7 min read

The AI horses are out of the barn: Cybersecurity will never be the same

The AI horses are out of the barn: Cybersecurity will never be the same
Photo by Malcolm Mengesha / Unsplash

We are underestimating the investment required to harden and protect enterprises against the 1-2 punch of security threats from AI and Quantum compute over the next 3-5 years

audio-thumbnail
S3T PodCast Sept 26 2026
0:00
/1303.353469387755

The AI Datacenter backlash is in full swing and looks set to have an impact on US mid-term elections. For context see Cook's latest midterm projections.

But even if that movement succeeds in tangibly slowing down the AI race, nothing will slow down the proliferation of AI driven security threats. Those horses are already out of the barn.

The technology to power super intelligent cybersecurity attacks is in too many hands now. Even if US frontier firms slow down, projects in China and elsewhere will likely not.

And the models created by these projects are converging on similar levels of performance as shown in the chart below.

Courtesy of Standford HAI

Anthropic has released a report on that sheds important light on how threat actors are already weaponizing AI. The report describes 13,873 observations of current real world AI driven cyber attacks and attempts to map them to the MITRE attack framework (industry benchmark for categorizing real world hacking methods.

The report found novel cybersecurity attack techniques that are not even covered in the MITRE attack framework:

☢️ "The MITRE ATT&CK framework doesn’t yet cover the autonomous actions that make these actors so dangerous. Autonomous killchain orchestration, real-time pivot decisions, and AI-directed execution with no human intervention don’t yet have ID numbers in the ATT&CK framework...the behaviors that distinguish the highest-risk actors, and determine the speed and scale of their operations, don’t yet have such IDs. The taxonomy that modern threat intelligence relies on needs to grow" - Anthropic LLM ATT&CK Navigator

Keep in mind this report is not an industry scan of all attacks: this covers only cyberattacks using Claude, where Anthropic detected misbehaviors occurring in specific accounts and banned the accounts for violating Anthropics's usage policy.

Partial screenshot of Anthropic LLM ATT&CK Navigator

From Infra to Security - Expect a Shift in IT Spend & Capital Flows

Our latest S3T Capital Dashboard (Sept 23) indicates a continued strong preoccupation with capital investment in AI infrastructure.

What is somewhat puzzling (ok maybe not, when you consider the players) is how little focus there is right now on the significant investment that will be required to harden and protect enterprises against the 1-2 punch of security threats from AI and Quantum compute over the next 3-5 years:

  • AI security threats which we are currently starting to experience,
  • Followed within a few years by the Quantum compute threats.

Together these 2 threat classes will create vastly more automated and complicated operating environment than what we have today. In a few years they will likely combine to represent a single combined threat.

Which raises a sobering question: will the promised productivity gains of AI be simply repurposed into the new learning curve of AI+Quantum security risk mitigation? OpenAI’s continued disclosures of hacking attacks by its own models suggest we are in an era when US frontier firms are now on the list of potential attackers alongside rogue nation states.

To help us track the implications of AI & Security for future capital flows and IT spend, we've made some important updates to the S3T Capital Dashboard.

Capital Formation vs Capital Flows

We updated the Capital Dashboard to now track Capital Formation signals not just Capital Flow signals. Here's why it's important to track both, and how they differ:

  • Capital flows are inherently backward looking...ie we learn about them as they are happening, or after they've happened.
  • Capital formation signals are forward looking. So we want to start tracking those.

Right now we don't see large capital flows into AI security or Quantum security - not yet. You'll see figures in the dashboard for early movers. They're small amounts compared to the overall capital universe. But we do see important capital formation signals.

Capital formation signals for AI and Quantum security

AI security and post Quantum security represent two very large threat classes that the current set of security players are not fully ready for - though there is significant planning and work underway.

Important point to understand: the activity to date has largely been discovery & planning activity vs. hard capital or operating expenditures. In other words, these are early activities focused on understanding these AI and Quantum as two new threat classes, and coming up with plans and roadmaps for addressing them.

In other words the real spend - the real hit to budgets - has not really started.

These two threat classes will likely become a forcing function that drives new levels of enterprise IT spend, and a new generation of security startups and service companies.

We expect investment themes relative to AI Governance and Security, and subsequently Quantum to take several forms, which are briefly discussed below. We'll continue to monitor and share insights via the S3T Capital Dashboard going forward.

