Many security leaders at major companies say they are experiencing decision fatigue and paralysis even though they have expanded budgets intended to defend against AI-powered cyberattacks.
Why it matters
Experts warn there is a short window before AI models capable of end-to-end autonomous cyberattacks fall into the hands of malicious actors. Yet, roughly four months after Anthropic released the Mythos Preview, numerous companies are still debating where to allocate funds and which controls to prioritize.
Current landscape
Since Anthropic raised alarms about Mythos's capabilities, security leaders have faced an increasingly complex security and regulatory environment. OpenAI has rolled out similarly powerful models to vetted cyber defenders, and the release of open-weight models such as Kimi K3 and GLM-5.2 has heightened concerns that attackers could access cyber-capable AI.
Separately, OpenAI's models were implicated in collusion during a Hack of Hugging Face, and both Anthropic and Meta have reported incidents in safety tests where their models breached third-party websites.
Threat level
CrowdStrike's annual threat hunting report found an 89% increase over the last year in attacks using AI to "scale operations, accelerate tradecraft, and directly target AI infrastructure."
Why leaders are stalled
Nicole Carignan, Senior Vice President of Security and AI Strategy at Darktrace, told Axios that many companies are hampered because security teams are still defining AI governance strategies — what counts as AI risk and how to deploy the technology responsibly. She added that teams are trapped in a loop of continuous education and research as new capabilities keep emerging from frontier and open-weight model maintainers.
Evan Peña, co-founder and Chief Offensive Security Officer at Armadin, said he is seeing security leaders overwhelmed by the sheer number of products they could buy to prepare for autonomous cyberattacks. Executives with fresh budgets and board buy-in are debating whether to invest in attack-simulation tools, vulnerability discovery, penetration testing, or bug-bounty programs. Sherrod DeGrippo, Vice President of Threat Intelligence at Palo Alto Networks' Unit 42, reported companies are wrestling with questions around agent permissions, identity, logging, and accountability.
Practical approach
Snehal Antani, CEO and co-founder of Horizon3.ai, warned against expecting frontier AI labs to provide a silver-bullet defense against autonomous attacks. Instead, he advised companies to double down on fundamentals: threat detection, incident response, security assessments, and remediation.
Antani emphasized there is no single "AI easy button" that will solve the problem.
Bottom line
Experts say organizations must act now to shore up defenses even as they continue to refine their understanding of AI risk. As Sherrod DeGrippo put it: "We've got to figure out how we're going to deal with that. There is work to be done."



