- AI – From Productivity Aid To Offensive Force Multiplier
- The Artificial Adversary Taxonomy
- Mythos Is The Warning Shot
- The Attack Surface Now Includes Human Emotion
- AI Also Becomes The Target
- How Defenders Must Change Their Operating Model
- The Board-Level Message
- The Adversary Is No Longer Only Human
- References
Cybersecurity has spent decades focused on the human adversary. We built models for nation-state actors, cybercriminal gangs, insiders, access brokers, ransomware affiliates, and fraud operators. We mapped their Tactics, Techniques, and Procedures (TTPs). We named and categorized their malware. We studied their mistakes.
That era is not over. But it is no longer sufficient.
A new adversary archetype is emerging: The Artificial Adversary.
The artificial adversary is not merely a hacker using Artificial Intelligence (AI). That concept undersells the shift. The artificial adversary is either a human adversary (individual or group) augmented by AI, or an autonomous AI system acting with malicious intent. In the first form, humans provide intent, targeting, strategy, and outcomes while machines execute much of the tactical workload. In the second form, the system itself begins to plan, test, adapt, and execute in ways that look increasingly adversarial.
This changes the economics of cyber conflict. AI compresses time, lowers skill barriers, scales persuasion, multiplies effectiveness of phases such as reconnaissance, accelerates vulnerability discovery, and enables synthetic identity creation, voice and video impersonation, adaptive malware, and agentic attack orchestration. Traditional attacks often fail and stop as they move on to easier targets. Artificial adversaries fail, learn, and adapt against the original target.
AI – From Productivity Aid To Offensive Force Multiplier
The first wave of adversarial AI use was mostly productivity enhancement via better phishing language, faster translation, commodity scripting, target research, fake profiles, and malware assistance. That mattered, but it did not fundamentally change the attack model.
The next wave is different. Google Threat Intelligence Group (GTIG) reported that the underground marketplace for illicit AI tools matured in 2025, with offerings designed to support phishing, malware development, and vulnerability research. GTIG also observed actors misusing AI across the attack lifecycle, from reconnaissance and phishing lures to command-and-control development and data exfiltration (Google Threat Intelligence Group, 2025).
More importantly, GTIG identified malware families that use AI capabilities during execution. As an example, PROMPTFLUX points toward self-modifying malware that can request rewritten code for evasion. PROMPTSTEAL, attributed to APT28-related activity, queried a language model to generate commands for stealing system information and documents (Google Threat Intelligence Group, 2025). That begins to blur the line between a static tool and an adaptive operator.
The Artificial Adversary Taxonomy
To defend against the artificial adversary, leaders need precise language. Not every AI-enabled threat is the same. A practical taxonomy has five levels.
- AI-assisted human operator – a human attacker uses AI for discrete tasks such as phishing, translation, research, script generation, or stolen-data summarization.
- AI-augmented threat crew – a criminal or nation-state team embeds AI into reconnaissance, exploit research, identity profiling, malware development, infrastructure staging, data exfiltration, and victim communications.
- AI-orchestrated campaign – agentic systems coordinate personas, assign tasks, monitor responses, tune timing, and manage parallel workflows while humans supervise outcomes.
- Semi-autonomous adversarial agent – the system conducts meaningful parts of the intrusion chain itself, including asset discovery, service testing, response analysis, and attack path modification.
- Autonomous malicious AI system – an AI system pursues malicious objectives with limited or delayed human direction, raising harder questions around attribution, containment, predictability, and control.
This taxonomy matters because an AI-assisted phishing actor requires different defenses than an autonomous agent probing applications, manipulating identities, and adapting to telemetry in real time.
Mythos Is The Warning Shot
The Claude Mythos Preview is important because it gives the industry a concrete glimpse of where this is heading. Anthropic described Mythos Preview as strikingly capable at computer security tasks and stated that, when directed by a user, it could identify and exploit zero-day vulnerabilities in major operating systems and web browsers (Anthropic, 2026a). Anthropic also framed Project Glasswing as a controlled effort to help critical software maintainers and infrastructure providers find and fix vulnerabilities before similar capabilities become broadly available (Anthropic, 2026b).
