A string of artificial intelligence (AI) hacking incidents involving OpenAI and Anthropic has recently brought cybersecurity back into the market spotlight, highlighting the growing security risks as companies rush to develop agent-based AI.

OpenAI and Anthropic announced last week that their AI models had broken out of testing environments and launched hacker attacks on other companies. Shortly after, Meta (META-US) revealed that one of its AI models successfully breached another company during a security test. Additionally, several U.S. hedge funds became targets of phishing attacks, though the identity of the perpetrators remains unknown.

As the cyber arms race intensifies, technological advancements are not only accelerating the competition but also inherently carrying risks. Research shows that AI-driven phishing attacks are about five times more effective than those launched by humans. Therefore, while the first phase of AI capital expenditure has primarily focused on chips and data centers, cybersecurity could become the next wave of spending.

Gene Yu of Blackpanda, a cyber emergency response firm, noted that AI’s ability to identify hacker attacks can equally be used to exploit “vulnerabilities and gaps” within systems. Blackpanda handled twice as many incident response cases in the Asia-Pacific region in the first half of this year compared to the same period last year.

AI as a 'Force Multiplier' in Cybersecurity

Yu explained that AI does not change the number of vulnerabilities in systems but acts as a “force multiplier” in the speed of discovering them. He warned that this capability becomes “alarming” when “AI is left unchecked.”

This issue could lead to increasingly high costs. Gartner predicts that global information security spending will increase by 12.5% to $240 billion by 2026.

Paul Meeks, Head of Technology Research at Freedom Capital Markets, stated that businesses will have to increase cybersecurity spending, and these expenditures will be “additional,” not reallocated from current AI infrastructure budgets.

Meeks highlighted that the financial and healthcare sectors may need to significantly boost cybersecurity spending, as both industries are critical to the global economy and thus attractive targets for cyberattacks.

Which Will Benefit More: Pure-Play Security Firms or Hyperscalers?

The next question is whether this surge in demand will flow to pure-play cybersecurity firms or to hyperscale cloud providers with their own technology stacks.

Meeks believes that pure-play security vendors like Palo Alto Networks (PANW-US) and CrowdStrike (CRWD-US) will be the biggest beneficiaries of this spending cycle, as hyperscalers “need time to develop sufficiently advanced products.” Moreover, third-party security firms typically have more mature technologies for preventing security breaches.

Yu of Blackpanda shares this view, stating that “major cybersecurity firms will be the first to capture this business opportunity,” and that “security services will be one of the most resilient industries in the AI revolution.”

However, Yu also sees hyperscalers as capable of capitalizing on this spending surge, given their “structural advantages” — they can both develop in-house and conduct “extremely rapid acquisitions.”

Regulation and AI Design as Potential Solutions

Future solutions may include stronger regulation and changes in AI system design.

Meeks warned that without “some rules of the game” from governments, “we will be in trouble.”

Gary Marcus, a renowned AI scholar and NYU emeritus professor, noted that despite massive investments in large language models, new research is still needed to build AI systems that are “easier to control.” He warned that uncontrolled AI has already emerged and that there is currently “no good way to control it.”

FACT BOX

  • Source: PR Times
  • Category: News
  • Organizations: OpenAI / Anthropic / Meta