This summer, the UK's AI Security Institute ran what was assumed to be a routine cybersecurity test on a number of advanced AI models. Except this time, the AI did something we’d never seen before.

The AI models autonomously decided to deceive people. They created fake identities based on real individuals. They sent spear-phishing emails. They tried to inject malicious code into open-source projects on GitHub. When blocked, they persisted, adapting their approach, trying again through different vectors.

This came on the heels of a series of high-profile incidents, as well as warnings from both Anthropic and OpenAI about the offensive cyber capabilities of frontier AI models. As a result of the doomsday headlines that followed, overnight, the conversation shifted away from the excitement surrounding this next-generation AI and toward a far more pressing question: have we entered a losing battle?

The shrinking window

In June research from Anthropic predicted that in the next 6-12 months, multiple AI companies will release frontier models with minimal safeguards. When that happens, the threat landscape shifts permanently. CISOs who haven't stress-tested their foundational assumptions by then will be operating with a cybersecurity framework designed for a world that no longer exists.

That leaves you with very little time to unlearn several of the core assumptions that have shaped how we've defended infrastructure for the past two decades. Here are five main assumptions that need to shift first.

Assumption #1 The vulnerability lifecycle still moves at human speed

We’re all used to operating within a discovery-to-patch window measured in weeks. The conventional timeline says: a security flaw is publicly disclosed, a software vendor releases a fix, your team tests it, patches get deployed. This pace shaped everything from monthly patching windows to response time commitments.

But frontier AI agents don't find vulnerabilities the way human researchers do. They automatically scan your applications and systems, not just identifying known published flaws, but uncovering hidden logic gaps and unexpected ways to chain multiple problems together to break security. What a senior security researcher would spend days analysing, these models can generate working attack methods for in minutes. And this takes place across your entire internet-facing environment.

The challenge has shifted from finding vulnerabilities to patching faster than AI can scan.

Assumption #2 Web applications are protected by firewalls and filters at the edge

Traditional web application firewall architectures assume malicious traffic can be recognised and filtered before it reaches the application. That works well for attacks with identifiable patterns, but far less so for requests that appear legitimate – something frontier AI has mastered.

These agents understand what your applications are trying to do. They can find authentication loopholes, exploit legitimate API connections to gain unauthorised access, and manipulate payment and transaction workflows in ways that traditional filters were never designed to detect.

External-facing web applications and API security are becoming prime targets precisely because they sit at the intersection of high business value and complex logic that older defence layers can't reason about.

"You need defences that understand your application's intended behaviour at a deeper level. The edge isn't enough on its own anymore."

Assumption #3: More visibility = more security

Before frontier AI even entered the picture, the average organisation already faced months-long backlogs just to fix critical web application flaws. As a result, your development and security teams were already stretched.

Frontier AI changes the scale of the challenge by increasing how quickly vulnerabilities can be discovered and analysed. The problem is that remediation does not accelerate at the same rate. Fixing vulnerabilities still requires investigation, prioritisation, testing and deployment across complex environments.

As the volume of discovered vulnerabilities grows, the gap between what organisations find and what they can fix will continue to widen. Adding more people alone will not solve a problem driven by machine-speed discovery. Organisations will need intelligent automation to handle routine assessment and response, allowing human expertise to focus on higher-value security decisions.

Simplify-your-spanmulti-cloud-networking-security-and-visibility-hero-banner

 

Assumption #4: You can detect your way to security

Traditional security operations centre workflows assume detection leads to investigation, investigation leads to containment, and containment leads to fixing. This reactive model worked when attackers operated at human bandwidth.

But when an autonomous agent can scan your complete external environment in just hours, and then attempt attacks in parallel across multiple angles, detection becomes a losing battle. By the time your security team identifies suspicious activity, the attacker has already moved deeper into your systems.

The shift requires moving from reactive detection to proactive architecture: designing applications with security built in from the start rather than added later, understanding what an intelligent attacker could theoretically do, and making it harder before an attack even begins.

Assumption #5: Code fixes are the fastest response

Historically, we’ve treated virtual patching as a temporary measure; a protective rule deployed at your firewall or application layer while you wait for the development team to ship a code fix. This assumes adequate time exists between a vulnerability being announced and active exploitation.

That assumption breaks down when frontier AI can exploit newly published flaws within hours of disclosure. Protective filtering at the edge will become your primary defence mechanism, deploying security policies that block exploit attempts without requiring development cycles.

The resilience challenge

Every major disruption exposes assumptions that organisations didn't realise they were making. Frontier AI is beginning to do the same.

If you’re a CISO or work in a cybersecurity function, this will no doubt feel like a fundamental shift in the ground beneath your feet. Everything you've built your security programme around was designed to defend against human attackers. We understand human motivation, human timelines, human constraints. Frontier AI agents don't have those constraints. Which means the assumptions your security architecture is built on are about to become your biggest liabilities.

For UK businesses navigating an already volatile environment, the challenge is not simply managing a new cyber risk, but building the agility to withstand a world where technological change is moving faster than traditional response models were designed for.