The United Kingdom AI Security Institute (AISI) later evaluated Mythos Preview and found that it solved a 32-step simulated corporate network attack in 3 of 10 attempts, completing an average of 22 of 32 steps across attempts. AISI also cautioned that its ranges lacked active defenders and defensive tooling, so these results should not be overread as proof against hardened environments (AI Security Institute, 2026).
That nuance is essential. The industry should not panic. It should also not hide behind skepticism. The correct conclusion is sharper, AI-enabled vulnerability discovery and exploit development are becoming more accurate, and the bottleneck may shift from finding flaws to verifying, disclosing, patching, testing, and deploying fixes. Anthropic has already said that verifying, disclosing, and patching large numbers of vulnerabilities is becoming the bottleneck for Mythos-class models (Anthropic, 2026b).
The Attack Surface Now Includes Human Emotion
Artificial adversaries do not only attack code and/or technology stacks. They attack context.
The most dangerous AI-enabled social engineering will not look like a clumsy phishing email. It will look like a relationship. It will understand timing, pressure, hierarchy, fatigue, urgency, fear, ambition, belonging, and trust.
This is where “vibe hacking” enters the threat model. Vibe hacking is social engineering powered by an AI stack. Instead of sending one fraudulent email, the adversary shapes the emotional context around a target over time. It mirrors tone, language, professional interests, anxieties, identity markers, and trust anchors. It does not simply ask the victim to do something risky. It makes the risky action feel normal.
Deepfakes extend this problem into business workflow. They are not just fake videos; they are trust-substitution tools. A synthetic executive in a video call, a cloned voice in a payment workflow, or a fake vendor persona in a collaboration channel can inject synthetic authority into real business processes. The 2024 Hong Kong deepfake fraud involving Arup showed that this is not theoretical; fraudsters reportedly used a digitally cloned senior manager in a video conference to help induce $25 million in transfers (Financial Times, 2024).
The defensive lesson is clear. Do not ask only, “Does this look or sound authentic?” Ask, “Is this request valid under policy, through an approved channel, with independent verification?” In the artificial adversary era, process integrity matters more than appearance.
AI Also Becomes The Target
The artificial adversary does not only use AI. It attacks AI.
As organizations deploy copilots, retrieval-augmented generation systems, autonomous agents, AI-enabled security tools, and workflow automation, they create new attack paths. Prompt injection, tool misuse, excessive access, data poisoning, insecure output handling, model supply chain compromise, memory poisoning, sensitive information disclosure, and model theft become security issues.
Frameworks help translate this risk into controls. OWASP lists critical LLM application risks including prompt injection, insecure output handling, training data poisoning, supply chain vulnerabilities, sensitive information disclosure, excessive agency, overreliance, and model theft (OWASP, 2025). NIST positions the AI Risk Management Framework as a voluntary framework to incorporate trustworthiness considerations into the design, development, use, and evaluation of AI systems (NIST, 2023). MITRE ATLAS gives defenders a structured knowledge base for adversary tactics and techniques against AI-enabled systems (MITRE, 2026).
These frameworks should not sit in policy documents. They should be operationalized through model and agent inventories, decision rights, logging, monitoring, human review thresholds, rollback paths, and incident playbooks for AI-related failures.
How Defenders Must Change Their Operating Model
The artificial adversary cannot be handled by a purely human-speed security model. Defenders need an operating model that is adaptive, identity-aware, telemetry-rich, and capable of learning faster than the adversary. This model should encompass:
- Sense continuously – correlate identity, endpoint, network, cloud, SaaS, code, data, and AI telemetry. Artificial adversaries exploit gaps between domains
- Verify trust dynamically – breached credentials, exposed PII, stolen cookies, synthetic profiles, and social context give artificial adversaries the raw material to impersonate trusted people and systems. Verification must account for behavior, device posture, session integrity, privilege context, and workflow legitimacy.
- Constrain autonomous authority – every AI agent with access to business data, production workflows, security tooling, or identity infrastructure needs an owner, a defined scope of authority, monitored access, escalation thresholds, and rollback options.
- Deceive the adversary – dynamic deception environments, honeytokens, synthetic identities, fake credentials, decoy documents, and instrumented workflows can force artificial adversaries to reveal themselves and/or waste resources. Against a learning adversary, deception is not a gimmick; it corrupts the adversary feedback loop.
- Respond at machine-relevant speed – human approval still matters for high-impact decisions, but every response cannot wait for manual analysis. Governed automation, adaptive access controls, session revocation, risk-based step-up authentication, and rapid isolation paths are now table stakes.
