top of page

Cybersecurity and AI: A new frontier to secure

2 hours ago
8 min read

AI isn't inventing a new kind of cybersecurity. It's speeding everything up, attack and defense alike, and humans need to stay in control.


That was the thesis that emerged from an after-work event held on September 22 by EFREI Bordeaux and CEFCYS Nouvelle-Aquitaine (a French association for women in cybersecurity): two talks and a panel on tomorrow's cyber talent. But the idea deserves to be pushed further. AI is no longer just one more tool in the kit. It is reshaping offensive capabilities, defensive capabilities and the very way information systems work, all at once.



And "staying in control" doesn't mean doing everything yourself. Control, oversight, approval and execution are four different things. That's exactly where the debate gets interesting, well beyond the comfortable "AI will never replace humans."

The real question is a harder one: if AI can carry out a growing share of cybersecurity work, what must remain under human control, and why?


1. AI accelerates cybersecurity, on both sides

The word that best sums up AI's effect on cybersecurity is amplifier. It doesn't change the rules of the game; it changes the speed.


On the attack side, the ENISA figures quoted during the evening are dizzying: around fifteen minutes between a vulnerability's disclosure and its exploitation, and 72 minutes from initial access to data exfiltration. A window once measured in months, even years, is now measured in minutes. One concrete example drives the point home. Faced with a password-reset flaw in an open-source identity management tool, an AI agent produced a working proof of concept in about thirty minutes, from a single instruction. What used to mean reading the patch, diffing the code and writing the exploit by hand now fits into a coffee break.


If that holds for a defensive team working within guardrails, it holds even more for attackers, who have no compliance, no sign-off and no ethics to worry about, and who use models without safeguards. The historical asymmetry between attack and defense isn't going away. It's widening.

On the defense side, the gains are real. AI detects faster and better calibrates the severity of SOC alerts. The average cost of a breach fell 9% in 2025 thanks to AI-driven defenses, before rising again in 2026 on the back of AI-driven attacks. Both sides are accelerating at once.


But this acceleration creates a new problem: volume. An organization equipped with cutting-edge AI detection tools could go from roughly one CVE a day to around 500. Not all of them are critical, and some are hallucinations. The bottleneck is shifting: the challenge is no longer finding vulnerabilities but triaging them, prioritizing them in light of each organization's context, and testing continuously rather than once a year.


2. When AI becomes an actor in the information system

Until recently, AI was a tool you consulted. With agents, it becomes an actor: it reads files, calls APIs, runs code, sends requests. It has credentials, permissions, a scope. In short, a non-human identity operating inside your systems.


A question from the audience captured this perfectly. You ask an agent whether a file is malicious, nothing more. To answer, it decodes a base64 payload, follows the URL inside, downloads the resource and runs it in a sandbox. Even when you only ask it to inform, it acts in the real world. The line between informing a decision and making one gets very thin.

Connectors add another dimension. A CRM, a billing tool and a marketing platform used not to talk to each other: each had its own access and its own boundaries. An AI assistant connected to all three builds a bridge between them. What was isolated becomes reachable from a single point, and therefore exfiltrable from a single point. Add shadow AI (personal ChatGPT or Gemini accounts where employees paste sensitive data) and the attack surface changes in nature.


Yet for now, the most common response is… to open everything up. Since nobody is quite sure yet what they want agents to do, they get every permission. That's the opposite of what cybersecurity has learned over fifteen years of identity management: least privilege, segmentation, separation of duties (one agent reads, another writes).

Hence the real question: what are we willing to let an AI do, and with what permissions? This is no longer a technical question. It's a governance decision.


3. Securing AI is about more than securing the model

When people talk about AI security, they think of the model first: can it be jailbroken, can it be tricked into revealing its instructions? That's a real issue. Years after the first demonstrations, prompt injection still has no definitive fix. Models resist better than they used to, but every new release eventually gets bypassed.

But the model is only one layer. An AI system is a model, data, tools, connections and the people who use it. Each layer carries its own risks, and most have already been observed in the wild:

Layer

Risk

Example

Response

Model

Prompt injection, guardrail bypass

Extracting the system prompt

Adversarial testing, output validation

Data

Leakage, poisoning

Semiconductor data leaked via a chatbot at Samsung (2023); around 250 documents may be enough to poison a model

Data classification, control over what goes in and out

Supply chain

Trojaned packages and models

Slopsquatting: attackers register the package names AI "hallucinates"

Vetting dependencies and imported models

Architecture and permissions

Over-privileged agents, connectors that break down silos

An assistant linked to both the CRM and billing

Least privilege, segmentation, human approval

Usage and governance

Shadow AI, no policy in place

Personal AI accounts used at work

Usage policy, approved tools, awareness training

The weakest layer isn't even technical. 96% of CISOs and CIOs consider AI very useful for their defense, yet only 37% of organizations have a policy governing its secure use, and that figure is falling. We are deploying AI faster than we are securing it.

