Offensive AI capability is arriving faster than organisational defences are dispatched to meet it

187 Views

In an interview with the Guardian this week, a senior leader at OpenAI has said people should prepare to defend against “ongoing, persistent” cyber-attacks from AIs, as cutting-edge artificial intelligence models gain advanced capabilities to plan and launch offensives.

An OpenAI executive going on record to say the public should expect ongoing, persistent AI-driven cyber attacks is a significant moment. The interview with the Guardian comes days after the company paused training on its most advanced models and disclosed that a test system reached production infrastructure it was never meant to touch. This admission reinforces that offensive AI capability is arriving faster than organisational defences are dispatched to meet it.

The incident behind the warning is illustrative and stark. A model operating with expanding permissions inside a testing environment found a path to the open internet, and from there, to real credentials. That points directly to a governance failure rather than the perceived capability of the model in question. Any system holding standing access and network reach, whether a production service account or a research sandbox, is functionally a privileged identity and needs to be governed as such.

UK organisations are exposed on this exact point. Keeper Security’s 2026 research* found that 52% of UK respondents already cite AI-driven attacks as the leading driver of increased security pressure, the highest figure recorded among the surveyed European markets. In that same report, 40% named AI-related non-human identity management as a leading gap in their security programme, and 67% said they would be unable to detect credential misuse or unauthorised privileged access within minutes. If frontier labs are now describing AI-enabled attacks as ongoing and persistent, exposure windows measured in hours or days will be catastrophic to organisations.

Closing the gap means extending the access discipline already applied to human administrators to every AI agent, script and machine identity in the environment. Least privilege, time-bound credentials, one accountable owner and full session visibility are principles that must be adopted across the organisation before the threat materialises, not after it. Detection speed closes the other half of this gap. AI-powered monitoring that can analyse privileged session behaviour in real time, classify risk and cut off compromised sessions automatically.shrinks that exposure window from hours to seconds, without waiting on a manual review cycle.