Cybersecurity Is the New Scoreboard of the AI Race 

Cybersecurity Is the New Scoreboard of the AI Race 

For the past few years, the AI competition was easy to follow. Benchmarks, leaderboards, context windows. Every new model release came with a chart showing who was ahead on reasoning, coding, or some other capability that could be measured and ranked. It was a race with clear metrics.

The picture looks different when viewed from a cybersecurity perspective. 

Something shifted over the past year. Quietly, without much fanfare, cybersecurity became one of the primary arenas in which AI capability actually matters, not in theory, but in operations. The implications reach further than most organisations have caught up with.

The Numbers First

The UK AI Security Institute (AISI) has been evaluating frontier models since late 2023. Their findings, published in the Frontier AI Trends Report this spring, are worth sitting with.

In 2023, AI models were completing cybersecurity tasks at the level of someone with less than a year of experience. By 2025, the first models crossed a meaningful threshold: they began completing tasks of the complexity that organisations would typically hire a senior specialist with a decade of experience to handle. This reflects task complexity rather than creativity or original attack development. Even so, it marks a meaningful operational threshold. The length of cybersecurity tasks that models can complete without human assistance has roughly doubled every 4-8 months. That’s not a projection. That’s the observed trend across multiple models and evaluations.

Recent vulnerability disclosure programmes are beginning to report a noticeable shift. AI-assisted code analysis is identifying substantially more vulnerabilities than traditional manual processes alone. Human researchers continue to uncover the most complex flaws, but AI is increasingly handling high-volume vulnerability discovery. 

The Uncomfortable Part

Here is where the analysis gets harder to sit with comfortably.

RAND conducted a controlled trial between September 2025 and January 2026, testing 157 participants on offensive cyber tasks: network exploitation, vulnerability discovery, attack chains; with half having access to frontier AI models (including OpenAI o3, GPT-5, and Anthropic Claude) and half without.

The headline finding that got quoted most was reassuring: for completely unskilled participants, AI did not produce statistically significant uplift. The absolute floor of the threat landscape didn’t drop.

But read further. For participants with some existing knowledge, AI filled skill gaps and accelerated execution. The threshold you need to clear to be a capable attacker is lower than it was two years ago. And that threshold is still moving.

Both sides of the equation are being upgraded simultaneously. The question that doesn’t have a clean answer yet is which side adapts faster.

Open Source Changed the Geography

Until early 2025, the list of organisations with access to frontier AI capabilities was short. A handful of American labs, some European research institutions, and a few well-resourced government programs.

DeepSeek R1, released in January 2025, disrupted that picture. The Chinese startup claimed to have trained a model competitive with OpenAI’s offerings at a fraction of the cost. Nvidia lost over 600 billion dollars in market capitalisation in a single day. Marc Andreessen called it “AI’s Sputnik moment.”

DeepSeek V4 arrived in April 2026. The Stanford AI Index 2026 noted that Chinese companies have significantly narrowed and in some cases effectively closed the performance gap with their U.S. rivals on key benchmarks.

Open-source models carry a specific implication for security. When a model can be downloaded, fine-tuned, and deployed locally, the question of who controls the infrastructure and whose legal jurisdiction applies becomes largely irrelevant. The capability is simply available to anyone with the technical baseline to use it.

Nation-state actors, of course, operate on entirely different infrastructure. But the two trends together paint a consistent picture: frontier AI capability is concentrating rapidly, and the gap that once defined the competitive landscape is narrower than it was eighteen months ago.

Washington Noticed

On June 2, 2026, President Trump signed an executive order titled “Promoting Advanced Artificial Intelligence Innovation and Security.” It directs agencies to accelerate AI-enabled cybersecurity initiatives and establishes a voluntary framework for early government access to frontier models before public release, specifically to assess security risks. Criminal enforcement against AI-enabled cyberattacks was listed as a priority.

OpenAI had flagged this publicly in December 2025, warning that forthcoming frontier models would pose high cybersecurity risk.

The executive order doesn’t resolve the underlying tension: how you make a model capable enough to be genuinely useful to defenders without making it equally useful to attackers. Technical mitigations exist, guardrails, output filtering, access controls, but none have fully closed the gap.

What Actually Matters for Organisations

The question of which lab is ahead on benchmarks is interesting. It’s not an operational question.

Who controls the AI your organisation uses? Models hosted in jurisdictions with different legal frameworks and different state relationships aren’t simply a data privacy question. They’re a security architecture question.

How are AI-generated recommendations validated? These models make mistakes in sophisticated ways; confident, plausible-sounding mistakes that a tired analyst might not catch on a busy day. The output of an AI model is not the same thing as a verified finding.

Is AI in scope for your third-party risk process? If your vendors and suppliers are embedding frontier models into their products, and some of those models are built on infrastructure you can’t audit, that risk sits in your supply chain whether it’s been formally assessed or not.

And the pace question, which is arguably the most important one: cybersecurity has always been a competition in adaptation speed. AI accelerates both sides. The organisations that treat this as something to evaluate next quarter are already behind the organisations that started evaluating it last year.

