I believe AI is going to make us much more secure.
But probably not tomorrow.
In fact, I think the next two years may be exactly the opposite: attackers will have the upper hand before defenders eventually turn the economics of cybersecurity in their favor.
For decades, we have built software with vulnerabilities and then created an enormous cybersecurity industry around finding, mitigating, patching, monitoring and responding to those vulnerabilities.
AI gives us an opportunity to change that model.
Not just to detect attacks faster.
To find vulnerabilities at machine speed. Fix decades of vulnerable legacy code. Continuously review new code. And eventually make secure-by-design something much closer to reality than the aspiration it has been for years.
Think about where this could eventually take us.
AI has become extremely good at finding vulnerabilities – to the point where remotely exploitable vulnerabilities in well-maintained software may become dramatically harder to find.
That would be an extraordinary achievement for cybersecurity.
But it comes with a price.
Governments and intelligence agencies also benefit today from vulnerabilities they discover and hold for legitimate intelligence and law-enforcement operations.
If AI helps software vendors systematically eliminate those vulnerabilities, governments may lose some of these capabilities. This could increase pressure for “exceptional access” or intentionally engineered backdoors.
We need to be very careful not to respond to dramatically better software security by deliberately making software weaker again.
The uncomfortable period in between
But I believe the more immediate challenge is what happens between now and that future.
Because attackers get the same AI.
And they don’t have to wait for organizations to transform their development processes.
AI can already help search code, identify vulnerabilities, accelerate exploit development and automate activities that previously required highly skilled people and significant time.
Meanwhile, defenders have decades of technical debt to deal with.
Millions of existing applications.
Old libraries.
Legacy infrastructure.
Known vulnerabilities that were never fixed.
And an enormous amount of new code now being generated faster than ever before – increasingly with AI.
At Upwind, we’re already seeing signs that we may be entering this transition period.

Across customer environments, our security teams have observed a significant increase in exploitation activity and attackers moving much faster from vulnerability disclosure to real-world exploitation. Public exploits, automated scanning and increasingly capable tooling are compressing a window that was already getting shorter.
We can’t attribute all of that acceleration to AI. But I believe it is a leading indicator of where we’re heading as AI-enhanced exploitation frameworks and kits become more capable and accessible.
So there is an uncomfortable transition ahead:
AI accelerates vulnerability discovery and exploitation immediately.
AI-driven secure software adoption at scale takes time.
During that gap, I expect attackers to have an advantage.
Secure the code before it reaches production
And this is where I think security and technology leaders need to act.
Just as cloud has become critical infrastructure, we need to start looking at the entire journey from code to cloud as a critical infrastructure security challenge.
Security cannot begin when code reaches production. It needs to be built into the entire lifecycle – from how we write and validate code, through CI/CD, all the way to how we continuously protect and validate what is actually running in production.
If you develop software, security capabilities need to become a native part of your CI/CD pipeline.
Every commit. Every build. Every release.
The ambition should be simple, even if achieving it isn’t:
Code should reach production with zero vulnerabilities.

There is another implication for CISOs and CIOs: our third-party security validation needs to evolve as well.
We still need to understand how vendors secure their code, whether security is embedded into their CI/CD pipelines, and how they prevent basic vulnerabilities from reaching production.
But that is only one side of the equation.
Continuously challenge what is already running
We already have code scanners embedded into development pipelines, and a new generation of AI-native solutions is making them significantly better – helping us find and fix more vulnerabilities before code ever reaches production.
That’s a major step forward. But it doesn’t make production secure forever.
Everything keeps changing.
Our environments evolve. Applications and APIs change. Frontier AI models gain new capabilities. New vulnerabilities are discovered. And attackers continuously adapt their techniques – increasingly using the same AI capabilities available to defenders.
So while shipping more secure code to production is one part of the answer, continuously validating our attack surface once it’s running in production is just as important.
This is why the bigger shift should be from periodic security validation to continuous security validation.

A penetration test performed once or twice a year gives us a snapshot. In a world where code and environments are changing continuously – and both vulnerability discovery and exploitation are accelerating with AI – that snapshot becomes outdated very quickly.
We should increasingly expect continuous testing: constantly challenging applications, APIs and infrastructure, looking for exploitable paths, validating whether security controls actually work, and feeding what we learn directly back into remediation.
In other words, not just “Are we secure?”
But “Can we continuously prove that what we’re shipping – and what we’re running – is secure?”
Soon, “we run a penetration test once a year” should sound as outdated as “we change passwords every 90 days.”
There is a strange paradox here.
AI is going to give attackers capabilities we should absolutely be worried about.
But the same technology may finally allow defenders to attack one of cybersecurity’s oldest problems at its source: the vulnerabilities themselves.
For most of my career, we accepted vulnerable software as an unavoidable reality and built layers of security around it.
Maybe we shouldn’t accept that assumption anymore.
The next two years could be painful.
But if we get this transition right, I believe AI can make the digital world significantly more secure than anything we thought realistically possible only a few years ago.
And that is a future worth building toward.
————————————
This article is based on insights from Jen Easterly’s “The End of Cybersecurity” in Foreign Affairs and Matthew Green’s “Everything is about to ‘go dark’,” combined with my own observations from working with cybersecurity and technology organizations.



