Why AI defence will not cancel out AI attackers
You read something about attackers using AI and it lodged. Then a supplier email arrived offering AI-powered defence, and the two clicked together into a tidy story: they have AI, so we need AI, and the invoice is the price of staying level.
Hold that thought, because the two halves are not symmetrical, and understanding why changes what you should buy.
Attacking is a technical problem. Defending is not
The National Cyber Security Centre made this argument plainly in a blog post called One does not simply defend agentically. Agentic tools, for anyone who has not had the term explained, are AI that acts on its own rather than just answering questions: you give it a goal and it works out the steps.
The post borrows a line from the security researcher Halvar Flake: "All offensive problems are technical problems, and all defensive problems are political problems." An attacker's questions are technical. Does this weakness work? How do I avoid being spotted? Those have right answers and an obvious signal when you reach one, which is exactly the shape of problem AI is good at. Point it at the problem and let it run.
Now list the things actually stopping your own defences improving. Getting budget signed off to replace the ageing server. Persuading whoever runs your systems to find a window for patching. Getting a firewall change approved when nobody is certain what it might break. NCSC's own examples, and probably yours.
None of those is a technical problem. They are questions about money, priorities, and who carries the blame if something stops working on a Tuesday morning. As NCSC puts it, defence is "a cost of doing business", one priority among many, while for the attacker it is the whole job. An AI product does not get your change request approved. It does not free the budget. And it will not be the one answering for the shop floor going offline.
That is the asymmetry, and it is structural. AI helps the attacker immediately and cleanly. It helps the defender slowly, through committees.
What that means before you buy anything
None of this says AI defence is useless. NCSC is building a national capability on it, and it sets out sensible ground for where automation is safe to start: tasks where the tool advises a human rather than changing systems itself, on a bounded set of systems, where you could undo it easily if it got things wrong. That is a decent test to hold any pitch against.
But NCSC's closing line is the one for a business your size. Organisations "cannot risk just waiting for agentic defence to roll in and protect them; they also need to be focussing on improving their security the traditional way". Read that as the actual answer to "attackers are getting faster". The gap between a weakness existing in your systems and someone finding it is shrinking, and what shrinks your exposure is not a new product. It is doing ordinary things sooner: knowing what you have that faces the internet, getting security updates on quickly, retiring what no longer gets them, making a stolen password useless on its own. Faster attackers make the fundamentals matter more, not less, because the fundamentals are what close the window.
There is a harder reading too. If your defences are held up by approvals and nervousness rather than a missing tool, the fix is organisational, and the organisation is you. A director can unblock a patching window or sign off replacing an end-of-life system in an afternoon. No product can do either.
What to do
If a supplier is pitching an AI security product, ask these four before the demo:
- What does it do on its own, and what does it only recommend? Anything that changes systems by itself needs a much harder look than anything that advises a person.
- If it acts and it is wrong, how do we undo it? A clean rollback is the difference between a low-risk tool and an outage you paid for.
- Which of our current problems does this actually remove? If the honest answer is "none of the approvals, none of the budget", it is not addressing your bottleneck.
- What would we have to fix first for this to be worth anything? A good supplier will tell you. A bad one will say the product covers it.
And before any of that, confirm the fundamentals: you know what of yours is reachable from the internet, security updates land within days rather than quarters, anything unsupported is retired or isolated, and strong authentication is on everywhere it can be. A business that cannot tick those four does not have an AI problem. It has a Tuesday problem, and AI attackers will find it faster than they used to.
How Steelwise can help
Working out which fundamentals genuinely need attention, before anyone spends money on a product, is the kind of short piece of work we do with businesses that have no security team. Get in touch.
Further reading
- NCSC: One does not simply defend agentically
- NCSC: Thinking carefully before adopting agentic AI
- NCSC: 10 Steps to Cyber Security