digital security environment.


AI Agents


Machine-Speed Defence


Cybersecurity


Human Oversight


Watch / Read on GZERO Media  →

 

Open Chronicle Explained

Sources and Further Reading

Selected research, technical documentation and reporting for readers
who want to explore the technologies and security questions examined
in this explainer.

01
AI and the changing cyber environment

Microsoft — Rethinking security for the age of AI

Hayete Gallot’s explanation of why autonomous systems,
machine-speed operations and the changing economics of cyber
threats require a different security architecture.


Read the Microsoft article →

02
Securing autonomous agents

Microsoft Security — Defense in depth for autonomous AI agents

Research into agent identity, least privilege, architectural
containment, human escalation and the security implications
of increasingly autonomous software.


Explore the research →

03
AI-enabled cyber threats

Microsoft Security — Threat actor abuse of AI accelerates from tool to cyberattack surface

An assessment of how threat actors are incorporating AI into
cyber operations, while noting that human operators remain
involved in many current attacks.


Read the threat analysis →

04
Identity for autonomous agents

Microsoft Entra — Security for AI overview

Technical documentation explaining identity, authentication,
authorization and governance for AI agents and other
non-human workloads.


Explore the documentation →

Editorial Note

Open Chronicle Explained
uses the GZERO Media interview as the starting point for this
explainer. The broader explanation incorporates additional technical
material from Microsoft security research and documentation.
Statements about future levels of cyber autonomy are presented as
possibilities rather than established descriptions of all current
cyber operations.

Open Chronicle Explained
What? How? Why?

Understanding the systems behind the headlines.

Explore Open Chronicle Explained →

Leave a Reply

Your email address will not be published. Required fields are marked *