The lock didn't fail/ The attacker found another way in.

AI Is Changing the Economics of Cyberattack

September 17, 2026•3 min read

One finding from Anthropic’s recent research into AI and encryption stopped me.

Claude discovered a new way to attack HAWK, an experimental security system being evaluated for a future in which quantum computers may threaten some of the encryption methods we rely on today. Human security experts had already studied HAWK for two years; Claude identified a significant weakness in about 60 hours. It also discovered a much more effective attack against a deliberately weakened research version of AES, one of the most widely used methods for protecting digital information.

To be clear, this does not mean AI has broken the encryption protecting businesses today. Anthropic says neither finding affects current production systems. What caught my attention was something else: AI found weaknesses that human experts had not found first.

The Lock May Still Work

Picture a bank vault. The door is closed. The lock works exactly as designed. But the burglar doesn’t attack the lock — he finds the ventilation shaft and gets in that way.

That is the business reality I believe executives need to consider. Some security weaknesses have stayed hidden partly because finding them required rare expertise, significant time, persistence, and money. The effort was high enough that many attackers simply looked elsewhere. AI is beginning to change that equation: a vulnerability that once required a specialist to uncover may become easier to find, and a target once too costly to pursue may suddenly become worthwhile because the cost of finding the weakness has dropped.

What I’d Look At Now

I wouldn’t respond to every new research finding by replacing systems or launching a massive cybersecurity initiative. I’d start with one business-critical system, process, or data set — something where a breach would create real financial loss, operational disruption, regulatory exposure, or reputational damage.

Consider a legacy system still running critical operations in the background. It may have never been formally documented, precisely because everyone assumed its obscurity was protection enough — nobody outside a small internal team fully understands how it works, so why would an attacker bother? That assumption is exactly what AI-assisted discovery threatens to undo.

With that kind of system in mind, I’d look beyond its strongest defenses and ask:

  • Are we relying on something being difficult to find rather than genuinely difficult to exploit?

  • If an attacker couldn’t defeat our strongest control directly, where might they go around it?

  • Which overlooked weakness would cause the most damage if AI made it easier to discover?

The goal is not to prove that a problem exists. It is to determine whether there’s an exposure worth investigating.

There’s an important upside as well. The same AI capability that could help attackers find vulnerabilities can also help security teams find and correct them first. The advantage goes to whoever looks first.

Another Assumption Is Starting to Move

I’ve been warning leaders about quantum-resilient cybersecurity because quantum computing may eventually threaten some of the encryption organizations depend on today. This research introduces a different pressure. Quantum may eventually challenge the lock itself. AI may become increasingly effective at finding the ventilation shaft beside it.

Neither risk is hypothetical anymore, and neither is fully solved by the security investments most organizations have already made. Together, they raise a broader executive question: are the assumptions underneath your cybersecurity changing faster than you are reviewing them?

The vault door may still be doing its job. I want leaders to know where their ventilation shaft is before someone else finds it.

If this raises questions about your own systems, data, or security assumptions, let’s have a complimentary 15-minute conversation about your situation — what concerns you most, where it may make sense to look first, and whether the risk deserves further investigation.

Kathy Kent Toney

Kathy Kent Toney

Kathy Kent Toney is a technology advisor and consultant focused on emerging technology, AI, automation, cybersecurity, and operational strategy for modern organizations.

Back to Blog