AI's most immediate effect on security operations is not a novel attack class but a cheaper, faster retry loop. A failed privilege-escalation attempt used to cost hours of documentation reading and debugging; with a model in the loop, the error is explained, the script fixed, and a new enumeration path tested within minutes. No step is new, but together they strip time, skill, and cost out of the unglamorous middle of an intrusion.
Threat reporting shows the same pattern. State-backed actors first treated generative AI as a productivity tool; later reports described malware phoning a model mid-execution, an extortion operation using AI across reconnaissance, credential harvesting, and ransom demands, and a May 2026 assessment that AI supported both discovery and exploit development for a two-factor authentication bypass. The article is careful to distinguish assessed AI assistance from confirmed deployment in the wild: attribution is hard, prevalence is unclear, and the reports are not a census. The direction, though, is AI sitting inside attacker workflows rather than beside them.
Defenders still run a linear lifecycle, while attackers run loops. Queues and handoffs interrupt the defensive loop at every joint: an alert idles unassigned, identity data lives in another console, and the explanation behind a closed false positive dies in a ticket. Mean time to acknowledge can look good while reconstruction takes hours, and few SOCs measure that decision latency. The five functions of threat intelligence, hunting, detection engineering, investigation, and remediation are not the problem; the transfer between them is, because each handoff squeezes context into an indicator or ticket and loses knowledge about entity identity, evidence, hypothesis, and telemetry sufficiency.
Provider guardrails deserve credit for raising the cost of misuse, but they live outside the enterprise. An operator can reframe a request, move to an open-weight model, split a malicious task into innocent-looking pieces, or wrap tooling around the policy layer. That friction slows misuse without becoming a security boundary. The response, the article argues, is not to start over with every alert but to compress the defender's own loop and measure what the handoffs actually cost.