Canary It Solutions

Are You Prepared for a Frontier AI Cyberattack?

Timeline of an AI-assisted cyberattack: attacker, internet-facing assets, automated reconnaissance, exposed vulnerability, foothold established within 60 minutes

Artificial intelligence is changing cyber security, but not through new attack techniques.

Security researchers and AI providers have documented incidents involving exposed AI models, compromised or malicious models, and AI systems used to support cyber operations.

Cases involving Hugging Face, together with research published by Anthropic and other organisations, show that AI models, agents and their supply chains can create pathways for credential theft, malicious code execution, data exposure and other cyber security threats.

These incidents extend the risk beyond an attacker using an AI model to generate malicious code. Staff are increasingly downloading models, connecting AI agents to external services and providing copilots with access to corporate applications and information.

Each of these actions creates additional software, identity and supply-chain trust relationships that attackers may be able to exploit.

Frontier AI enables attackers to perform familiar activities such as vulnerability discovery, exploitation, reconnaissance and understanding attack-paths more quickly and at greater scale.

Recent Australian survey data points to a readiness concern. The 2026 Cohesity Global Cyber Resilience Report (linked in the Australian Cyber Security Magazine) found that only 2% of Australian organisations thought their recovery plans were good enough to address frontier AI threats.

That result reflects a level of confidence rather than technical testing. Even so, it raises an important question for business and security leaders – what does practical preparedness for a frontier AI-enabled cyberattack look like?

The Biggest Change Is Speed

The Australian Signals Directorate (ASD) has warned that frontier AI could reduce the time required for some vulnerability discovery and exploitation activities from days to hours.

That affects an assumption that underpins many security programs.

An organisation may have effective vulnerability management, Endpoint Detection and Response (EDR), incident response and recovery processes. An attacker may now be able to discover a vulnerability, exploit it, compromise an identity and begin moving through the environment before the first security alert has been fully investigated.

Existing cyber security fundamentals are still important and still relevant. Secure configuration, patching, identity security, least privilege, segmentation, monitoring and recovery are not becoming obsolete.

The question is whether those controls can operate within increasingly compressed attack timelines.

The Developing AI Risk Inside Organisations

Frontier AI is changing more than attacker capabilities.

Organisations are increasingly connecting copilots and AI agents to corporate data, applications and external services through Application Programming Interfaces (APIs), connectors and Model Context Protocol (MCP) servers.

‘Shadow AI’ is continuing to emerge and is creating a new trust boundary.

An employee connects a third-party AI tool or MCP server to an approved enterprise AI platform. The integration may gain access to organisational information or invoke tools using permissions granted to the agent.

The external service does not need to contain traditional malware to create risk. Threats include malicious URLs, data harvesting, prompt injection, poisoned content, excessive permissions, compromised third-party services and instructions intended to manipulate an agent into performing unauthorised actions.

Organisations should treat external AI agents, MCP servers, connectors and APIs as untrusted third-party dependencies by default.

It’s critical to understand what these tools can access, where information can be sent, what actions they can perform and how their activity will be monitored.

Is EDR Still Enough?

EDR is still an important defensive control. And you should have it deployed and active across all endpoints. However, endpoint visibility captures only part of an increasingly distributed attack path.

An AI-assisted threat may move between an internet-facing application, SaaS platforms and cloud infrastructure without every action occurring on a traditional endpoint.

Organisations should be focussing on cross-domain detection and response.

Depending on requirements, this may involve Extended Detection and Response (XDR), SIEM or SOC services or a combination of these capabilities.

The technology itself is less important. Defenders need to correlate activity across endpoints, identities, cloud services, networks, SaaS platforms and AI systems, and have visibility to respond quickly enough to contain an attack.

Preparing for Frontier AI Incidents Still Carries Costs That Can’t Be Ignored

Preparing for AI-enabled threats does not require investment in every available security capability. It requires understanding the risks, determining which warrant treatment and prioritising investment accordingly.

Security capabilities have both implementation and ongoing costs. SIEM ingestion and retention, XDR platforms, SOC services, detection engineering, identity security, vulnerability management, backup and recovery capabilities all compete for limited budgets and resources.

Governance activities, including Incident Response Plans (IRPs), Disaster Recovery Plans (DRPs), Business Continuity Plans (BCPs), risk assessments, exercises and assurance activities, also require continued investment.

Risk should drive investment decisions, not technology.

Organisations should identify material attack paths, critical systems and sensitive information, assess the likelihood and business impact of compromise, and determine whether existing controls reduce risk to an acceptable level. Where residual risk remains above the organisation’s tolerance, investment should be directed towards the controls that provide the greatest reduction in exposure.

The same principle applies to telemetry. Collecting every available log is unlikely to be financially sustainable and may not improve security outcomes. High-value telemetry should support defined detection, investigation or compliance requirements. Lower-priority data may justify shorter retention periods, lower-cost storage or no collection at all.

Not every identified risk requires immediate expenditure. Where a risk assessment supports the decision, a risk may be accepted, deferred or monitored and reassessed as threats, business impacts or treatment costs change.

The objective is to prioritise security investment according to risk. Frontier AI may increase the speed, scale or likelihood of some cyber threats, but the underlying management approach remains unchanged: understand the risk, determine the organisation’s tolerance and invest where treatment provides a justified reduction in exposure.

What Does Being Ready Look Like?

A practical test is to assume that an AI-assisted attacker identifies an internet-facing weakness, compromises a user account and then begins automated lateral movement within an hour.

Timeline of an AI-assisted cyberattack: attacker, internet-facing assets, automated reconnaissance, exposed vulnerability, foothold established within 60 minutes
  • Could you detect the activity?
  • Could compromised credentials be revoked quickly enough?
  • Could lateral movement be contained?
  • Could critical services continue operating?
  • Could systems be recovered from data and infrastructure that remain trustworthy?

The same assessment should be applied to internal AI use.

What happens if one of your staff connects a compromised or malicious external AI service to corporate information? (The assumption here is that they didn’t know it was compromised or malicious.)

  • Does the organisation know the connection exists?
  • What permissions has it been granted?
  • Could it access sensitive information?
  • Can it communicate with external destinations?
  • Would the security team detect and investigate the activity?

These are now practical cyber resilience questions that organisations should be able to answer.

Assess Your Readiness

We’ve developed a Frontier AI Cyberattack Preparedness and Agentic AI Risk Threat Intelligence Report that examines these threats in detail. The report includes AI agent, detection and telemetry requirements, EDR and XDR considerations, recovery planning, governance, and the financial implications of improving preparedness.

Download the Threat Intelligence Report to review the findings and assess their relevance to your organisation.

If you need any help to assess your cybersecurity architecture, AI integrations, detection capabilities or cyber resilience arrangements, get in touch to talk through areas that may need further attention.

Author

Are You Prepared for a Frontier AI Cyberattack?