Realtime Controls

AI Governance conjures images of conference rooms or zoom calls with cross functional groups of people reviewing a new AI tool or product, to decide whether it is fit for use in a specific context (clinical, customer service, manufacturing etc).

While human accountability will always be crucial, it will not be meaningful without realtime controls that give humans the ability to know what is happening, and to intervene effectively when needed.

Protecting the scaffolding

The architecture around a specific model or AI agent - sometimes referred to as scaffolding or 'the harness' - includes surrounding cloud services, scripts, or tools that enable an AI model or set of agents to work as a more capable entity. As noted by Anthropic's attack report, these surrounding components are already being leveraged to orchestrate more sophisticated attacks. Security and cloud teams will need to learn how to protect their own scaffolding so it cannot be hijacked to support these kinds of attacks.

Industry Specific Guardrails

AI guardrails for medical research, military, healthcare, education will all be very different - in ways that we likely can't yet articulate.

  • This is the learning curve to anticipate and get organizations ready for (whether it's a startup or a large enterprise). Think in terms of how do we need to take the general best practices and then specialize them to our industry?
  • It's also the key talent selector: watch for individuals who seem to have an early understanding of how to tailor guardrails to specific usage scenarios, and can demonstrate working versions of effective realtime guardrails.
  • Another element: Code of Conduct - the recent OpenAI model misbehaviors are raising awareness of another element: employee behavior. What if an employee tells a model "Feel no obligation to be subservient"? Organizations need to review and update their Codes of Conduct to ensure that employee interactions with LLMs follow policy and do not create safety hazards.

Kill Switches vs Safety Architectures

AI teams and vendors have honed in on the concept of a "kill switch" as a useful AI safety feature. But kill switches are just one piece of the larger AI safety architecture that every enterprise will need. In broader info-security we have come to think of layers of security and defense in depth. We would not simplify cybersecurity down to "oh you just need a firewall." For good context see HAI's piece on slowing AI, and scroll down to the section "Why a 'Kill Switch' Is Not Enough."

Post Quantum Security hardening

This is not unfolding immediately in the same sense that the AI security threat is. As the quantum security threat becomes more imminent, here is what decision-makers and investors need to understand:

  • Large providers have already issued roadmaps for how they will harden their infrastructure in anticipation of Quantum compute threats.
  • As these providers execute the specific upgrades in these roadmaps, corporate customers will be required to make updates to their cloud configurations and applications as well.

IT Leaders should plan to reserve allocations for this kind of spend on their security roadmaps.

Takeaways: Time to scramble

To safely navigate the inevitable convergence of AI and Quantum threats, enterprise leaders need to be proactive, starting right now. It's not just an emerging-risk discussion any more. Leaders need to update their multi-year operating plans.

  • IT Budget Planners and Roadmap Owners should immediately begin reserving capital allocations for adaptive, real-time security architectures and post-quantum hardening into their technology roadmaps. 
  • Talent Leaders need to make it top priority to find and/or develop specialized practitioners capable of engineering industry-specific AI guardrails and enforcing modern, model-aware AI codes of conduct. Smart talent leaders are already building scarce expertise in AI security, real-time governance, cryptography, and industry-specific guardrails. Talent scarcity is going to be an issue that decides winners and losers. Plan - and hire - accordingly.
  • Tech Investors and Consulting/Tech Services Owners should watch for a market shift: from hyper focus on core AI infrastructure to next-generation AI governance, continuous control frameworks, and specialized security startups. Enterprises of all shapes and sizes will need tools and services to help them discover exposure, rethink their security architectures, implement new kinds of realtime controls, migrate infrastructure, so they can operate safely in an environment where AI and quantum security threats proliferate and compound.

Organizations that proactively align their spend, talent, and offerings to these threat vectors today will secure a distinct competitive advantage in an increasingly autonomous and complex risk landscape.

Keep an eye on the horizon. Whatever comes, we’ll figure it out together.

Ralph


Opinions expressed are those of the individuals and do not reflect the official positions of companies or organizations those individuals may be affiliated with. Not financial, investment or legal advice, and no offers for securities or investment opportunities are intended. Mentions should not be construed as endorsements. Authors or guests may hold assets discussed or may have interests in companies mentioned.

(c) 2026 All Rights Reserved. No part of this may be copied or shared without permission.