Palo Alto Networks just gave a rare look inside what happens when a cybersecurity company gets early access to the most advanced AI models before anyone else does. Its researchers spent months testing tools built by Anthropic and OpenAI, tools so powerful that neither company has released them to the public. What they found should worry anyone who runs a business connected to the internet, which by now is nearly everyone.
The core finding is simple to state and hard to sit with. These AI tools can find security flaws in software that would normally take a team of human experts about a year to uncover, and they can do it in a fraction of that time. That is good news when the flaws get fixed before criminals find them. It becomes a serious problem the moment the same capability lands in the hands of someone who wants to break in rather than patch things up.
That is not a hypothetical anymore. Palo Alto Networks is currently investigating a case where a hacker used AI to break into a company, exploit fifty separate weak spots, move around inside the network, gain higher level access, and steal information, all within ten hours. The company says that job would normally take a human hacking team about two weeks. The speed is the whole story here: most companies built their alarm systems and response plans assuming they had days to notice a break in, not hours.
This is not the first sign of trouble. Late last year, Anthropic disclosed that a Chinese state linked hacking group had turned its own AI chatbot against roughly thirty organizations, including banks, technology companies and government agencies, tricking it into carrying out most of the attack on its own. Anthropic said the AI handled the large majority of the work, moving at a pace no human team could match.
The pattern connecting both stories is that the gap between what AI can do for defenders and what it can do for attackers is closing fast, and right now it is closing in the attackers' favor first. Breaking into one system is simpler than defending every system at once. That is why more than one hundred companies, including Palo Alto Networks, Microsoft, Amazon and the AI makers themselves, signed a public letter this year warning that businesses have a short window to strengthen their defenses before this becomes routine.
For a business outside the tech industry, the lesson is not abstract. Old habits like patching software slowly, reusing passwords, or assuming an attack takes weeks to unfold no longer hold up. Security vendors are racing to bundle these same AI tools into products for customers, so better defenses are becoming available. But they cost money and attention, and the companies that treat this as next year's problem are the most likely targets once these tools spread wider, something researchers now expect within months rather than years.