ao link
Menu
Teiss - Cracking Cyber Security
Teiss - Cracking Cyber Security

Chaos or control?

Organisations are quick to publicly showcase their use of AI or highlight the cost savings through the new AI use case. However, this value is not always making it to the bottom line—or public investor reports. Further, boards are working hard to ensure AI is at the top of the agenda, but are trying to decide if cost savings, governance or security should be their primary AI objective.  

 

The reason—we are trying to solve a problem that cannot yet be solved; AI is moving at a speed rarely seen before in technology.

 

How fast is frontier AI really moving?

To demonstrate the speed of progress, the National Cyber Security Centre (NCSC) released an article on 30th March stating, “As of March 2026, no public model has completed the full scenario end-to-end.”  

 

The scenario referred to was the AI Security Institute (AISI) evaluating the cyber-security capabilities of seven frontier models, simulating a 32-step enterprise network attack that would take a human 14 hours to complete. This showed a rapid, but incomplete capability, with Claude’s Opus 4.6 completing 22 of the 32 steps. Just over a week later, Anthropic announced its Claude Mythos Preview (7 April 2026), which they held back from public release because it could do so much more than previous models. 

 

The regulators are watching

The regulators also took notice. On the 15th May, the Financial Conduct Authority (FCA), Bank of England and HM Treasury released a statement articulating that frontier AI models’ cyber-security capabilities can now exceed what a skilled practitioner can achieve faster, at times more cheaply, and at a much larger scale.

 

As such, the threat landscape has expanded. Tools that were once confined to sophisticated hackers and nation states are now available to the bedroom hacker. This pace of change is why the EU AI Act, in force since August 2024, has had elements of its high-risk regime delayed to December 2027 to simplify implementation, boost innovation and give organisations time to keep pace.   

 

Why curiosity is the new required skill

Many organisations are confident they are responding in the right way, and the news flow reflects key changes to the risk landscape resulting from AI. 

 

What is needed now is not another framework or tool - but curiosity - to understand how security threats are changing weekly in response to frontier AI. Curiosity to ask the right questions at the right time. And crucially, curiosity to understand what security changes make the most sense to consider, not simply how to comply with the most recent regulation. 

 

Governance and compliance of these frontier AI tools are constantly competing with an organisation’s need to showcase value from the AI investments. 

 

The World Economic Forum’s January 2026 Global Cybersecurity outlook report showcases the growing gap in the ‘AI Arms Race’ between the pace of cyber-threats and organisations’ or governments’ ability to respond. Frontier AI is rapidly widening this gap, with slower-moving organisations falling further behind.  

 

While the risks associated with frontier AI are front and centre on the cyber agenda and top of mind for boards, the pace of defensive AI is not (yet) moving at the same speed across all organisations. Organisations that have been relatively secure, but operating with 30-day patching SLAs, periodic penetration tests and annual assessments will quickly get left behind. Organisations making use of automated defensive techniques, machine-speed detection and continuous testing will pull ahead, and the gap between them and slower-moving peers will widen as the models improve.  

 

Where to start

  1. Understand how your attack surface has evolved, with a focus on external-facing assets. With over 45% of vulnerabilities in large organisations remaining unpatched after 12 months, this previously lower-risk attack surface needs to be re-evaluated. 
  2. The way you assess the risk of vulnerabilities has inherently changed. A collection of previously medium-severity issues may now collectively provide a direct path to a critical system, despite a higher-ranked issue being harder to exploit.  
  3. Identity should remain a key priority; many incidents occur due to identity abuse. Implement a robust inventory for all identities, including machine identities, enforce least privilege and ensure privileged access has been appropriately defined. Accelerate the use of conditional access and behavioural analytics, which can give early signals of potential misuse, when, not if, an incident occurs. 
  4. Cyber-resilience strategies must incorporate post-March 2026 frontier AI model considerations. The years of annual assessments are changing. A curious team should ask how this might impact our environment, not just how we are aligning to existing controls. 

At a time in which frontier AI tools are iterating multiple times in a year, it is pivotal to ask the next hire for your team how curious they are. After all, the next big leap in frontier AI could happen before you read about it in the paper.

 


 

Belton Flournoy is Managing Director at Protiviti

 

Main image courtesy of iStockPhoto.com and Vladislav Chorniy


Please take 30 seconds to register

Register Now

 

Already have an account? Sign in

Remember Login
Teiss - Cracking Cyber Security

Subscribe to our Weekly Newsletter

Receive the latest insights direct to your inbox, and gain access to our exclusive events.
Teiss - Cracking Cyber Security

Winstone House, 3rd Floor,
Units 306-309, 2-4 Dollis park,
London, N3 1HF

 

020 8349 4363

info@teiss.co.uk

 © 2026, Lyonsdown Limited. teiss® is a registered trademark of Lyonsdown Ltd. VAT registration number: 830519543