Regulation, for its part, is moving forward. The EU AI Act is being phased in, with full requirements for high-risk systems due in August 2027. But waiting until you're subject to it before writing your own rules would be a mistake. An AI security policy isn't a document for show: it's where you write down what the AI is allowed to do without asking.


4. Humans don't disappear: their role shifts

"AI is an assistant, never a replacement": everyone at the event agreed on that. In a SOC, AI perceives, alerts and recommends, and the human decides. In practice, 70% of CISOs and CIOs keep a human in the loop for critical decisions, but 14% already let AI act on its own.

The principle is sound, but vague. "Staying in control" can cover very different roles:

Human role

What the AI does

What the human does

Example

Execution

Assists

Does the work

Writing an exploit yourself with help from a chatbot

Approval

Proposes and prepares

Signs off on each action before it happens

An agent asks permission before downloading a suspicious file

Oversight

Acts alone within a defined scope

Monitors, can interrupt, reviews afterwards

Automated triage of tier-1 alerts

Control

Acts within the set framework

Defines the rules, permissions and limits, and is accountable for them

The policy stating what agents may do without asking

The mistake would be to think humans must stay at the execution level to remain in control. That's already untrue: nobody manually re-checks the day's 500 CVEs. And requiring human approval for every single action ends up backfiring, with people clicking "yes" without reading.

What must remain human is rather:

•      the framework: defining what the AI is allowed to do, with which permissions and within which scope;

•      the context: knowing what really matters to this organization, what is critical and what isn't;

•      irreversible or high-impact decisions: deleting, shutting down, publishing, exposing;

•      accountability: an AI doesn't answer for its actions, so someone has to answer for them.

An ANSSI report (France's national cybersecurity agency) cited during the evening points the same way: mainstream models, driven by competent experts, are worth as much as cutting-edge models without guardrails. The value doesn't lie in the power of the model, but in the quality of the piloting.


5. Will cybersecurity jobs disappear or transform?

If execution gets automated, what happens to the people whose job it was? The panel didn't settle on a single answer, and that's a good thing: the disagreements were more instructive than a consensus would have been.


Pentesting changes pace. A yearly penetration test makes little sense when a vulnerability can be exploited in fifteen minutes. The job is shifting toward continuous testing, automating part of the know-how, and sorting through what the tools surface.

Juniors are losing their learning tasks. This is the most delicate point. The small tasks once handed to beginners are exactly the ones AI automates best. Some companies are therefore hiring fewer juniors for one-off projects, and more to grow a team over time. The risk is real: if we stop training juniors, where will tomorrow's experts come from? One avenue mentioned: small organizations with no cyber team (non-profits, hospitals, law firms), which are looking for work-study students and where they get to build everything from scratch.

Expertise changes shape. Do you still need to be an expert? For some panelists, AI now carries part of the expertise, and the value lies in the ability to move across topics, step back and question yourself. For others, fewer experts are needed than five years ago, but they are still essential: faced with an AI's output, only a competent person can tell whether it's correct and whether it fits the situation. Without real expertise, it's easier to accept a wrong answer. Both positions meet on one point: we need fewer executors and even more judgment.

New roles are emerging: securing AI integrations, red-teaming models, AI governance, managing agent identities.

The foundations, however, stay the same. The fundamentals (networking, systems, software development) remain essential to understand what you're securing. AI shouldn't be learned as a separate subject: it's one more tool, like math for someone in finance. And it isn't the only frontier, with post-quantum cryptography on the way too. The skill that cuts across all of this is adaptability.


6. A new equation: capability × control × accountability

Everything above can be summed up in a simple equation. The value AI brings to cybersecurity depends on three factors:

•      capability: what AI can do, and it can do more every month;

•      control: the framework it operates in, with its permissions, limits and approval points;

•      accountability: the person who answers for what the AI does.

It's a product, not a sum. If any one of the three drops toward zero, so does the result, or it even turns negative. A highly capable AI without control is an agent with every permission, tearing down the walls between your data. A controlled AI with no one accountable is a policy nobody enforces. And control so heavy that it stifles capability hands the advantage to attackers, who don't wait.

Right now, capability is growing far faster than the other two. That's the challenge for the years ahead: growing control and accountability at the same pace as capability. As one of the speakers put it, the question isn't choosing between AI and cybersecurity, but making them grow together.

Which leaves the question that closed the second talk, one every organization should be asking right now:


In your organization, who is really protecting your AI?


This article draws on the EFREI Bordeaux × CEFCYS Nouvelle-Aquitaine cybersecurity after-work event of September 22, featuring Tarik Ziari (InariSec), Julia Banderier (Themis Cyber), Fériel Bouakkaz, Mouna Andaloussi Stergiou, Manon Souchon-Garrigue and Léo Dupouy, moderated by Aurélie Pougin.

Comments


bottom of page