The attacker side of this problem has followed its own evolution. Piotr Wojtyla, who leads Threat Intel at Abnormal AI, describes a three-stage progression in how adversaries are integrating AI into their operations:
Exploration - individual operators experimenting with tools
Industrialization - workflows automated at scale
Fully autonomous attacks - the world that's coming next
"We're in that initial phase," Wojtyla says. "The first six to twelve months were exploration. Then it's industrialization, automation, trying to figure out which workflows to scale. Now we're heading toward that autonomous world."
"We're heading toward that autonomous world. An AI agent that reviews invoices and sends payments—if that agent starts scraping two cents from every transaction, who's going to detect that? That attack use case doesn't exist in our minds yet. But we're inching toward it."
— Piotr Wojtyla, Head of Threat Intel & Platform, Abnormal AI
What this means operationally is that the attack chains defenders have learned to recognize (reconnaissance, initial access, lateral movement) will run faster and at higher scale than any human analyst can triage in real time.
