Artificial Intelligence

Fear of AI is growing, but is the fear justified?

By
3 Minute Read

On 27 August 2026, over 100 technology companies, including Anthropic, Google, Microsoft and OpenAI, signed an open letter calling for greater collaboration to defend against AI-enabled cyber threats. 

The irony is difficult to ignore.

The same companies investing billions to advance AI are also warning about the risks it creates.

Should we be worried?

Popular culture would suggest so.

The Terminator imagined a future where autonomous military AI escapes human control. Recent events in Ukraine show that autonomous systems are no longer science fiction. AI is increasingly influencing critical infrastructure, defence capabilities and everyday life.

But perhaps the greater risk is not AI itself.

Perhaps it is the way it is arriving.

Unlike previous technological revolutions, AI is advancing gradually. Each new capability appears incremental. Each new use case seems reasonable. Yet humans often struggle to recognise slow-moving change because we notice contrast more easily than progression.

Early in my career, I worked on the safety and security of strategic nuclear weapons. What struck me then, and still does today, is that the challenge was never just the technology. It was governance, accountability, operational discipline and ensuring human judgement remained firmly in control.

While concerns around AI-enabled cyber-attacks are valid, recent events such as the Hugging Face breach may prove more significant as a warning sign than a catastrophe. They suggest governance and control frameworks are struggling to keep pace with the technology they are meant to oversee.

The real question is not whether AI can create risk.

It is whether we are consciously managing that risk while pursuing the benefits.

Admiral Hyman G. Rickover, the father of the nuclear navy, once observed:

"The devil is in the details, but so is salvation."

History offers a useful lesson

Nuclear technology has delivered immense benefits and immense destruction. Society responded with governance, safety frameworks, treaties, regulations and oversight. The technology itself was neither inherently good nor evil. The lesson for AI may be similar.

The question is not whether AI is dangerous.

The question is whether governance, security controls and operational discipline can evolve as quickly as the technology itself.

For organisations, that starts with the fundamentals; including but not limited to knowing where AI is being used, understanding its influence and maintaining human accountability and the application of security fundamentals, Contextual, risk-based, defence-in-depth and people enablement/investment.

Fear alone has never solved a technological challenge. Discipline, governance and responsible adoption have.

Is AI our next nuclear moment, is governance keeping pace or are we overestimating the risks and underestimating the benefits?

We can already see this governance challenge playing out in cybersecurity.

AI is rapidly improving our ability to find potential vulnerabilities, but finding more does not automatically mean understanding more or becoming more secure. The real value will come from combining AI’s speed and scale with the context, evidence and human judgement required to decide what is relevant, what is exploitable and where action is genuinely needed.

Two developments are particularly noteworthy. The first is the rapid advancement of AI-driven vulnerability discovery, while the second is the emergence of AI-enabled attacks that are evolving in sophistication and altering the nature of cyber risk itself.

Focusing on the former, AI tools can now analyse vast codebases, configurations and software dependencies and identify potential weaknesses at a scale and speed never previously possible.

At face value, it sounds like an overwhelmingly positive development but in reality, presents a challenge many organisations are coming to realise.

Whilst AI may be finding more vulnerabilities than ever it doesn't necessarily make us more secure.

Why, because discovery is accelerating far faster than our ability to interpret, prioritise and act. Many organisations are already struggling with:

CVE backlogs
Advisories
Alerts
Threat intelligence feeds
Audit and regulatory requirements

The result is something intelligence analysts have faced for decades: More information does not automatically create more understanding. It often can result in uncertainty.

The question becomes:

"Which vulnerabilities actually matter?" and "Where should I act?"

This is also where context becomes critical.

When a vulnerability is identified, leaders need to understand:

Is the affected component present within our environment?
Is it exploitable? Is there any evidence of it being exploited 'in the wild' (forensic report / PoC)?
Does a realistic attack path exist?
What business services are affected?
What controls already reduce the likelihood of exploitation?
What action is proportionate to the risk?

AI can help identify potential weaknesses. What it cannot yet reliably provide is organisational context.

Those decisions currently still require evidence, validation and judgement.

This distinction is becoming increasingly important as regulatory frameworks evolve to emphasise demonstrable risk management rather than simple technical activity. In other words, leaders should be moving beyond questions such as:

"How many vulnerabilities do we have?"

and ask:

"Which vulnerabilities represent material risk to the organisation?"

The organisations that benefit most from AI-driven discovery will not necessarily be those that identify the largest number of vulnerabilities.

They will be those that develop the capability to rapidly determine:

What is relevant?
What is exploitable?
What is material?
What action is appropriate?

It will be those that can transform an increasing volume of intelligence into informed, evidence-based decisions.


Register your interest for The Security Event 2027  

Subscribe to The Security Briefing for monthly updates!

Ben Lipczynski

Ben Lipczynski

Origina Director of Security Services Ben Lipczynski served for 12 years in the British Royal Navy where he was responsible for the operational delivery, safety and security of numerous capabilities and systems, including advanced security solutions, mission-critical information systems, and strategic weapons engineering operations. After a stint as a Global IT/Communications Networks Operations Manager for the U.K. Ministry of Defense, Ben held various corporate cybersecurity roles at EY, Accenture, and Deloitte before joining Origina. He holds two patents, one for a multimodal object detection system with a 5G array and another for a dynamic end point configuration-based deployment of network infrastructure. Ben is also the author of the Contextual, risk-based, defense-in-depth framework.

Author