AI Is Becoming a Tool, a Target and a Force Multiplier for Hackers
Artificial intelligence is changing cybersecurity on both sides of the fight.
According to CrowdStrike’s latest threat hunting research, attackers are increasingly using AI to accelerate reconnaissance, vulnerability research, social engineering and other parts of their operations.
But there is another important development:
AI systems themselves are becoming targets.
Organizations are increasingly deploying AI models and agents with access to sensitive data, internal applications, source code and cloud infrastructure.
That creates a new attack surface.
AI Is Changing the Speed of Attacks
Traditional cyberattacks often require attackers to manually analyze information and decide what to do next.
AI can reduce that workload.
Attackers can use AI to:
- analyze large amounts of information,
- automate reconnaissance,
- generate convincing social-engineering content,
- assist vulnerability research,
- analyze stolen data,
- and accelerate operational decision-making.
The result may not always be a completely autonomous attack.
Instead, AI can act as a force multiplier, allowing a relatively small team to perform more work in less time.

AI Is Also Becoming a Target
The other side of the problem is increasingly important.
Companies are connecting AI systems to real infrastructure.
An AI agent might have access to:
- internal documentation,
- source repositories,
- cloud platforms,
- databases,
- APIs,
- credentials,
- and business applications.
If such an agent is compromised, the attacker may not need to attack the underlying infrastructure directly.
They could potentially exploit the AI system as a new route into the organization.
This makes AI security an extension of traditional cybersecurity rather than a completely separate discipline.
The Security Challenge
Organizations now have to defend against attacks using AI while simultaneously protecting the AI systems they deploy.
That creates a new security equation:
AI as a defender + AI as an attacker + AI as an attack surface.
Security teams therefore need to think beyond model accuracy.
Identity, permissions, isolation, logging, monitoring and least privilege are becoming increasingly important for AI deployments.
The question is no longer whether attackers will use AI.
They already are.
The bigger question is whether defenders can deploy AI securely enough to gain the advantage without creating an even larger attack surface.
Source: CrowdStrike — 2026 Global Threat Hunting Report