The Bottom Line

The AI race isn’t slowing down, and it’s no longer principally about which model writes better code.

The capability to find vulnerabilities, accelerate attacks, and automate offensive operations is now available, improving rapidly, and increasingly accessible. The defensive applications are real and significant. So is everything else.

For security teams, the conversation has moved past experimentation. Governance, validation, supply chain scrutiny, and speed of adaptation are the work now.

Get your pass

The most exclusive Cyber Security EVENTS in the world.

Exclusive C-level cybersecurity gatherings across Europe. Limited seats, maximum impact.

Session reserved
05:00
Your registration session is active. Complete your application within the reserved time.
Next IT Security · East Central
Main Conference Ticket
€495
/ Ticket
Tickets are exclusively reserved for C-level executives from end-user companies of IT security services. September 30, Belgrade.
  • Full-day access
  • 1:1 executive meetings
  • Roundtable sessions
  • Networking dinner
  • All speaker sessions
  • Post-event materials
Workshops — Sold Separately
Workshop 1 Chapter 1 · Compliance & Regulation
From Regulation to Reality: Making NIS2 & DORA Work in Practice
A working session for security leaders who need to translate regulatory requirements into operational plans. Participants work through actual compliance gaps, build a self-assessment framework, and leave with a prioritised action list — without dedicated compliance teams or enterprise-level budgets.
Time
09:00 – 11:00
Format
Masterclass + working groups
Duration
2 hours
Capacity
Limited seats
Workshop 2 Chapter 2 · AI & Emerging Threats
Shadow AI: How to Find It, Govern It, and Not Kill Innovation Doing It
A practical masterclass for security leaders dealing with AI tools that were never approved, deployed without oversight, and are already inside the environment. Participants map their own shadow AI exposure and build a proportionate governance framework.
Time
11:15 – 13:15
Format
Masterclass + case analysis
Duration
2 hours
Capacity
Limited seats
Workshop 3 Chapter 3 · Vendor Dependency & Sovereignty
Managing Vendor Risk Without Rebuilding Your Stack
A strategic working session on third-party risk, technology dependency, and realistic options for East Central organisations. Participants conduct a structured dependency audit, evaluate viable European alternatives, and leave with a vendor risk strategy that is operationally grounded.
Time
13:15 – 15:15
Format
Masterclass + structured audit
Duration
2 hours
Capacity
Limited seats
Workshop 4 Chapter 4 · Cybercrime in a Borderless Threat Landscape
Cross-Border Cybercrime: What Private Sector Security Leaders Need to Know
A practitioner-led masterclass bridging private sector incident response and the realities of cross-jurisdictional law enforcement. Participants learn how cybercrime investigations unfold across borders and how to build an incident posture that works with — not against — public sector constraints.
Time
15:30 – 17:30
Format
Masterclass + Q&A
Duration
2 hours
Capacity
Limited seats
By submitting this form, you acknowledge that you have read and agree to our Privacy Policy .
Next IT Security · Nordics
C-Suite Edition
€990 €0
Promo Code Applied ✓
/ Ticket
Tickets are exclusively reserved for C-level executives from end-user companies of IT security services. October 22, Stockholm.
  • Full-day access
  • 1:1 executive meetings
  • Roundtable sessions
  • Networking dinner
  • All speaker sessions
  • Post-event materials
By submitting this form, you acknowledge that you have read and agree to our Privacy Policy .
Next IT Security · Benelux
C-Suite Edition
€990 €0
Promo Code Applied ✓
/ Ticket
Tickets are exclusively reserved for C-level executives from end-user companies of IT security services. November 12, Amsterdam.
  • Full-day access
  • 1:1 executive meetings
  • Roundtable sessions
  • Networking dinner
  • All speaker sessions
  • Post-event materials
By submitting this form, you acknowledge that you have read and agree to our Privacy Policy .
Next IT Security · DACH
C-Suite Edition
€990 €0
Promo Code Applied ✓
/ Ticket
Tickets are exclusively reserved for C-level executives from end-user companies of IT security services. November 26, Frankfurt.
  • Full-day access
  • 1:1 executive meetings
  • Roundtable sessions
  • Networking dinner
  • All speaker sessions
  • Post-event materials
By submitting this form, you acknowledge that you have read and agree to our Privacy Policy .
Next IT Security · Nordics
C-Suite Edition
€990 €0
Promo Code Applied ✓
/ Ticket
Tickets are exclusively reserved for C-level executives from end-user companies of IT security services. March 11, Stockholm.
  • Full-day access
  • 1:1 executive meetings
  • Roundtable sessions
  • Networking dinner
  • All speaker sessions
  • Post-event materials
By submitting this form, you acknowledge that you have read and agree to our Privacy Policy .
Next IT Security · Benelux
C-Suite Edition
€990 €0
Promo Code Applied ✓
/ Ticket
Tickets are exclusively reserved for C-level executives from end-user companies of IT security services. April 15, Amsterdam.
  • Full-day access
  • 1:1 executive meetings
  • Roundtable sessions
  • Networking dinner
  • All speaker sessions
  • Post-event materials