Cybersecurity Has Entered the Age of Machine-Speed Adversaries.
The Taiwan campaign suggests that AI is beginning to change more than the sophistication of cyberattacks. It could change their operating model.
Cybersecurity has traditionally contained an important constraint: attackers are human.
Humans investigate targets, select vulnerabilities, change tactics and decide what to try next.
AI agents are beginning to weaken that constraint.
Security researchers investigating a recent campaign against Taiwanese government systems reported multiple AI agents operating in parallel, mapping targets, identifying vulnerabilities and adapting attack strategies as conditions changed.
Taiwan confirmed experiencing an unusual AI-assisted cyber campaign, although the degree of autonomy remains contested.
That distinction matters.
But the strategic signal matters more.
Cyber risk may be moving from AI-assisted attackers towards AI-operated attack cycles.
That changes the economics of defence.
An autonomous attacker doesn’t need to become dramatically more intelligent to become more dangerous.
It can gain advantage through speed, persistence, parallelism and adaptation.
One human operator could potentially supervise agents probing hundreds of targets simultaneously, learning from failed attempts and redirecting effort without waiting for another analyst.
For boards, that creates an uncomfortable asymmetry.
Many organisations still defend through systems containing human-speed dependencies: investigations, approvals, escalations and incident-response decisions.
The attacker increasingly may not.
This suggests cybersecurity resilience needs another metric beyond prevention:
response-time asymmetry.
How long does the adversary require to detect an opportunity, adapt and act?
How long does your organisation require to detect that action, decide and contain it?
If the first number keeps shrinking while the second remains organisationally fixed, cybersecurity exposure changes even if your controls haven’t.
The AI cyber race may therefore not be decided simply by who has the strongest models.
It may be decided by whose decision loop moves faster.


