In brief: AI agents enable cybersecurity teams to scale threat detection, but grant attackers the same automation capabilities—while securing AI-powered systems is hampered by their unpredictability and connectivity requirements.
Check Point deploys AI agents to scale threat intelligence and test products more efficiently—yet generative AI and autonomous systems make it easier for attackers to automate campaigns at scale and identify new targets in AI-driven enterprise infrastructures.
Jonathan Zanger, CTO of Check Point Software, describes the current state of cybersecurity as a profound upheaval—comparable to the advent of the internet. The company uses AI agents to scale its threat detection: red teams that once manually tested products for security gaps now work 20 times more efficiently. Approximately 300 AI instances continuously monitor and test systems—a combination of human expertise and automated analysis that enables faster development of new signatures against attackers and identification and blocking of suspicious networks.
Yet the same technology empowers cybercriminals. Generative AI lowers the barrier to entry for attackers: smaller, faster threat groups can conduct phishing campaigns with lower technical expertise, create malware automatically, and accelerate exploits. The result is a multiplication of attack groups and higher attack velocity. This creates a dual challenge for CISOs: they must not only protect existing infrastructure but also secure AI systems being increasingly deployed in enterprises.
A critical problem lies in the nature of AI agents themselves: unlike deterministic systems that deliver predictable outputs for identical inputs, AI agents do not always behave predictably. They understand natural language, handle ambiguity, and thus require fundamental changes to security architecture. Additionally, a structural conflict emerges: security teams want to minimise AI system connections to limit attack surface. AI advocates, by contrast, demand maximum connectivity for data collection—the more connections, the higher the risk and attack surface.
Zanger warns: while generative AI accelerates and democratises software development, cybercriminals leverage the same capabilities to scale phishing, ransomware, malware, and vulnerability exploits. Organisations must prepare for an environment in which threats emerge faster and in greater volume. Classical defence strategies—access restriction and manual analysis—are no longer sufficient.
Source: www.csoonline.com · Published 10 July 2026
Lumi AI News — AI-assisted curation pursuant to Article 50 EU AI Act. Paraphrasing and classification by Lumi News Pipeline v1.7.3.