Skip to main content
    Pritect
    All resources
    CybersecurityPerspective6 min readUpdated 22 Jun 2026

    AI in cybersecurity: the double-edged sword

    AI strengthens defence and sharpens attacks at the same time. A practical look at the new threat surface, why AI systems themselves need securing, and how to keep it governed.

    By André Årnes·Cybersecurity Partner, White Label Consultancy

    AI is a double-edged sword in cybersecurity. It makes defence faster and more capable, and at the same time it hands attackers better tools and new techniques. Drawing on themes from ENISA's work on AI and cybersecurity, this piece sets out what that means in practice and how to keep it under control rather than just worrying about it.

    Two edges, one blade

    On defence, AI improves detection, triage, and response, and helps small teams cover more ground. On offence, the same capabilities lower the cost of convincing phishing, speed up vulnerability discovery, and help attackers adapt. The uncomfortable conclusion from the research community is that traditional, static controls are not enough on their own against threats that evolve at the pace of modern AI. The response is not a single product; it is a shift toward continuous, adaptive defence and toward treating AI threats as a first-class category in your risk work.

    Securing AI is now part of cybersecurity

    It is tempting to think of AI as something the data science team owns. But every AI system you run is also an attack surface: training data can be poisoned, models can be manipulated or extracted, and prompts can be abused. Securing the AI development and deployment lifecycle is possible but genuinely complex, and it belongs inside your security programme, not adjacent to it.

    A useful way to organise the risk, drawn from the trustworthy-AI discussion, is three buckets:

    • Technical risks: loss of accuracy, reliability, and robustness.
    • Socio-technical risks: loss of explainability, fairness, transparency, and security.
    • Governance risks: loss of accountability and traceability.

    The technical risks are the ones with metrics. The socio-technical and governance risks are harder to measure and are exactly where most programmes are weakest.

    Use the frameworks that exist

    You do not have to invent the structure. The NIST AI Risk Management Framework gives a way to organise AI risk management, and MITRE ATLAS catalogues real adversary tactics and techniques against machine-learning systems. ENISA's good-practice material for AI cybersecurity is a further reference. Used together, they give you a shared vocabulary and a checklist to assess against, which matters because there is still no single universally accepted standard.

    The human point

    A recurring theme in the research is that human expertise, judgement, and collaboration remain central. AI changes the tooling on both sides; it does not remove the need for skilled people, and the skills shortage in AI-and-cybersecurity is real. The organisations that cope treat AI as an amplifier of a strong security function, not a replacement for one.

    Bring AI systems into the same maturity model and risk register as the rest of your security programme.

    Explore Cybersecurity