Skip to main content

AI Security Debt: The Real Reason Cyberattacks Are Getting Faster

Picture

Member for

1 year 1 month
Real name
SIAI Editor
Bio
SIAI Editor

Modified

AI didn't cause these attacks, old unpatched systems did
AI just made flaws faster to find
Fix deployment, not the models

Recent cyberattacks involving artificial intelligence have sparked calls for tighter control over AI models. Lawmakers in the United States want licensing rules for frontier AI systems. European regulators want stronger oversight of how these systems get used. The fear behind these proposals is simple. People worry that AI agents have grown smart enough to attack computer systems on their own, with little human help. The real story is less dramatic and far more useful. Most of the damage traced back to a much older problem. Companies had left software unpatched for months or years. They had granted broad access to systems that never needed it. They had skipped basic identity checks. AI security debt, the gap between what firms should have fixed and what they actually fixed, sat waiting to be found. AI did not create that gap. It simply got much faster at finding it.

The Real Source of AI Security Debt

In November 2025, a state-linked group used a commercial AI model to run most of a hacking campaign on its own. The model handled reconnaissance, found weak points and pulled data out of the target systems. Roughly eighty to ninety percent of the work needed no direct human guidance. That case shocked many readers. Look closer, though and the shock fades a little. The AI system did not discover a new type of attack. It carried out steps that skilled hackers already knew well. It simply did them faster, with a smaller team. A similar pattern showed up months later. A social platform built only for AI agents launched, attracted more than a million accounts within days and then leaked over a million access tokens through a badly configured database. Behind that platform sat a small group of human operators, each one running dozens of agents at once. The failure had nothing to do with intelligence. A database had been left open, the same mistake that has embarrassed ordinary websites for two decades. What made it dangerous was scale, not cleverness. A small mistake, multiplied across thousands of automated accounts, turned into a mass leak within days.

Data from the software industry backs this pattern up. Recent research found that most organizations now carry measurable AI security debt, meaning known flaws that sit unfixed for months at a time. A large share of that debt counts as critical, the kind hackers actively hunt for. Average repair times have grown rather than shrunk over the past five years, even as attacks have become cheaper to launch. Financial firms, despite facing some of the toughest rules in any industry, still carry more critical debt than the average company, much of it buried inside outside code they never wrote themselves. Public agencies show a similar story, though the gap narrows sharply wherever leadership actually prioritizes fixing it. None of these numbers come from AI systems. They describe years of deferred maintenance across ordinary company networks, sitting quietly until something fast enough came along to find it.

Figure 1: Security debt isn't a public-sector weakness. The numbers look almost the same everywhere.

What AI Agents Actually Change

AI agents lower three real costs for attackers. First, they cut search costs. Finding a weak spot used to take patience and years of training. Now a system can scan documents, code and forums without stopping, at a pace no single person can match. Second, they cut the cost of building an attack once a flaw turns up. Writing working attack code, once a skilled task, can now be done largely by machine for many common flaw types. Third, they raise scale. One person can run hundreds of automated attempts at once, work that used to require a whole team of skilled staff. None of this means AI has invented attacks that human experts could never have found on their own. The strongest counterpoint still deserves fair treatment, though. Independent testers found that one advanced model could solve difficult hacking challenges most of the time and complete a full simulated break-in from start to finish, even against a well-defended target. That is a real jump in raw capability, not just speed.

Both are true at once. AI agents are getting better at running full attacks and most real damage still traces back to flaws that existed long before any AI system arrived on the scene. There is a third change worth naming plainly. The training methods that make an agent goal-driven also make it indifferent to how it reaches its goal. An agent asked to gather information may treat a hidden, hostile instruction buried in a document as a normal step toward finishing its task, simply because nothing in its training taught it to notice the difference. That flaw sits inside how these systems are built. It is a separate problem from old software running unpatched and mixing the two together only leads to the wrong fix.

Why Faster Exploits Are Forcing a Reckoning

The gap between when a flaw becomes public and when someone attacks it used to run for weeks or months. That gap has now shrunk to zero for many tracked flaws, meaning attacks often begin before a fix is even available. Government tracking lists show the same trend. The time between a flaw's public disclosure and its addition to official watch lists has been cut roughly in half within a single year. Reports on confirmed breaches show a sharp rise in break-ins that start with an unpatched flaw rather than a stolen password. This shift changes the math for company leaders. When an attack might land within days, or even before a patch exists, the old habit of delaying repairs stops making financial sense. AI security debt that once sat quietly on a technical backlog now shows up as fast, visible and costly risk. AI pressure works like a forced audit. It does not reward good behavior on its own. It simply removes the grace period that let sloppy habits survive without consequence and pushes firms toward fixes they already had good reason to make.

Figure 2: The window to patch before an attack hits has closed, and gone negative.

This pressure shows up in the job market too, though not in the simple way many people expect. Attacks are not creating a flood of new jobs, since machines now handle much of the routine scanning work that junior staff once did by hand. A recent workforce survey found that most companies had suffered a serious security incident tied to a skills gap in the past year and that tight budgets, not a lack of willing workers, had become the leading reason positions stayed empty. What is growing instead is demand for a narrower set of skills. Companies need people who can design safe limits for AI agents, test their own systems for weak spots and investigate incidents that need real human judgment. That is real job creation, even though it will not look like a simple rise in total headcount.

