Artificial Intelligence and Cyber Risks

Jennifer Schülzky
by Jennifer Schülzky · 27.09.2026

New threat landscape for companies

AI tools have been used for cyberattacks for years, such as for automated phishing campaigns or the generation of malicious code. In April 2026, the US-based AI company Anthropic announced the launch of Anthropic AI for Enterprise. Presentation of Claude Mythos Preview, a new general language model, but clearly indicating that this development has reached a new dimension.

Mythos Preview and Project Glasswing: A New Dimension of Cyber Risks

According to Anthropic, the new model was able to identify thousands of previously unknown security vulnerabilities of high and critical severity within a short period of time and, upon request, exploit them as well. Affected were common operating systems and web browsers. Interestingly, many of these vulnerabilities are extremely subtle and difficult to detect and have existed for decades. These are so-called zero-day vulnerabilities, that is, errors whose existence was previously unknown.

For example, a 27-year-old vulnerability was identified in the OpenBSD operating system, which is considered particularly secure and is used in, among other places, critical infrastructure. According to Anthropic, even individuals without formal security training were able to develop functional exploits with the help of the model.

Anthropic deliberately did not make the model publicly available and instead published the Project Glasswing It is a collaboration with security researchers, companies, and authorities with the goal of identifying vulnerabilities in common software and IT infrastructure through the use of the new model and responsibly closing them before models with comparable capabilities become widely available and can be misused.

Nevertheless, it is foreseeable that models with comparable capabilities will become more widely available in the future and can therefore be used for abusive purposes as well. Companies should incorporate this development into their risk assessment early on.

How the threat landscape is changing

1. Decreasing entry barriers

Activities such as vulnerability analysis, exploit development, or circumventing security systems have previously required specialized expertise and significant resources. By using AI, these processes can increasingly be automated. This significantly expands the range of potential attackers, as less specialized actors can also access corresponding tools.

2. Acceleration of attacks and shortened reaction times

The tests described by Anthropic not only reveal new attack vectors, but above all a drastic acceleration of existing processes. For example, Mythos Preview was able to develop functional exploits within a few hours – a process that previously could take days or weeks even for experienced security experts.

The time between the publication of a vulnerability and its actual exploitation („Time-to-Exploit“) is significantly shortened. Security vulnerabilities must therefore be detected and closed much faster than before. Delays that were previously tolerable could in the future lead directly to real attacks.

3. Attacks on unknown vulnerabilities

Classical protection mechanisms such as virus scanners, firewalls, or intrusion detection systems regularly rely on known attack patterns. They reach their limits when attacks are based on previously unknown vulnerabilities. Companies should therefore align their IT architecture according to the principle of multi-layered security, so that even if a single vulnerability is exploited, a complete compromise is not achieved.

4. Scaling and automation of attacks

AI enables parallel and continuously optimized attacks on a wide variety of systems with minimal additional effort per target. Current reports show a significant increase in attacks by actors using AI. This fundamentally changes the structure of cyberattacks. They are becoming broader, faster, and more systematic.

5. Increasing pressure for automation on the defense side

At the same time, it becomes clear that AI models already available today are capable of identifying vulnerabilities on a large scale. Companies can actively take advantage of this development, for example for automated software analysis, prioritizing security notifications, or assisting in the remediation of vulnerabilities.

Furthermore, the pressure to automate existing processes is increasing. The expected increase in vulnerability reports and attack attempts will no longer be manageable solely manually. In particular, the response to security incidents, the analysis of alerts, and the prioritization of measures must be supported more by technical systems, including AI.

Importance for companies

For companies, the requirements for IT security are rising significantly. The drivers are both the rapid development of AI and increasing regulatory requirements. Article 32 of the General Data Protection Regulation (GDPR) requires the implementation of technical and organizational measures in line with current best practices. This is continuously evolving through AI. The NIS2 Directive and its national implementation oblige affected companies to comprehensive risk management, technical protection measures, and reporting obligations; the responsibility lies explicitly with the management. With the European AI Act, additional requirements for transparency, security, and risk management are added for certain AI applications.

Conclusion and recommendations for action

Current developments show that the technical prerequisites for cyberattacks are fundamentally changing. Artificial intelligence acts as a catalyst and amplifier of existing risks. Therefore, companies should regularly check whether their technical and organizational measures still comply with current standards and, if necessary, adapt them.

An early and structured approach to addressing the new risks is crucial to avoid security gaps and meet regulatory requirements.

1. Short-term measures

  • Ensure that patch cycles are reviewed and that critical security updates are implemented much more quickly, in particular.
  • Check whether a complete overview of externally accessible systems and digital assets is available; it is a prerequisite for the further implementation of effective protection measures.
  • Make sure that existing incident response plans are up to date and work in the event of an emergency.

2. Medium-term measures

  • Check the use of AI-based solutions for the detection and analysis of security incidents.
  • Ensure that clear internal policies exist for the use of AI.
  • Regularly educate and train employees, especially with regard to increasingly realistic social engineering attacks.

3. Strategic measures

  • Ensure that a structured information security management is established or further developed (e.g., based on recognized standards).
  • Systematically verify and document compliance with regulatory requirements, especially in the context of NIS2 and data protection.
  • Check whether existing safeguards, such as cyber insurance, adequately cover the new risks associated with AI.

Check the mandatory fields –
Step-by-step in the webinar

FAQ

How has artificial intelligence changed the threat landscape for companies?


Why does AI reduce the entry barriers for cyberattacks?


Why must companies close security gaps faster in the future?

Why are traditional protective mechanisms no longer enough?


What legal requirements are relevant for cyber risks caused by AI?


What measures should companies take now?