Cybersecurity - 8 min read

The Defenders' Window: Why Aeon Expects AI-Enabled Cyber Incidents to Increase

OpenAI is calling for urgent collective cyber defense. Aeon expects AI-enabled incident pressure to rise and explains what organizations should test, fix, and verify now.

The Defenders' Window: Why Aeon Expects AI-Enabled Cyber Incidents to Increase

OpenAI has issued a call for collective action on cyber defense, warning that AI-enabled attacks are likely to become more widespread and sophisticated as model capabilities advance.

Aeon AI Risk Management agrees with the direction of that warning. We expect cybersecurity incidents involving AI-assisted discovery, targeting, social engineering, vulnerability exploitation, and operational automation to increase.

That is a directional risk assessment, not a claim that every incident will be caused by AI or that every organization faces the same level of exposure. The practical point is simpler: attackers need less time and specialist effort to test more ideas against more systems, while many organizations still carry years of unresolved vulnerabilities, excessive permissions, weak authentication, misconfiguration, and technical debt.

The defensive opportunity is real too. The same class of tools can help security teams examine attack paths, review code, validate suspected weaknesses, prioritize remediation, and verify whether fixes work. The organizations that benefit will be the ones that convert capability into disciplined defensive action now.

Why Aeon expects incident pressure to rise

Capability is becoming easier to apply

Cyber operations have always required a mix of reconnaissance, technical knowledge, persistence, and time. AI does not remove those requirements, but it can compress them.

A capable system can help an operator interpret unfamiliar code, generate test cases, adapt scripts, compare possible attack paths, summarize large amounts of technical material, and continue iterating. As access to capable models spreads, more operators can attempt work that previously required a larger team or deeper specialization.

The result does not need to be a novel exploit to create harm. A higher volume of competent attempts against known weaknesses can still produce more compromises.

Attackers can test more paths at lower cost

Most organizations do not fail because of one cinematic zero-day. They fail through combinations of ordinary weaknesses: an exposed service, a reused credential, an overprivileged identity, an authorization gap, an unpatched dependency, or a cloud configuration that was never revisited.

AI-assisted workflows can make it cheaper to search for those combinations. They can also help attackers adapt more quickly when one route fails. Even if the success rate of each attempt remains low, a large increase in the number and speed of attempts can raise incident pressure.

The attack surface is expanding

Organizations are adding APIs, cloud services, AI-generated code, AI agents, retrieval systems, MCP servers, and connected tools. Each new integration creates trust relationships involving identity, data, permissions, and actions.

The model itself is only one part of that boundary. An agent can be safe at the conversational layer and still be connected to an overprivileged tool. A retrieval application can answer correctly while exposing another tenant's data. An MCP server can perform its intended function while failing to enforce project or user scope.

These are conventional security problems expressed through new architectures.

Defensive backlogs remain large

OpenAI's letter highlights longstanding bugs, excessive permissions, insecure or unpatched software, weak authentication, misconfiguration, and legacy technical debt. That list will be familiar to most security leaders.

AI capability is advancing faster than many organizations can remove those accumulated weaknesses. This creates a temporary imbalance: attackers gain speed while defenders still face constrained budgets, incomplete asset inventories, remediation queues, and difficulty proving whether a fix actually closed the path.

That is why Aeon sees a defenders' window. The priority is not to predict the exact number of future incidents. It is to reduce the reachable attack paths before increased capability finds them.

What organizations should do now

Identify the systems where failure would matter

Start with business-critical web applications, APIs, administrative interfaces, identity systems, internet-facing services, and AI applications that can retrieve sensitive information or take external actions.

The question is not only, "Do we have a vulnerability?" It is, "Which reachable weakness could create a material business outcome?"

Test authorization, not just authentication

Logging in successfully does not prove that access controls work. Organizations should test whether users, tenants, agents, services, and tools can read or change objects outside their intended scope.

Authorization failures are especially important in APIs, AI agents, MCP systems, and multi-tenant applications because a valid identity may still receive excessive access.

Validate plausible attack paths

Automated scanners are useful for coverage, but a scanner result is not automatically an exploitable finding. High-priority issues should be reproduced safely, tied to the actual environment, and evaluated for realistic impact.

This is where capable AI can assist defenders, but human review remains essential. A model hypothesis is a lead. A reportable finding requires evidence.

Fix the path, then test it again

Closing a ticket is not the same as closing the vulnerability. Remediation should be checked against the original path and nearby variants. Where a direct patch is not immediately possible, compensating controls should be specific, measurable, and verified.

Reassess after material change

New integrations, identity changes, agent tools, model-generated code, major releases, and infrastructure migrations can create new paths. Security testing should be repeated after material architectural or permission changes rather than treated as a one-time compliance event.

How Aeon CyberGuard supports clients

Aeon supports the collective-defense direction through CyberGuard, our authorized, AI-assisted and human-reviewed security assessment service.

CyberGuard can assess:

  • public websites and web applications
  • application and service APIs
  • authentication, authorization, tenant, role, and object boundaries
  • AI agents and their tool permissions
  • MCP servers and connected workflows
  • RAG applications and sensitive data paths
  • code paths, cloud configurations, and integration boundaries within the agreed scope

We use advanced cyber capabilities to help form hypotheses, trace complex paths, review evidence, and challenge proposed fixes. We do not treat model output as a verified vulnerability by default.

Every engagement starts with written authorization and defined targets. Consequential actions remain controlled and human-reviewed. Findings are supported by reproducible evidence, calibrated to demonstrated impact, and translated into practical remediation priorities.

CyberGuard is not a certification, a guarantee that a system is secure, or permission to test outside the approved scope. It is a focused way to find credible weaknesses, understand their business consequence, and verify what should be fixed first.

Use the defenders' window

The expected increase in AI-enabled cyber activity does not make defense futile. It makes timing more important.

Organizations can reduce risk now by removing exposed attack paths, tightening authorization, limiting agent and service permissions, validating high-impact weaknesses, and verifying remediation before incident pressure grows further.

If you need an authorized assessment of a website, application, API, AI agent, MCP deployment, RAG system, or related trust boundary, contact Aeon AI Risk Management or email info@airiskmanagement.ca.

Learn more about Aeon CyberGuard.

Sources