
Artificial intelligence-powered cyber-attacks are giving new meaning to the phrase, “before they know what hit ’em.”
The lag time between the publication of Common Vulnerabilities and Exposures (CVEs) and an in-the-wild exploit is no longer measured in years or months, but in days. Soon, it’s likely to be minutes. AI is not only making the alarming increase in speed possible, but it’s also fueling the frequency of attacks because top-tier large language models (LLMs) have made the cost of launching an attack dirt cheap, while at the same time making those attacks lightning quick.
To prove the point, OpenAI’s ChatGPT-5.5 recently solved a complicated reverse engineering challenge in 10 minutes, 22 seconds for a mere $1.73 in API token costs. The UK’s AI Security Institute (AISI), which designed the multi-step cyber-attack simulation and conducted the test, said the same task would take a human security expert about 12 hours. Meanwhile, the cost of a manoeuvre like ChatGPT-5.5’s is expected to soon drop to 50 cents.
The turbo-charged exploits enabled by the likes of GPT-5.5 and Anthropic’s Claude Mythos are accelerating the last mile, so to speak, of what was already a steep reduction in time-to-exploit (TTE), which has fallen off a steep cliff in less than a decade.
The average TTE has plunged from 2.3 years in 2018 to one single day, according to Zero Day Clock, a live dashboard that tracks how TTEs have shrunk. The biggest leaps occurred after the arrival of LLMs, which started with ChatGPT’s initial appearance on Nov. 30, 2022. In 2021, the average TTE was still one year, roughly half of what it was three years earlier. By 2025, it was one month. Then, 2026 started with the average TTE at one week before dropping to the current rate of one day. Zero Day Clock projects that TTEs will fall to one hour by 2027, and one minute by 2028.
That really doesn’t give security teams much time to react. To survive, they need to take a similar, AI-powered approach to defending their networks and data. But that will require more than just putting AI tools on the ramparts. Organisations must implement a comprehensive, enforceable AI governance policy and establish an education program to upskill and empower a cohort of AI-skilled, security-trained developers to meet this growing challenge.
The dramatic reduction in the time and cost of a cyber-attack should be a top concern for enterprise security leaders, as it leaves them vulnerable to attacks they never saw coming. As attacks become faster, teams don’t have enough time to prepare and respond, especially when using traditional methods. In 2018, for example, 18.7% of CVEs were exploited on or before the day the vulnerability was disclosed. By 2026, that number was up to 71.4%.
Part of the challenge in defending against hyper-speed attacks is that security teams are often working in the dark. Most organisations lack visibility into how AI tools affect software development and production code, even though 72% of developers in Sonar’s 2026 State of Code Developer Survey said they use AI tools daily. That lack of visibility leaves organisations extremely vulnerable from the inside. In fact, Gartner projects that by the end of 2026, 80% or more of unauthorised AI transactions will result not from malicious attacks but from internal policy violations.
It’s time to rethink some traditional security practices, starting on the ground floor with a comprehensive, reactive AI software governance program.
There are a few important measures CISOs should implement if they haven’t already. For example, they should implement and enforce identity and access management policies while also limiting access to sensitive information or untrusted data. They can use containers to host AI agents and Model Context Protocol (MCP) servers, which allow LLMs to connect enterprise databases, APIs and other external tools with data sources. Behavioral monitoring, typically used to watch over human actions, can also be used to keep an eye on AI agents.
And most importantly, they need to apply zero trust principles, such as continuous authentication and authorisation for both human and machine identities, as well as network segmentation and continuous monitoring.
Some of these steps are familiar, of course, and may already be in place. But the amplified speed brought on by AI could require that established security practices be taken to a new level, while some new procedures may have to be added.
For one thing, when TTEs are down to a day, or hours, or minutes, the idea of monthly patch cycles becomes obsolete. Threat management, including patching, must be done continuously.
A governance plan also needs to include guardrails for AI use and agile policies that can adapt to changes that are bound to occur as AI use becomes more widespread. You also need to keep track of MCP activity to ensure clear observability and traceability and monitor which AI tools are in use, who is using them and how they are being employed.
And a critical step is ensuring that your developers have the security skills and AI tools to protect the codebase.
An organisation’s risk level starts with the quality of its software, which can be rife with vulnerabilities. Developers who aren’t educated in security best practices can overlook flaws, which often make their way into production before security teams have time to mitigate them. Organisations can and should prioritise bringing security into the software development lifecycle (SDLC) early, but the speed of today’s attack cycles requires a bit more. In fact, it’s likely time to replace the SDLC with a more up-to-date Agentic Development Lifecycle designed to deal with what AI agents bring to the table.
A big part of that approach is making sure that developers have the skills and tools they need to guarantee software safety and security while using AI development tools.
The latest AI tools have made cyber-attacks possible almost in the blink of an eye, and the window between the appearance of a vulnerability and its exploitation is going to get even smaller.
CISOs and security teams need to be prepared to confront this onslaught with their own AI-powered tools, but those tools must be guided by strict governance rules and a fully educated developer workforce that knows how to use them.
Pieter Danhieux is CEO & Co-Founder of Secure Code Warrior
Main image courtesy of iStockPhoto.com and phakphum patjangkata
Winstone House, 3rd Floor,
Units 306-309, 2-4 Dollis park,
London, N3 1HF
020 8349 4363
© 2026, Lyonsdown Limited. teiss® is a registered trademark of Lyonsdown Ltd. VAT registration number: 830519543