AI meets IT security
Is the AI transformation bigger than the railway expansion and the Apollo programme?
An article published in the Wall StreetJournal in 2026¹compared the expected investments by Meta, Amazon, Microsoft and Alphabet in AI and data centre infrastructure with historical US infrastructure and technology programmes. According to the article, the expenditure forecast for these four companies in 2026 amounts to around 2.1 per cent of US GDP. This exceeds the average annual expenditure on US railway expansion in the 1850s and is significantly higher than that of the Apollo space programme (0.2 per cent), which, after all, did put humans on the Moon:

Important: It is not the total historical programme costs that are being compared here, but the average annual capital expenditure (as a percentage of US GDP). It remains to be seen over what period this investment momentum will continue and whether it will lead to a similarly sustainable wave of infrastructure development as seen with previous major projects. Nevertheless, it is impressive from today’s perspective, and the tech giants seem to be taking the issue quite seriously. But what does this actually mean in concrete terms for all those involved in IT security?
A look at software development
Despite the relatively recent emergence of generative AI technology as we are currently experiencing it, there are already early indications of where this journey might lead. These can be found in software development. Back in January of this year, Andrej Karpathy, a well-known AI researcher, commented on X that his programming workflowhad shifted from 80 per cent manual coding and 20 per cent AI input to 80 per cent AI input and 20 per cent manual adjustments2.
Also at the start of the year, Boris Cherny, developer and head of Anthropic’s Claude Code, wrote that for more than two months, 100 per cent (!) of his programme code has been generated by AI³. He believes that statistics across the majority of the software industry will follow a similar trend in the coming months. Both individuals are, of course, at the forefront of current developments and should therefore be regarded as pioneers rather than the norm. Whether their findings can be extrapolated to the wider industry remains to be seen. Either way, a clear trend is emerging.
Upheavals in IT security
Can we expect to see a shift in IT security too, moving from manual tasks supported by AI towards full automation via AI under the supervision of subject matter experts? Current developments certainly suggest this is a plausible conclusion. In May 2025, a security researcher reported that GPT-o3 – the state-of-the-art model at that time – was able to identify a vulnerability in the Linux kernel in one out of 100 runs, a vulnerability the researcher had previously discovered manually. As an added bonus of this experiment, o3 even discovered a previously unknown vulnerability in the same code 4.
In February, Anthropic reported that, with the help of its Frontier model Opus 4.6, it had already identified more than 500 serious vulnerabilities in open-source projects 5. A month later, Anthropic followed up by describing how a total of 22 vulnerabilities had been detected in Mozilla’s ‘Firefox’ browser. 14 of these vulnerabilities were classified as ‘high’ by Mozilla. According to the researchers, Firefox was chosen as a target because it has a highly complex codebase and is regarded as one of the most thoroughly tested and secure open-source projects worldwide 6.
In early April, the announcement of Anthropic’s latest, previously unpublished model, ‘Mythos Preview’, caused a stir in the security community. This model is said to have reached a level of competence that – with the exception of the most capable experts – surpasses everyone else in identifying and exploiting vulnerabilities, and is reported to have discovered thousands of zero-day vulnerabilities within a few weeks 7. The developers classify Claude Mythos as too dangerous for public release and, as part of ‘Project Glasswing’, allow only a handful of American software and security companies to use it to detect vulnerabilities in their software before other individuals or nations are able to do so. In mid-April 2026, the AI Security Institute reports that, in a simulated corporate network, Claude Mythos manages to completely compromise the network in 3 out of 10 attempts – from the initial reconnaissance phase through lateral movement within the network to the exfiltration of sensitive data 8.
Shortly afterwards, the same institute reported that OpenAI’s GPT-5.5 also managed to fully compromise the network in 2 out of 10 attempts 9. Furthermore, GPT-5.5 is not restricted to individual companies but is publicly available. However, in order to make full use of its cyber capabilities, interested parties must demonstrate, via OpenAI’s ‘Trusted Access for Cyber’ (TAC) programme, that they are active in the field of IT security – in other words, on the ‘good side’ 10.

