Blog

Fight AI with AI: The Foundations of Security Control Management

August 20, 2026
5 min read

AI is a doubled-edged sword. It accelerates missions that advance our safety and security. It also provides a new set of capabilities to those who seek to disrupt and undermine our safety and security.

AI is a game-changer. It helps us do things we couldn’t do before. It helps us move faster. It helps us go bigger, and it reduces the time to mission.

But at the end of the day, AI is a tool. It doesn’t decipher between good and bad. It only wants to get the job done.

AI is quickly becoming a potent weapon for cyberattacks, as the combination of speed, scale, and novel capabilties form a powerful advantage for adversaries. Cybersecurity is a race to stay ahead of adversaries, and AI will make it harder to keep up. 

New Vulnerabilities: Attackers probe systems to find a way in. AI provides powerful new tools to find openings faster. In a particularly harrowing sign, Claude Mythos’ preview version outperformed humans at finding vulnerabilities in commonly-used software platforms. Engineers without cyber expertise prompted their way to the discovery of zero-day vulnerabilities that were 10-20 years old.

Faster Exploitation: After being found, vulnerabilities can be exploited faster, as well. CrowdStrike’s 2026 Threat Hunting Report stated that, “From January through June 2026, 88% of CrowdStrike-observed exploitation of vulnerabilities with a public PoC was conducted within 48 hours of the PoC’s release.” Exploit windows are expected to continue to shrink.

Autonomous Attacks: Agents become nefarious when placed in the hands of attackers. Taiwan was recently targeted in the first fully-automated attack of a government, where eight agents conducted intrusions, adapted to setbacks, and made decisions without human intervention, according to CNN.

Overwhelmed Defenses

AI-powered attacks expose weaknesses in our defenses. Systems are rarely secure when they are deployed, leaving vulnerabilities from the start. Patches are issued, but too often they don’t get applied. Compliance frameworks allow years to pass between certifications, even as users make changes, the threat landscape evolves, and regulatory requirements shift.

AI didn’t create these issues, but it is much better at taking advantage of them. They are the result of a very human system, where people forget things, grapple with shifting priorities, and struggle to change. By contrast, AI moves with ruthless efficiency to accomplish its task. It finds a way in. It looks for the right answer, even when it encounters a roadblock. It adapts willingly. Human-powered defenses won’t be able to keep up.

To fight AI-enabled attacks, AI-enabled defenses are required. Just as AI is a powerful weapon, it can also be a powerful shield. In truth, AI can help us to finally confront the challenges that have long left us vulnerable. For too long, security and compliance have been treated as an afterthought. In some cases, security and engineering are on separate teams, and they don’t speak the same language. In other cases, engineers have to learn compliance to get a system deployed, when they would rather be focused on solving engineering problems. This friction slows everything down, and leaves gaps.

AI-Enabled Security Control Management

With AI, we finally have the opportunity to embed security and compliance throughout the development pipeline. AI-enabled Security Control Management lays the foundation. To stay ahead of attackers, tools must move at machine speed. Before they can do so, they need a few building blocks, including:

Chat-Based Queries: Nothing in AI happens without a prompt. Systems must have native chatbots, or easily integrate with common chat-based tools, such as OpenAI, Claude, and Gemini.

Customizable Policies: The standards laid out by a DISA STIG may be different from what your system needs. AI-native tools map requirements to particular needs, providing the alignment needed to establish a secure baseline from day one.

Machine-Readable Policy: When one team works in spreadsheets and another works in code, they talk past each other. Compliance policies must be written in common languages that are understood by both humans and machines. That means systems must translate human-written policy into code or OSCAL. This is the foundation to autonomous scanning, remediation, monitoring, and evidence generation.

Don’t Just Find it, Fix It: Tools have focused on showing what’s wrong, or providing a snapshot of system health. Autonomous systems have the ability to devise a solution and act to fix it. Engineers spend countless hours and brain power on remediation. Let’s automate it.

Continuous Enforcement: We can’t wait for point-in-time audits, years apart. In a world where exploitation windows are counted in hours, scanning and remediation must be constant. Hardening is a constant.

Where Security is Mission-Critical

It’s bad enough that security and compliance processes have left us vulnerable. What’s worse, they’ve also distracted from the mission. Engineers spend hours parsing compliance frameworks. Teams can’t deploy while they’re waiting for an ATO. In government and highly-regulated industries, security and compliance are part of the mission. They should be an enabler of success, not a drain on resources.

AI-enabled security control management provides a new paradigm. Compliance is autonomously executed by purpose-built tools, and humans can stay focused on the mission. 

Let’s make AI the force multiplier we’ve always wanted, and stay ahead of attackers.

Share this post