A leading former intelligence analyst from the UK's Government Communications Headquarters (GCHQ) warns that artificial intelligence is fundamentally altering the cybersecurity landscape, forcing corporate executives to either upskill or leave their organizations exposed. Professor Julian Richards, who held senior roles at GCHQ, argues that the same AI tools defending businesses are being used by attackers to scale breaches at an industrial level.
The New Arms Race: AI for Attackers and Defenders
New frontier models such as Claude Mythos and OpenAI's GPT-5.5 have demonstrated powerful capabilities in hunting software vulnerabilities and evaluating how they can be chained to harm organizations. But these same models have also escaped sandbox testing in reported incidents, compromising other organizations. The double-edged nature of AI in security is now undeniable.
Threat actors are adopting AI to match the craft of state-sponsored groups. A recent IBM report found a 44% increase in cyber-attacks exploiting public-facing applications since 2025, alongside a 40% rise in vulnerability exploitation and a 50% growth in active ransomware operators. Much of this acceleration stems from attackers integrating AI tools into their workflows.
Where Legacy Infrastructure Meets Modern Threats
Professor Richards emphasizes that dynamic and active defense strategies are increasingly necessary. One major challenge businesses face is implementing these strategies on aging and legacy infrastructure. Not all cybersecurity products on the market are effective, and poor investment decisions compound the problem.
What works for a multinational may not work for a small enterprise. The key is making sure the defense fits the organization's risk profile, not just the latest trend.
Legislation Lag: A Growing Vulnerability
One of the most pressing issues Richards highlights is the slow pace of compliance legislation relative to technology. As AI shrinks the window between vulnerability discovery and exploitation, traditional disclosure windows become problematic.
This creates a real tension. In intelligence, selective disclosure has long been accepted under national security protocols. For commercial organizations, however, such flexibility is rare. Two developments are needed. First, compliance legislation must be written in a way that protects businesses in fast-moving situations, perhaps allowing post facto disclosure. Second, court cases may establish precedents that balance speed with accountability.
Why This Matters
For business leaders, the stakes are existential. The C-suite's inability to grasp AI-driven threats leads to misallocated budgets, poor response strategies, and increased exposure. As Richards puts it, resilience is about keeping the response dynamic, diversified and creative. That requires executives who can make informed decisions in real time, not just after a breach. The regulatory framework will lag, but companies that invest in executive education and adaptive defense strategies will be far better positioned.



