CYBERSECURITY
This summer, the UK’ s AI Security Institute ran what was assumed to be a routine cybersecurity test on a number of advanced AI models. Except this time, the AI did something we’ d never seen before.
The AI models autonomously decided to deceive people. They created fake identities based on real individuals. They sent spear-phishing emails. They tried to inject malicious code into open-source projects on GitHub. When blocked, they persisted, adapting their approach, trying again through different vectors.
This came on the heels of a series of high-profile incidents, as well as warnings from both Anthropic and OpenAI about the offensive cyber capabilities of frontier AI models. As a result of the doomsday headlines that followed, overnight, the conversation shifted away from the excitement surrounding this next generation AI and toward a far more pressing question: have we entered a losing battle?
The shrinking window In June, research from Anthropic predicted that in the next 6-12 months, multiple AI companies will release frontier models with minimal safeguards. When that happens, the threat landscape shifts permanently. CISOs who haven’ t stress-tested their foundational assumptions by then will be operating with a cybersecurity framework designed for a world that no longer exists.
That leaves you with very little time to unlearn several of the core assumptions that have shaped how we’ ve defended infrastructure for the past two decades. Here are five main assumptions that need to shift first.
“ CISOs who haven’ t stress-tested their foundational assumptions by then will be operating with a cybersecurity framework designed for a world that no longer exists”
Vaibhav Dutta Vice President and Global Head of Cybersecurity Products and Services Tata Communications
70 October 2026