Skip to content
Lomond Logic

Technology That Makes Sense.

Journal London

When Cyber Attacks Move at Machine Speed

Douglas McFarlaneSeptember 2, 2026

Cybersecurity has spent decades as a contest between attackers looking for weaknesses and defenders trying to close them.

Artificial intelligence is now changing the speed and scale of that contest so dramatically that cyber risk may need to be viewed less as an IT problem and more as a threat to the infrastructure on which modern society depends.

More than 100 technology, financial services and cybersecurity organisations, including Google, Microsoft, Anthropic and OpenAI, have warned that the world has a limited window in which to strengthen its cyber defences. Their concern is unusually immediate. AI-enabled cyber attacks could become substantially more widespread and sophisticated within months, while existing security arrangements may no longer be sufficient.

Artificial intelligence changes the economics of cybercrime. Work that once required skilled hackers, significant resources and considerable time can increasingly be automated. AI systems can search for vulnerabilities, analyse networks, generate software, construct convincing communications and adapt their behaviour when they encounter resistance.

The result could be the industrialisation of cyber attack. Instead of choosing a limited number of valuable targets, attackers may increasingly be able to investigate thousands of organisations simultaneously. Highly personalised phishing can be generated automatically, vulnerabilities can be identified faster and autonomous systems may be able to coordinate elements of an attack with progressively less human intervention.

There are already indications of where this could lead. During security testing, groups of OpenAI agents were reported to have coordinated with one another and successfully attacked the Hugging Face platform. Anthropic has also developed an AI security system capable of discovering vulnerabilities extremely quickly, including a weakness in legacy software that had apparently gone undetected for 27 years.

These developments expose a fundamental imbalance. AI capabilities can improve within months, while hospitals, water utilities, transport networks, governments and other critical infrastructure may depend upon systems that take years to replace. Many organisations must contend with ageing technology, limited budgets, complex procurement and environments where taking a system offline for an upgrade can itself create significant operational risk.

Attackers are beginning to operate at software speed while much of society still defends itself at institutional speed.

That gap could become one of the most important systemic vulnerabilities of the AI era. A regional hospital or water company may never attract the technology budget of a global bank or hyperscale cloud provider, yet disruption to those services can have consequences far beyond the organisation concerned. The companies behind the warning are consequently calling for advanced defensive AI, funding, testing and technical assistance to be extended to under-resourced critical infrastructure.

Cyber risk also becomes more dangerous as digital systems become increasingly interconnected. A successful attack against a major cloud provider, telecommunications network, software supplier or payments platform can affect thousands of organisations at once. The initial breach may be relatively contained, while the disruption travels through dependencies that neither the attacker nor the organisations affected completely understand.

This is what moves cybersecurity firmly into the territory of systemic risk. Pandemics, financial crises, energy shocks and natural disasters become particularly destructive when disruption cascades through connected systems. Modern digital infrastructure has the same characteristic, with the additional complication that an adversary can deliberately search for the connections most likely to amplify the damage.

Artificial intelligence will also strengthen defence. AI can examine networks continuously, discover vulnerabilities, identify unusual behaviour and respond faster than human security teams. The cyber environment may therefore evolve into a contest between offensive and defensive systems increasingly operating at machine speed.

The transition is likely to be uneven. Large technology companies, governments and financial institutions may be able to deploy sophisticated defensive tools rapidly, while smaller utilities, healthcare providers and public bodies struggle to keep pace. This creates the uncomfortable possibility that some of society’s most essential systems could also become some of its most attractive targets.

There is a geopolitical dimension too. Cyber operations already allow states to disrupt adversaries without crossing many of the traditional thresholds associated with military action. More capable AI could expand those options, allowing future geopolitical confrontation to place simultaneous pressure on communications, energy, logistics, financial networks and government infrastructure.

Cybersecurity and geopolitical risk may therefore become progressively harder to separate. The origin of an attack might be criminal, commercial, political or military, while the resulting disruption to society could be remarkably similar.

The technology industry has commercial interests in greater investment in AI cybersecurity, so its warnings deserve scrutiny rather than automatic acceptance. Even so, a coordinated call involving more than 100 organisations, including many of the companies developing the world’s most capable AI systems, is a significant signal.

The most important implication is the shrinking timescale. Governments and infrastructure operators traditionally plan technology investment over years, but an adversarial technology capable of advancing significantly within months forces a very different approach to resilience.

Preventing every cyber breach is unlikely to be realistic. The more important objective is ensuring that essential systems continue functioning when breaches occur, with fewer single points of failure, stronger network separation, faster recovery and a much clearer understanding of the dependencies capable of turning an isolated incident into a wider crisis.

For Lomond Logic, cyber risk should therefore sit alongside geopolitical instability, financial stress, energy security, pandemics and natural hazards as a core component of global systemic risk. Useful indicators could include attacks against critical infrastructure, major software vulnerabilities, ransomware activity, state-sponsored campaigns, cloud concentration, telecommunications disruption and the growing capabilities of offensive and defensive AI.

The critical question is no longer simply how many cyber attacks are occurring, but whether the resilience of the systems connecting modern society is improving quickly enough to keep pace with the machines learning how to attack them.

The cyber arms race is accelerating, and much of the infrastructure it threatens was built for a slower world.