Cybersecurity is entering a new phase: AI is increasingly being used on both sides of the attack.

On October 1, 2026, Thales CEO Patrice Caine called for organizations to “fight AI with AI”, arguing that AI-powered defenses are needed to counter increasingly automated and sophisticated cyberattacks. Reuters reported that some attacks are becoming autonomous, reducing the need for direct human involvement.

⚔️ Why AI changes cyberattacks

Traditional cyberattacks often require significant human effort—finding targets, identifying vulnerabilities, creating phishing messages and adapting attacks.

AI can automate portions of this process.

According to Thales' 2026 research, organizations reported increasing AI-related threats including sensitive-data attacks and AI-generated misinformation. Thales says 61% of surveyed organizations reported their AI applications were being targeted by attackers. The research surveyed 3,120 security and IT professionals globally.

AI-enabled bots are another emerging problem. Thales reports that daily AI-enabled bot attacks increased from 2 million to 25 million in one year in its analysis of bot activity.

🛡️ So how does AI fight back?

The basic idea is simple:

Attacker AI → finds and exploits weaknesses
⬇️
Defender AI → detects unusual behavior
⬇️
Automated response → blocks or isolates the threat
⬇️
Human security team → investigates and makes critical decisions

AI can analyze huge amounts of network activity much faster than a human security team. It can look for abnormal login behavior, suspicious traffic, unusual API requests and other patterns.

Thales is also developing systems designed to protect AI applications and autonomous AI agents. Its current security work includes protection against AI-assisted vulnerability discovery, exploit generation and reverse engineering.

🧠 But there's a problem

Using AI to defend against AI doesn't automatically make systems secure.

A defensive AI system can itself become a target.

Attackers may attempt to:

  • manipulate AI inputs
  • steal credentials
  • exploit vulnerable AI applications
  • inject malicious instructions
  • trick automated systems into making unsafe decisions
  • use AI to generate convincing phishing campaigns

That creates a difficult question:

What happens when both the attacker and defender can operate at machine speed?

The answer may depend less on having the “smartest” AI and more on how well organizations combine AI automation, access controls, monitoring, encryption and human oversight.

🌍 The bigger picture

The cybersecurity industry is moving toward an environment where humans aren't necessarily responding to every individual threat.

Instead, AI systems may continuously:

Monitor → Detect → Analyze → Respond → Learn

That could dramatically reduce the time between detecting an attack and responding to it.

But completely autonomous cybersecurity also introduces new risks. If an AI system incorrectly identifies legitimate activity as malicious, an automated response could disrupt important services.

So the future isn't necessarily humans vs. hackers.

It increasingly looks like:

AI attackers vs. AI defenders—with humans controlling the rules.

And that may become one of the defining cybersecurity battles of the next few years.

Source: Reuters, October 1, 2026; Thales 2026 Data Threat Report.