Cyber resilience in an AI-fueled autonomous threat environment

Artificial Intelligence (AI) is reshaping the cyber risk landscape by enabling threat actors to operate with unprecedented speed, scale, and autonomy. Unlike traditional AI tools, agentic AI can independently execute multi-step tasks, navigate workflows, learn from outcomes, and pursue objectives with limited human intervention.
“Agentic AI has the potential to change the way cyberattacks are conducted,” said Ian Walsh, Vice President, U.S. Cyber Product Leader, QBE North America. “Activities that once required expertise, resources and coordination are becoming accessible to a much broader range of threat actors.”
The commercialization and accessibility of agentic AI is effectively lowering barriers to entry for cybercriminals. Threat actors can leverage these tools to continuously scan networks, bypass security controls, identify vulnerabilities, steal credentials, and exfiltrate sensitive data without attracting attention. In many cases, agentic AI can mimic legitimate user behavior, making detection more difficult and allowing attacks to proceed without triggering security alarms.
The impact extends beyond traditional cybercrime. Agentic AI also creates new risks associated with corporate espionage. Autonomous systems can rapidly map organizational networks, identify valuable databases and repositories, and gather sensitive information at a speed and scale that human operators cannot match. “By automating much of the attack lifecycle, threat actors can pursue multiple targets simultaneously while significantly reducing the time required to prepare and execute campaigns,” added Walsh.
An example of these growing capabilities emerged in late 2025, when researchers at Anthropic disclosed an operation involving a suspected state-sponsored threat group that targeted approximately 30 organizations. According to the investigation, Anthropic’s AI tool Claude allegedly performed 80% to 90% of the campaign’s tactical work, including reconnaissance, vulnerability identification, and data exfiltration, while human operators provided limited oversight.
While this case highlighted the potential of agentic AI, it also demonstrated that current systems generated inaccurate information. These limitations may provide some advantages for defenders today, but they are unlikely to remain permanent as AI capabilities mature.
The broader concern for organizations is that agentic AI compresses the attack lifecycle. Threat actors can identify vulnerabilities and exploit them almost immediately after discovery. The traditional cybersecurity model where organizations may have days or weeks to remediate issues is becoming increasingly difficult to sustain.
“As attack timelines continue to shorten, businesses must adapt their approach to cybersecurity,” said Walsh. “Strong security fundamentals remain critical, but businesses also need greater visibility, governance, and oversight across the technologies they are deploying.”
Basic cybersecurity hygiene remains essential. Organizations should maintain rigorous identity and access management controls, continuously verify user identities, and enforce multi-factor authentication across critical systems. Security teams should also limit access privileges, implement short-lived access tokens, and restrict where sensitive information can be accessed, transferred, or stored.
At the same time, businesses should increasingly view their own AI systems as critical assets requiring additional oversight and protection. If AI tools have the ability to access internal systems, process sensitive information, write code, or connect to external services, organizations need robust governance frameworks to monitor their activity and limit potential misuse.
As AI becomes more deeply embedded in business operations, governance efforts have not always kept pace. Security leaders are increasingly focused on establishing clear policies, defining acceptable use cases, monitoring third-party AI providers, and maintaining visibility into how autonomous systems access corporate data and interact with business processes.
Preparation also extends beyond technology. Organizations should conduct regular tabletop exercises and incident response simulations. As attacks become more automated, companies must be prepared to identify, contain, and respond to incidents within minutes.
Regulatory scrutiny is also likely to increase. Customers, regulators, and business partners are expected to demand greater transparency around AI governance, cybersecurity controls, third-party risk management practices, and vulnerability remediation processes. Organizations should be prepared to demonstrate that they are managing AI-related risks responsibly and maintaining appropriate safeguards across their technology environments.
Despite the growing number of cyber incidents, cyber insurance coverage gaps persist. A QBE survey of 400 decision makers of IT, administration or insurance in businesses with 100 to 2,000 employees in the United States found that only 67% have cyber insurance while 24% do not, leaving many organizations exposed to the financial consequences of cyber incidents and emerging AI-enabled threats.
Notably, as these threats evolve, cyber insurance is also evolving. Historically viewed primarily as a financial backstop following a cyber incident, cyber insurance is increasingly becoming part of a broader risk management strategy focused on prevention, preparedness, response, and recovery.
“Cyber resilience is no longer just about recovering from an incident,” said Walsh. “Organizations are looking for support before, during and after an event, including risk assessment, preparedness planning, incident response expertise and guidance on emerging threats.”
Agentic AI represents a fundamental shift in the cyber risk landscape. By accelerating attacks, broadening the pool of capable threat actors, and creating new opportunities for fraud and corporate espionage, technology is reshaping how organizations approach cybersecurity. Companies that combine strong governance, layered security controls, proactive risk management, and appropriate insurance protection will be best positioned to navigate an increasingly autonomous threat environment.