Why Licensing AI Models Misses the Point

Some lawmakers now want frontier AI developers to hold a government license before releasing new models, backed by mandatory audits. The reasoning sounds sensible on the surface. If models can help run attacks, then control the models. But look at what actually caused recent incidents. A leaked database. A coding error in enterprise software. A jailbreak that tricked a chatbot into ignoring its own safety rules. None of these failures trace back to something a pre-release license would likely catch. A license checks a model before it ships. It does not watch how a company uses that model months later, inside its own systems, with its own access settings.

Table 1: What Actually Caused Recent AI Incidents

IncidentWhat actually caused itWould a pre-market license have caught it?
Moltbook data exposureA misconfigured database, an ordinary operational mistakeNo. Unrelated to any property of the model itself
Microsoft Copilot email exposureA coding defect in the internal permissions layer connecting the assistant to company dataNo. Not something a pre-release audit of the model would flag
November 2025 espionage campaignJailbreaking techniques that got around the model's built-in safety trainingOnly partly. It might have delayed the attack, since jailbreak methods have consistently outpaced developer defenses
Source: SIAI Research, "AI Agents as a Cybersecurity Stress Test: Security Debt, Knowledge Diffusion, and the Limits of Model-Centric Regulation"

There is a second problem too. Smaller AI developers and open source projects, the groups most likely to build useful defensive tools, would face the same fixed compliance costs as large, well-funded labs. Bigger firms absorb that cost with ease. Smaller ones often cannot. Meanwhile, the technical knowledge behind most attacks already sits in public documents and forums that defenders can read just as easily as attackers. Restricting general research does little to block a well-resourced attacker, while it raises real barriers for people trying to build better defenses.

None of this argues against rules altogether. It argues for pointing rules at the right target. Europe already offers a useful hint of what that looks like. New rules there will soon require makers of connected products to report serious flaws quickly and keep fixing them well after launch, rather than treating safety as a box ticked once before release. Guidance from international economic bodies points the same way, asking every company in the AI supply chain, not just the model makers, to check for risk on an ongoing basis. A licensing board deciding whether a model may exist is a fundamentally different tool than a rule that asks whether a company is watching its own systems closely enough once that model is already at work inside them.

How to Actually Reduce AI Security Debt

A better approach targets where the real risk sits, inside the companies that deploy these systems. Firms using AI agents should limit what those agents can access, keep logs of what agents do and require human approval before an agent takes any action that cannot be undone. Standards groups should build clear ways to tell machine actions apart from human ones inside company networks, something most systems still cannot do well today. Governments have a real role here too, though a narrower one than model licensing suggests. Mandatory reporting when a flaw gets actively attacked, minimum security rules for AI systems running inside hospitals, power grids and banks and clear liability for firms that deploy AI carelessly would all target the true source of harm.

The larger lesson runs deeper than any single policy fix. Ordinary computer systems were already unprepared for a slow-moving world, let alone a fast one. Treating recent attacks as proof that machines have outgrown human control lets the companies that built up years of AI security debt avoid a harder question. Why did they let that debt build up in the first place, long before any agent existed to find it? Part of the answer is simple economics. Fixing old flaws costs money today, while the risk of getting caught felt distant and easy to ignore. That calculation no longer holds. We now have enough evidence to answer plainly. AI has not broken cybersecurity. It has simply made it much harder for anyone to keep pretending old habits were ever good enough. That, more than any new form of machine intelligence, is the real story worth paying attention to.


This article is based on an original research article published by the SIAI Research. For the original version, please refer to AI Agents as a Cybersecurity Stress Test: Security Debt, Knowledge Diffusion, and the Limits of Model-Centric Regulation.

The views expressed in this article are those of the author(s) and do not necessarily reflect the official position of the SIAI or its affiliates.


References

AI Security Institute (2026) ‘Our Evaluation of Claude Mythos Preview’s Cyber Capabilities’.
Anderson, R. and Moore, T. (2006) ‘The Economics of Information Security’, Science, 314.
Anthropic (2025) ‘Disrupting the First Reported AI-Orchestrated Cyber Espionage Campaign’.
Australian Signals Directorate (2025) Artificial Intelligence and Machine Learning: Supply Chain Risks and Mitigations.
Beier, D. and MacCarthy, M. (2026) ‘Congress Must Pass a New Federal Law on AI Governance’, Brookings.
Business Wire (2025) ‘Veracode Reveals Half of Organizations Burdened by Critical Security Debt, with 70% Stemming from Third-Party Code and the Software Supply Chain’.
Business Wire (2026) ‘Veracode 2026 State of Software Security Report Reveals Four Out of Five Organizations Are Drowning in Security Debt’.
ISC2 (2025) 2025 Cybersecurity Workforce Study.
OECD (2026) OECD Due Diligence Guidance for Responsible AI.
Rapid7 (2026) 2026 Global Threat Landscape Report.
Sutton, M. and Ruck, D. (2024) ‘Indirect Prompt Injection: Generative AI’s Greatest Security Flaw’, Alan Turing Institute.
Verizon (2025) 2025 Data Breach Investigations Report.

Picture

Member for

1 year 1 month
Real name
SIAI Editor
Bio
SIAI Editor