- Learn faster than the adversary – every incident, simulation, false positive, missed detection, and control bypass should feed back into detection logic, identity policy, awareness training, incident response, and AI governance.
The Board-Level Message
The artificial adversary is not a technical curiosity. It is a governance issue.
Boards and executives should understand three things:
- AI compresses the attack timeline.
- AI expands adversary capacity.
- AI attacks trust, it exploits identity, workflow, urgency, authority, emotion, and process exceptions.
Cyber risk reporting must therefore evolve. Metrics should include identity exposure, patch latency, agent privilege coverage, AI system inventory coverage, deepfake verification readiness, exception rates, logging completeness, time-to-containment, and response performance.
The Adversary Is No Longer Only Human
The artificial adversary is here. It may still have humans behind it. It may still depend on imperfect models. It may still fail. But failure is not reassurance. Failure is training data.
The defining cyber conflict of the next decade will not be fought between people and machines. It will be fought between teams that know how to combine human judgment with machine speed and teams that do not.
We need to stop treating AI as a tool category. We need to treat it as a change in adversary economics. It changes speed, scale, cost, persistence, personalization, and adaptation. It turns reconnaissance into a continuous process. It turns social engineering into emotional targeting. It turns vulnerability discovery into an industrialized pipeline. It turns weak governance into part of an exposed attack surface.
Artificial adversaries do not have egos. They do not suffer burnout. They do not get distracted by corporate drama. Your defenses do.
The organizations that survive this shift will not be the ones that panic. They will be the ones that adapt faster, govern smarter, harden the basics, deploy AI responsibly, and rehearse against machine-speed pressure before the real adversary arrives.
References
AI Security Institute (2026) Our evaluation of Claude Mytho s Preview’s cyber capabilities. Available at: https://www.aisi.gov.uk/blog/our-evaluation-of-claude-mythos-previews-cyber-capabilities (Accessed: 5 June 2026).
Anthropic (2026a) Assessing Claude Mythos Preview’s cybersecurity capabilities. Available at: https://red.anthropic.com/2026/mythos-preview/ (Accessed: 5 June 2026).
Anthropic (2026b) Expanding Project Glasswing. Available at: https://www.anthropic.com/news/expanding-project-glasswing (Accessed: 5 June 2026).
Financial Times (2024) ‘Arup lost $25mn in Hong Kong deepfake video conference scam’, Financial Times. Available at: https://www.ft.com/content/b977e8d4-664c-4ae4-8a8e-eb93bdf785ea (Accessed: 5 June 2026).
Google Threat Intelligence Group (2025) GTIG AI Threat Tracker: Advances in threat actor usage of AI tools. Available at: https://cloud.google.com/blog/topics/threat-intelligence/threat-actor-usage-of-ai-tools (Accessed: 5 June 2026).
MITRE (2026) MITRE ATLAS. Available at: https://atlas.mitre.org/ (Accessed: 5 June 2026).
NIST (2023) Artificial Intelligence Risk Management Framework. Available at: https://www.nist.gov/itl/ai-risk-management-framework (Accessed: 5 June 2026).
OWASP (2025) OWASP Top 10 for Large Language Model Applications. Available at: https://owasp.org/www-project-top-10-for-large-language-model-applications/ (Accessed: 5 June 2026).
About the Author
Andres Andreu serves as both the Chief Executive Officer (CEO) and Chief Information Security Officer (CISO) at Constella Intelligence. He is a 4X CISO and distinguished cybersecurity leader with credentials including CISSP, ISSAP, and Boardroom Certified Qualified Technology Expert (QTE). His diverse career spans federal law enforcement, where he earned three U.S. Department of Justice awards for contributions to lawful intercept technology, corporate leadership at Hearst, Ogilvy & Mather and 2U, Inc./edX, and entrepreneurial success as a founding executive at Bayshore Networks (acquired by Opswat in 2021). An acclaimed author of The CISO Playbook, Professional Pen Testing Web Applications, and the upcoming The CISO Playbook: The Adversarial Mindset, he also holds patents in cybersecurity innovations and advises at Forgepoint Capital’s Cybersecurity Advisory Council.
Andres can be reached online at Linkedin and at our company website https://constella.ai/

