AI and the Changing Cybersecurity Landscape

By Mumeenah Oyindamola Abdulrahman

There is something mildly unsettling about teaching a machine to recognise an intruder, only to discover that the intruder has access to the same machine.

Cybersecurity has always been a contest of time. Someone finds a weakness, someone else notices it, patches it, blocks it, or arrives five minutes too late and writes an incident report. Artificial intelligence has not changed that basic arrangement. What it is changing is the speed at which both sides can participate.

For defenders, this is useful in a very practical sense. A security team may be staring at millions of login attempts, network events, emails and endpoint alerts, most of which are harmless and a few of which matter a great deal.

Machine-learning systems can look for patterns humans would struggle to notice at that scale: a user suddenly signing in from an unusual location, a device behaving differently from its normal pattern, or a stream of messages carrying signs associated with phishing.

Generative AI can go a step further by summarising alerts, connecting related events and helping analysts decide what deserves attention first. Microsoft, for instance, already describes AI-assisted threat analysis and automated actions such as suspending suspicious accounts or initiating password resets as part of modern defence.

That sounds suspiciously close to replacing the analyst. It is not. A model can tell you that something is unusual. “Unusual” and “malicious” are not synonyms.

A legitimate employee travelling abroad can look suspicious. So can a badly configured server. And an AI system asked to explain an incident can produce a confident answer that is simply wrong. Cybersecurity has always had false positives; now we have the possibility of false explanations too.

The attackers, naturally, are not sitting around admiring the innovation. In January 2025, Google’s Threat Intelligence Group reported that state-backed and criminal actors were already using generative AI for things such as reconnaissance, phishing content, vulnerability research and code troubleshooting. At the time, the important detail was almost anticlimactic: the technology mostly made existing work easier rather than granting attackers completely new powers.

United Kingdom’s National Cyber Security Centre reached a similar conclusion, assessing that AI would primarily increase the effectiveness and volume of familiar attack techniques through 2027 rather than suddenly produce entirely new forms of intrusion.

Then the line began to move. By May 2026, Google reported the first case in which it believed a threat actor had used AI to help develop and weaponise a zero-day vulnerability. That does not mean an AI independently woke up, discovered a vulnerability and decided to ruin somebody’s day. Google’s assessment was more careful than that. But it does suggest that the gap between AI as an assistant and AI as a genuine expansion of capability is becoming less comfortable.

This is where the real problem sits. AI lowers the cost of competence. A convincing phishing email once required some knowledge of the target, decent writing and enough patience to personalise the message.

Generative AI can help produce hundreds of variations, in several languages, with fewer obvious mistakes. Reconnaissance can be summarised. Stolen information can be processed faster. Malware code can be debugged. Deepfake voices and synthetic identities make impersonation cheaper.

None of these ideas are new, which almost makes them more worrying. Criminals do not need science fiction when ordinary fraud suddenly becomes easier to scale.

But defenders get the same advantage. AI can shorten investigation time, correlate signals across systems and automate simple responses before an analyst has finished making coffee. The temptation, then, is to automate further. If the machine can detect, investigate and respond, why keep the human in the loop? Because the loop is exactly where judgement lives.

Security decisions are not made in clean laboratory conditions. They involve incomplete evidence, business context, privacy, consequence and sometimes the uncomfortable choice between shutting down a service and taking the risk of leaving it running. AI may become better at recommending that choice.

It may even become better than humans at parts of the reasoning around it. But a system that can be manipulated, fed misleading information or simply arrive confidently at the wrong conclusion should not quietly become the final authority because it works faster.

Perhaps the arms race is not really between human hackers and intelligent machines. It is between people who learn where to trust automation and people who learn where to exploit that trust.

The more capable the machines become on both sides of the door, the less useful it is to ask whether AI is “good” or “bad” for cybersecurity. The better question is who remains capable of judgement when speed stops being the scarce resource.

*Mumeenah is a Computer Science student at Kwara State University (KWASU). She can be reached at [email protected]*

Bank Recapitalization-abacha-university-ad