Organizations need to prioritize building AI agents now to defend against increasingly capable adversaries utilizing local models.

Imagine a summer in Riyadh filled with international flights and an abundance of discussions among CISOs, all centered on the pressing topic of AI strategy. Regardless of where you are in the world or which industry you belong to, the dialogue starts and ends with one crucial question: how prepared are we for the incoming wave of AI-driven threats? It's time to address that head-on.
Right now, executives should be pondering two essential questions:
- Are we proactively developing and refining AI agents to combat future adversarial incidents?
- Do we possess the intelligence necessary to react at the speed of machines?
The Need for AI Agents Today
Why is now the moment for investment in AI agents for defensive operations? Two main reasons stand out.
First, consider malicious actors motivated by financial gain who operate outside the purview of state resources. While state-sponsored threats come with unique capabilities, financially motivated adversaries are building their arsenals independently. Reports indicate that advanced AI models could potentially facilitate automated malware generation and orchestrated intrusion strategies, with government intelligence agencies like the Five Eyes explicitly warning about these emergent risks. However, we haven’t yet witnessed a significant uptick in the deployment of such offensive agents. It’s akin to waiting for the proverbial Uruk-hai assault in The Lord of the Rings; while we expect it, the automated forces haven’t surged—yet.
The current limitations related to frontier AI models provide a buffer. Despite their potential, these models remain difficult to use at scale for autonomous attacks. Malicious entities walk a tightrope between leveraging third-party APIs—which heightens their risk of detection—and developing their own local open-source models. The reality is that while open-source models are often discussed, they demand considerable resources and technical know-how for effective offensive use. For instance, a recent test with tools like LibreChat and Dolphin-llama3:14b on a mid-range server highlighted that even with decent hardware, executing straightforward tasks like coding a web shell remains a hard challenge.
Yet, this barrier will only diminish as time progresses. Quantization serves as a pivotal factor to observe. In simple terms, quantization reduces the computational load by simplifying the precision of model weights, making sophisticated AI more accessible through lower hardware requirements. While this might lead to a slight dip in model efficiency, even these less capable versions are still functional for malicious tasks. As hardware costs decline, the window of opportunity for these actors to execute large-scale attacks widens significantly.
The real peril for cybersecurity professionals lies not in the flashy frontier models but in the straightforward deployment of effective local models that can run on relatively modest hardware. As advancements in open-source capabilities continue, particularly in the next year, we may see a surge in opportunistic attacks as these actors leverage locally trained models.
This scenario underscores the importance of constructing a defensible AI strategy now. As with adopting autonomous vehicles, organizations shouldn’t leap in without rigorously testing edge cases. The same principle applies to agent workflows; iterating and refining these systems through experimental trials is non-negotiable.
CISOs who are ahead of the curve are already investing in building an AI control plane that fosters transparency in AI usage, monitors project ROI, and ensures code security. This effort isn’t just about developing agents; it’s part of a wider framework essential for modern cyber defense.
Faced with the dual pressures of data regulations and security demands, CISOs must instill trust and confidence in their AI agents. Although humans will likely play a central role in decision-making for the foreseeable future, monitoring agents in semi-controlled environments is crucial. Every function—from patch application to revoking access—requires iterative learning. While vendor insights are valuable, teams must take ownership of their agent workflows to mitigate risks effectively.
Organizations that delay building and testing these agents will soon find themselves significantly outmaneuvered by financially motivated adversaries enhancing their capabilities through open-source tools.
Strategic Priorities for Implementing Agents
Now that we’ve established the urgency, it’s time to consider where to focus the deployment of these AI agents. The effectiveness of agents hinges on the quality and breadth of data they can access, which in turn facilitates rapid responses grounded in machine intelligence.
Here are three high-impact areas for deploying agents:
- Continuous Threat Exposure Management (CTEM): All five stages of CTEM are compatible with AI implementation. The need for AI-assisted vulnerability discovery is escalating, although consistent availability of reliable patches remains an issue. The key focus should be on Known Exploited Vulnerabilities (KEVs).
- Breach & Attack Simulation (BAS): This approach mirrors continuous Red Team initiatives. Existing controls frequently fail to detect or block threats effectively, necessitating preemptive validation through AI-enhanced BAS.
- Security Operations: The current wave of AI innovation in this sector emphasizes speed and efficiency. Deep intelligence from a range of sources gives agents a decision-making edge, essential in differentiating between low-risk and high-risk actions.
Choosing Early Adoption Versus Caution

While production-grade AI agents may still be evolving, investing in R&D now can significantly bolster organizational resilience as these models mature. The urgency for effective defenses is just beginning; organizations that prepare now will certainly fare better against opportunistic threats deploying localized AI solutions.
By coupling external vendor expertise with internal AI and security knowledge, organizations can expedite their learning curve. While humans remain critical for nuanced judgment, agents are poised to take over the routine tasks. The message is clear: don’t wait—start developing your AI agents today.
Discussion
Sign in to join the discussion.