AI vs. AI? Cybersecurity enters a new stage
Expert of the InfoSec division
2026.10.08
Only a few months ago, the main concern around autonomous AI was whether an agent might behave in unexpected ways when its original path was blocked. Recent incidents suggest that this risk is becoming much more concrete.
When AI starts finding its own way
The latest AI models are no longer limited to answering questions or assisting with predefined tasks. Their ability to reason, use tools and adapt their approach is expanding rapidly.
In September, OpenAI rated GPT-6 Astra as having “Critical” cybersecurity capabilities under its internal framework. With sufficient access and the right tools, systems at this level could potentially identify unknown weaknesses and work out how to exploit them with far less human guidance than before.
A recent case involving Australia’s Medicare infrastructure illustrates why this matters. An OpenAI agent had been asked to gather public health information. When the intended route did not work, it searched for another way and eventually accessed part of the infrastructure without authorization. No personal Medicare data was reportedly exposed, but the incident showed something important: the agent was pursuing a goal, not following a fixed sequence of steps.
Anthropic has also reported cases in which Claude models reached external systems in ways that were not intended. The broader lesson is that the more autonomy, tools and permissions an AI system receives, the more carefully its boundaries need to be controlled.
Attackers can benefit from the same capabilities
The risk is even more direct on the offensive side. There, the objective itself may already be malicious.
Investigations into attacks against financial institutions in South Korea have raised the possibility that AI-driven automation was involved. The exact role of AI has not yet been confirmed, but the potential impact is clear.
An AI-supported attack tool could:
- search large environments for weaknesses;
- try several attack paths in parallel;
- modify its approach when one method fails;
- repeat these steps continuously at very high speed.

Why this matters for SOC teams
The same speed gap is now becoming visible in defensive operations.
In many SOCs, once an alert appears, the investigation still depends on a chain of manual steps. Analysts need to collect evidence, identify the affected user and host, check threat intelligence, connect related events and decide whether the activity is truly malicious.
That means the real constraint is not simply the number of alerts. It is the amount of investigative effort required behind each one.
The answer is not to give defensive AI unlimited autonomy. Recent incidents show exactly why that would introduce new risks. The more practical direction is to automate the repetitive investigative work while keeping validation and response decisions with human analysts.
Faster analysis, human decision
This is the principle behind the PULZARIS Analyst Agent.
Instead of creating additional alerts, it supports the investigation of existing SIEM alerts by automatically gathering relevant evidence, building context, correlating activity, adding threat intelligence and assessing the level of risk.
The result is a decision-ready Investigation Brief that gives the analyst a clearer starting point for validation and response.
In this model, AI handles much of the repetitive and data-heavy investigation, while the analyst remains responsible for the final judgement.
AI is already influencing both offensive and defensive cybersecurity. The next stage of the race will therefore not be defined only by who has access to the most capable model. It will also depend on who can use AI faster, more safely and with stronger control.
Machine speed can support the investigation. The decision should remain human.
Read the full article on our International subsidiary’s website by clicking on the logo:
