top of page
Search

The AI Arms Race

Writer: Stephanne Payne
Stephanne Payne
Jul 24
2 min read

I was talking to a bud the other day and that convo made me realize that there are days when AI feels less like a technological revolution and more like an arms race.


As security leaders, we're watching both sides accelerate at the same time.


Attackers are discovering vulnerabilities faster. They're crafting phishing campaigns that are cleaner, more believable, and increasingly tailored to the individual. Social engineering isn't getting more sophisticated because humans suddenly became more creative. It's getting better because machines are.


Naturally, the response has been... MORE AI!!!


Every vendor in my inbox promises that their AI will discover, govern, control, manage, classify, prioritize, automate, predict, remediate, orchestrate, and probably make me breakfast if I sign the contract before quarter-end.


By lunchtime I've received a dozen emails explaining why every other AI platform is inadequate and why THEIRS is the ONE ONE capable of saving cybersecurity.


It has become AI defending us from AI (that was built to defeat the AI we installed last quarter).


SOMEWHERE ALONG THE WAY WE'VE STARTED CONFUSING ACCELERATION WITH PROGRESS.


The reality is that AI is an amplifier. It magnifies capability—for defenders and attackers alike. Same rate. It wasn't only the bad guys getting AI. It isn't only bad guys we worry about using AI in our environment. AI doesn't magically replace good architecture. AI doesn't eliminate governance. AI doesn't create security strategy. It doesn't teach people to think critically. And it certainly doesn't absolve leaders from making difficult risk decisions.


The organizations that win won't necessarily be the ones with the most AI.


They'll be the ones that know exactly where AI creates value, where human judgment is irreplaceable, and where saying "no" to another shiny ball... err, platform is actually the smartest security investment they can make.


Maybe the next competitive advantage isn't buying more AI but actually having the discipline to stop long enough to ask a simple question:


Are we solving a business problem... or are we just keeping up in an AI arms race that nobody seems capable of slowing down?

 
 
 

Recent Posts

See All
Deep Questions About AI, Governance, and Ethics

I had a conversation with AI this morning that left me with a governance question I don't think we're asking early enough. We spend enormous amounts of time discussing how we should govern what increa

 
 
 

Comments


  • Linkedin

Cybersecurity Leadership Manifesto

© 2026 by Stephanne 
Powered by secure practices and innovative thinking.

bottom of page