AI in cyber security: from evolving threats to automated defence

The advent of artificial intelligence has changed all the rules of the game, including in cybersecurity. It serves as both a powerful shield for defenders and a dangerous weapon for malicious actors.
AI and cyber security: risk or opportunity?
Artificial intelligence makes cyberattacks larger in scale, faster, and much harder to detect. The technical barrier to breaching secure systems has dropped dramatically. In fact, anyone with access to an AI tool and the intent to commit a cybercrime can now do so. Cybercriminals cannot only automate attacks easily, but also generate malicious code in minutes.
However, artificial intelligence is equally essential to defence, giving organisations advanced tools to detect and protect against malicious attacks. In cybersecurity, AI identifies vulnerabilities, analyses massive datasets, automates responses to emerging threats, and recognises patterns that indicate malicious activity.
Artificial intelligence is a two-sided coin — serving as both a threat and an opportunity. At its core, AI is a tool whose impact depends entirely on human intent, raising a critical question: could AI eventually begin acting maliciously on its own initiative?
What AI precedents have occurred in the UK?
Over the past year, AI-driven security incidents in the UK have escalated to unprecedented levels. According to a recent IBM study, more than one in five UK security breaches involve artificial intelligence. AI-powered impersonation was the most common attack type (45% of all cases), followed by malware and AI-leveraged phishing campaigns (19% and 17%, respectively).

UK Cyber Threat Landscape (based on data presented in the article “IBM Study: More Than One in Five Malicious UK Breaches are AI Generated”)
UK fraud prevention service Cifas reported 444,000 fraud cases over the past year, with AI increasingly driving these attacks. Mobile devices, online purchases, and credit cards remained the primary vectors for account takeover scams. Stephen Dalton, Director of Intelligence at Cifas, warns that AI will increasingly enable highly personalised cyberattacks and long-term synthetic identities. This shift underscores the need for cross-sector collaboration to catch early indicators of compromise.
A new wave of concern has emerged over the autonomous, unlawful actions of artificial intelligence. The UK’s Artificial Intelligence Security Institute (AISI) detailed these evolving cyber security challenges after incidents in which advanced language models compromised enterprise systems. While developers stepped in during those 16% of instances where testing ran amok (19 of 122 evaluations), the Institute cautions that safeguards remain lax across both public-facing tools and high-capability frontier models.
Balancing risk and defense: how AI can be used to prevent cybercrime
While AI poses significant cybersecurity threats, it can also strengthen defences. Generative AI is a branch of machine learning that can produce diverse content types, including code, video, text, and images. This core capability enables fundamentally new approaches to cybersecurity. However, these systems rely on massive training datasets to identify patterns and generate effective defensive responses.
Here is how AI is already being deployed to strengthen organisational cyber security:
Threat identification and analysis. AI algorithms establish baseline employee behaviour and immediately flag suspicious activity — such as an off-hours access attempt to confidential files from an unrecognised device.
Automating core security tasks. Generative AI can automate routine security operations by generating code and updating system configurations with minimal human intervention. It can write custom deployment scripts to patch vulnerabilities across dozens of endpoints simultaneously.
Threat and vulnerability modeling. AI can simulate sophisticated cyber-attacks to evaluate organisational resilience and pinpoint system vulnerabilities. These automated exercises also play a key role in security awareness training, helping staff recognize phishing tactics and complex social engineering schemes.
Sources referenced
IBM Study: More Than One in Five Malicious UK Breaches are AI Generated. Available at: https://uk.newsroom.ibm.com/IBM-Study-More-Than-One-in-Five-Malicious-UK-Breaches-are-AI-Generated
AI scams drove UK reports of fraud to record 444,000 last year. Available at: https://www.theguardian.com/money/2026/mar/12/ai-scams-uk-fraud-artificial-intelligence-mobile-bank-online-shopping-cifas
UK experts sound alarm after AI caught trying to trick human with malicious code. Available at: https://news.sky.com/story/uk-experts-sound-alarm-after-ai-caught-trying-to-trick-human-with-malicious-code-13569902
How Can Generative AI Be Used in Cybersecurity. Available at: https://bit.ly/3V9IkHx



