Enterprise cybersecurity has entered a new phase, requiring a practical security operating model that closes the gap between knowing about risk and protecting live systems.
As Cisco’s Talos Intelligence research team puts it, “The era of agentic attackers has effectively arrived.”
Just as concerning is Talos’ finding that model guardrails are not reliably stopping misuse. The researchers wrote:
“One of the immediate takeaways is that guardrails are not functioning as expected. We did not encounter any sophisticated encoding or techniques designed to trick the models — most of the time it was a simple ‘I'm allowed to do this,’ and the model complied. When guardrails did engage, they accomplished little.”
The teams’ findings challenge a common assumption that AI platforms’ built-in controls will be enough to prevent malicious or risky activity. In practice, organizations should assume that attackers can still use AI systems to support parts of their workflow, even when those systems have nominal safety restrictions.
That does not mean every attacker is suddenly advanced. Talos found that skill still matters, as novices often generate flawed tooling, while sophisticated actors use AI as a true force multiplier. But AI is clearly reducing friction across the attack lifecycle.
The enterprise response cannot be another static checklist. It has to be a practical operating model built around speed, prioritization, automation, and customer trust.
As Brian Gracely, Senior Director of Portfolio Strategy at Red Hat, told CX Today in a recent interview, the issue is getting fixes into production fast enough once vulnerabilities are uncovered.
“The reality for most enterprise customers is the amount of time it takes them to get from getting that patch to getting it into production, getting it into their systems that are live, oftentimes takes quite a long time… 40 days, 50 days, 90 days.”
In the AI era, that timeline is becoming harder to defend.
As Quincy Castro, Chief Information Security Officer at Chainguard, told CX Today, organizations are facing “an inherent mismatch” between the speed of AI-enabled vulnerability discovery and the slower processes many enterprises still rely on to remediate software risk.
So, what should enterprises do now?
-
Accept That Attackers Are Already Using AI
The first step is organizational acceptance. AI-enabled cyber risk is not theoretical, or limited to one frontier model. Attackers are already using AI because it helps them move faster.
Gracely put it plainly:
“Whether or not you love the AI technology or you have concerns about the AI technology, the reality is attackers don’t really care about your opinion of it, your emotions around it.”
“They’re looking at it as this makes my life easier, this makes my life faster in terms of being able to break into things or steal things or create situations that are advantageous to them,” Gracely added.
The team at Talos reached the same conclusion from its research:
“From an enterprise perspective, organizations need to understand that threat actors are heavily leveraging AI capabilities in their pipelines, and defenders need to do the same.”
Practical steps:
- Update threat models for AI-assisted reconnaissance, exploit development, phishing, and credential theft.
- Brief boards and executive teams on AI-enabled cyber risk as a current business issue.
- Treat AI cybersecurity as a shared concern across security, engineering, IT, compliance, legal, and customer experience.
- Stop assuming attackers need elite skills for every stage of an operation.
As Talos warns: “The capabilities exist; the only missing ingredient is malicious intent, and it’s a matter of time before threat actors supply it.”
-
Close the Patch-to-Production Gap
Many enterprises can now identify vulnerabilities faster than they can remediate them, creating a dangerous gap. A company may know a vulnerability exists, have a patch available, and still remain exposed because internal change processes are too slow.
Gracely described this as the “patch-to-production challenge” and framed the core question as: “How fast can we get you from having a patch to getting that into production?”
Castro made the same point from the vulnerability management side, telling CX Today that the ability of frontier models to find vulnerabilities changes remediation expectations.
“The policy says 30, 60, 90, and that’s how we do it — that’s dead. We’re just not going to live in that world anymore.”
Practical steps:
- Measure average time from patch receipt to production deployment.
- Create accelerated paths for critical and externally reachable vulnerabilities.
- Pre-approve emergency change processes before a crisis.
- Automate testing and deployment where possible.
- Maintain rollback plans to reduce outage risk.
- Prioritize remediation by exposure, exploitability, and business impact.
The goal is safe acceleration.
-
Prioritize Exploitability, Not Just Severity
Traditional vulnerability management often starts with severity scores. That still matters, but AI makes context more important.
Attackers can use AI to understand how multiple lower-severity weaknesses might be chained into a larger compromise. Castro warned that even less-skilled attackers could use AI systems to analyze many vulnerabilities and find a path to domain administrator access.
The Talos research team also observed adversaries using AI for vulnerability research, credential harvesting and expanding proof-of-concept code into more scalable exploitation pipelines.




