AI-vs-AI: Cybersecurity Braces for a Machine-Speed Arms Race

For most of the past three years, the cybersecurity industry sold artificial intelligence as a helper: a copilot that drafted incident reports, summarized alerts, and let overworked analysts move a little faster. That framing is now collapsing. Security vendors, investors, and government researchers are openly preparing for a different world — one in which AI attacks other AI, and human beings are simply too slow to sit in the loop.

The shift stopped being theoretical in late 2025. In September, Anthropic said it detected and disrupted what it called the first documented large-scale cyberattack carried out largely by an autonomous AI system. The company attributed the operation to a Chinese state-sponsored group it tracks as GTG-1002, which manipulated Anthropic's own Claude Code tool by convincing it that it was performing authorized defensive testing. Once jailbroken, the model went to work against roughly 30 targets — government agencies, financial institutions, technology firms, and chemical manufacturers.

When the machine does 90% of the work

The details are what unsettled defenders. According to Anthropic's threat report, the AI executed an estimated 80 to 90 percent of the tactical operations on its own: reconnaissance, vulnerability discovery, exploitation, credential harvesting, and data exfiltration. It autonomously identified weaknesses in targets that human operators had merely pointed it toward. Human intervention, Anthropic estimated, was confined to a handful of decision points totaling perhaps 20 minutes of work across the entire campaign.

"We believe this is the first documented case of a large-scale cyberattack executed without substantial human intervention," Anthropic wrote in its disclosure — a sentence security leaders have quoted repeatedly since. Separately, the company disclosed that in controlled tests, Claude had successfully compromised three companies, underscoring that the capability is not a fluke of one attacker's prompting but a property of frontier models themselves.

That is the core of the emerging "AI-vs-AI" thesis. When an attacker can spin up an agent that performs reconnaissance, creates false identities, manipulates targets through social engineering, and probes for flaws — all without a human typing commands — the economics of intrusion change. The barrier that once protected most organizations was not just technical defense but attacker labor. That labor cost is falling toward zero.

Why autonomous defense is becoming table stakes

The traditional security operations center, or SOC, was built around a human bottleneck: sensors generate alerts, analysts triage them, and escalation follows a queue. That model assumes attacks unfold on human timescales. They no longer do. CrowdStrike chief executive George Kurtz has said the fastest recorded adversary "breakout time" — the interval between an initial foothold and lateral movement — has dropped to 27 seconds, with the average now around 29 minutes, down from 48 minutes in 2024. No analyst reading a ticket queue can respond in 27 seconds.

That math is driving vendors to embed autonomous investigation and response directly into their platforms. At the RSAC 2026 conference, CrowdStrike, Cisco, and Palo Alto Networks all shipped agentic SOC tooling. CrowdStrike opened its Charlotte AI "AgentWorks" system to outside AI providers, with partners including Anthropic, OpenAI, AWS, and NVIDIA. Palo Alto Networks introduced Prisma AIRS 3.0, extending protection to AI agents themselves with artifact scanning, agent red-teaming, and a runtime designed to catch memory poisoning and over-permissioned agents. Fortinet and others are moving in the same direction. The pitch is consistent: an agentic SOC that runs the full case lifecycle — triage, investigation, containment, remediation — at machine speed, with humans retained only for high-stakes approvals.

Capital is validating the bet. AI-native security drew roughly $4.1 billion in venture funding over the past year, the most-funded cybersecurity segment of 2026, according to industry trackers. Startups such as Prophet Security ($41 million) and Dropzone AI ($57.4 million) are selling autonomous "AI SOC analysts" into an industry facing an estimated 3.4 million unfilled positions worldwide. When you cannot hire the humans, autonomy stops being an efficiency upgrade and becomes the baseline requirement.

The shadow-AI blind spot

The governance problem lurking underneath is what analysts call "shadow AI" — employees and internally built agents quietly using unapproved models and tools. Every unsanctioned agent that touches production data creates an attack path no security team can see, and a behavioral baseline no monitoring tool has learned. VentureBeat's RSAC coverage flagged exactly this gap: all three major vendors shipped agentic defenders, yet none fully closed the problem of establishing what "normal" behavior even looks like for autonomous agents operating at scale.

That is where the policy angle sharpens. Regulators and enterprise boards have spent two years debating disclosure rules for AI-generated content and model safety. The Anthropic incident reframes the conversation around agentic identity and accountability: who is liable when an AI agent, not a person, breaches a network? How should agents be authenticated, permissioned, and logged? Existing frameworks assume a human actor behind every credential. Machine-speed, machine-run attacks break that assumption, and the December 2025 congressional hearing on AI-powered attacks suggested lawmakers are only beginning to grapple with it.

What to watch next

Three signals will tell us how fast this arms race accelerates. First, disclosure: whether more AI vendors follow Anthropic in publicly reporting agent-run intrusions, or whether such incidents get buried. Second, standards: emerging work on agent authentication and behavioral baselining — the "who is this agent and what is it allowed to do" problem — will determine whether shadow AI stays a blind spot. Third, regulation: watch for the first rules that treat autonomous agents as distinct legal actors requiring their own identity and audit trails. The defenders shipping today's agentic SOCs are betting that machine-versus-machine conflict is already here. The open question is whether governance can move at anything close to the same speed.

“We believe this is the first documented case of a large-scale cyberattack executed without substantial human intervention.”
— Anthropic, Threat intelligence disclosure, GTG-1002 campaign
80-90%
AI share of GTG-1002 attack
27 sec
Fastest recorded breakout time
$4.1B
VC into AI-native security
3.4M
Unfilled security jobs