Implications for corporate IT security
The rapid development of ‘offensive security’ capabilities does indeed bring to mind the opening chapters of relevant sci-fi novels such as Daniel Suarez’s *Daemon* or Andreas Brandhorst’s *Das Erwachen*. It’s not quite that bad, of course, but whilst writing these lines, I couldn’t help but think of those books. But what does this mean for corporate IT security around the globe? The good news: the basics haven’t changed. The bad news: failings in the basics are likely to be ‘punished’ much more swiftly in the near future and will result in far more serious consequences. In the past, IT administrators sometimes still had a few days’ notice before the first widespread waves of attacks could be expected following the disclosure of security vulnerabilities 11:

Even the time from initial infection to the exfiltration of data could, in some cases, still be measured in days. In both instances, it is to be expected that these timeframes will shrink rapidly – due to the anticipated high level of automation.
So what are the ‘basics’ mentioned above that, in light of these rapid developments, are even more important than before?
- Promptly applying published patches, particularly to perimeter infrastructure components such as firewalls, VPN gateways, load balancers, email and remote access systems.
- Keeping the attack surface as small as possible, for example by consistently disabling unnecessary services, restricting exposed management interfaces and maintaining a thorough asset inventory.
- Strengthen resilience and ‘defence in depth’, i.e. network segmentation, directory tiering, zero-trust architecture, least privilege, strong authentication and consistent logging.
- Strengthen detection and response capabilities so that attacks are not only prevented but can also be detected early, assessed and contained.
- Carry out regular penetration tests and – depending on the level of maturity – red teaming exercises to test not only individual vulnerabilities but also realistic attack chains, detection capabilities and response processes.
- Maintain an up-to-date incident response manual that clearly sets out roles, decision-making processes, communication channels, external contacts and immediate technical measures.
- Establish a well-developed backup strategy and regularly simulate disaster recovery scenarios to ensure that recovery is not only theoretically possible but has also been tested in practice.
What next?
The UK’s NCSC (National Cyber Security Centre) emphasises that AI must also be viewed as an opportunity to strengthen defence capabilities 12. Among other things, the centre identifies particular benefits in the following three areas:
- Vulnerability scanning and penetration testing through continuous monitoring of active systems, identification of vulnerabilities and misconfigurations, assessment of exploitability, and simulation of attack paths.
- Threat detection through triage of alerts, identification of patterns in log files, and the generation of reports to support analysts.
- Automated response to threats through blocking network traffic, isolating suspicious processes and revoking permissions.
- CANCOM is currently running several research projects in these areas. The resulting prototypes are delivering impressive results in laboratory environments.
However, whilst attackers have the advantage when using AI in that they do not necessarily have to take risk minimisation and data protection into account, these requirements are essential for the defence side. Ensuring that autonomous systems act in a compliant and predictable manner when simulating attack paths and implementing automation-supported defence is one of the key focuses of this research.
Sources:
[1] https://www.wsj.com/tech/ai/ai-spending-tech-companies-compared-02b90046
[2] https://x.com/karpathy/status/2015883857489522876
[3] https://x.com/bcherny/status/2015979257038831967
[4] https://sean.heelan.io/2025/05/22/how-i-used-o3-to-find-cve-2025-37899-a-remote-zeroday-vulnerability-in-the-linux-kernels-smb-implementation/
[5] https://red.anthropic.com/2026/zero-days/
[6] https://www.anthropic.com/news/mozilla-firefox-security
[7] https://www.anthropic.com/glasswing
[8] https://www.aisi.gov.uk/blog/our-evaluation-of-claude-mythos-previews-cyber-capabilities
[9] https://www.aisi.gov.uk/blog/our-evaluation-of-openais-gpt-5-5-cyber-capabilities
[10] https://openai.com/index/gpt-5-5-with-trusted-access-for-cyber/
[11] https://zerodayclock.com/
[12] https://www.ncsc.gov.uk/blogs/why-cyber-defenders-need-to-be-ready-for-frontier-ai