
Organisations are quick to publicly showcase their use of AI or highlight the cost savings through the new AI use case. However, this value is not always making it to the bottom line—or public investor reports. Further, boards are working hard to ensure AI is at the top of the agenda, but are trying to decide if cost savings, governance or security should be their primary AI objective.
The reason—we are trying to solve a problem that cannot yet be solved; AI is moving at a speed rarely seen before in technology.
To demonstrate the speed of progress, the National Cyber Security Centre (NCSC) released an article on 30th March stating, “As of March 2026, no public model has completed the full scenario end-to-end.”
The scenario referred to was the AI Security Institute (AISI) evaluating the cyber-security capabilities of seven frontier models, simulating a 32-step enterprise network attack that would take a human 14 hours to complete. This showed a rapid, but incomplete capability, with Claude’s Opus 4.6 completing 22 of the 32 steps. Just over a week later, Anthropic announced its Claude Mythos Preview (7 April 2026), which they held back from public release because it could do so much more than previous models.
The regulators also took notice. On the 15th May, the Financial Conduct Authority (FCA), Bank of England and HM Treasury released a statement articulating that frontier AI models’ cyber-security capabilities can now exceed what a skilled practitioner can achieve faster, at times more cheaply, and at a much larger scale.
As such, the threat landscape has expanded. Tools that were once confined to sophisticated hackers and nation states are now available to the bedroom hacker. This pace of change is why the EU AI Act, in force since August 2024, has had elements of its high-risk regime delayed to December 2027 to simplify implementation, boost innovation and give organisations time to keep pace.
Many organisations are confident they are responding in the right way, and the news flow reflects key changes to the risk landscape resulting from AI.
What is needed now is not another framework or tool - but curiosity - to understand how security threats are changing weekly in response to frontier AI. Curiosity to ask the right questions at the right time. And crucially, curiosity to understand what security changes make the most sense to consider, not simply how to comply with the most recent regulation.
Governance and compliance of these frontier AI tools are constantly competing with an organisation’s need to showcase value from the AI investments.
The World Economic Forum’s January 2026 Global Cybersecurity outlook report showcases the growing gap in the ‘AI Arms Race’ between the pace of cyber-threats and organisations’ or governments’ ability to respond. Frontier AI is rapidly widening this gap, with slower-moving organisations falling further behind.
While the risks associated with frontier AI are front and centre on the cyber agenda and top of mind for boards, the pace of defensive AI is not (yet) moving at the same speed across all organisations. Organisations that have been relatively secure, but operating with 30-day patching SLAs, periodic penetration tests and annual assessments will quickly get left behind. Organisations making use of automated defensive techniques, machine-speed detection and continuous testing will pull ahead, and the gap between them and slower-moving peers will widen as the models improve.
At a time in which frontier AI tools are iterating multiple times in a year, it is pivotal to ask the next hire for your team how curious they are. After all, the next big leap in frontier AI could happen before you read about it in the paper.
Belton Flournoy is Managing Director at Protiviti
Main image courtesy of iStockPhoto.com and Vladislav Chorniy
Winstone House, 3rd Floor,
Units 306-309, 2-4 Dollis park,
London, N3 1HF
020 8349 4363
© 2026, Lyonsdown Limited. teiss® is a registered trademark of Lyonsdown Ltd. VAT registration number: 830519543