The rise of AI in the enterprise has created new surfaces for security teams to secure, as well as opportunities to improve existing security workflows. However, there’s a third change coming, and it will be the biggest one. What does the asymmetry between how attackers and defenders apply AI mean for the viability of detection and response? And what alternative approach can harness the intelligence revolution for the good guys?
Why we went from antivirus to EDR
There was a time when prevention ruled the world. On the endpoint, that meant antivirus that prevented breaches by recognizing and blocking the threat actor’s malware. This was the official best practice, with the National Institute of Standards and Technology guiding all organizations in 2005 to “Deploy antivirus software on all systems for which satisfactory antivirus software is available.” (NIST SP 800-83)
While antivirus vendors like Symantec and McAfee became industry powerhouses, attackers got increasingly good at bypassing AV. By the early 2010s, it was clear that signature-based prevention was no longer effective. Dwell times regularly exceeded a whole year. Over 90% of breaches were identified by someone outside the organization. And in 2013, NIST withdrew its previous guidance, saying that attacks had evolved such that “Largely signature-based security controls, such as antivirus software, cannot keep up with them.” (NIST SP 800-83 REV. 1)
The rise of detection and response gave the advantage back to the defenders and spawned some of the biggest players in the industry. Experts like Rich Bejtlich from Mandiant wrote in The Practice of Network Security Monitoring that “It’s become smarter to operate as though your enterprise is always compromised.” Meanwhile, the availability of cheap and limitless cloud storage meant that telemetry data could be analyzed and stored for as long as needed to support correlated detections, incident response, and threat hunting.
With powerful new solutions such as EDR and NDR operationalizing the “assume breach” model, organizations saw a dramatic improvement in security metrics. Median dwell time fell from 416 days in 2011 to 14 days in 2025 (M-Trends). Internal detection rates, once below 10%, rose to 52%, meaning that the majority of breaches are now discovered by internal security teams. An entire generation of security practitioners has grown up in a world where defense is based on early detection and rapid triage, investigation, and mitigation.
A powerful new trend signals disruption
Much has already been written about the explosion in intelligence playing out in the frantic race between frontier labs at OpenAI, Anthropic, Google, Meta, and their competitors in China. The AI “autonomous task horizon”, or how much time models can spend working well independently, has been doubling every four months since 2023. In our industry, that exponential curve is showing up in metrics such as:
- Google's Big Sleep finding a single exploitable SQLite bug in late 2024 vs 20+ vulnerabilities across established open-source projects by August 2025
- Anthropic’s Opus finding 2 exploits for Firefox vs Mythos finding nearly 100x as many
- Average time from vulnerability disclosure to weaponization dropping from 63 days in 2018 to -7 days in 2025. Negative because so many vulnerabilities are now weaponized before they are even published
Clearly, attackers are taking full advantage of agentic technology to take on more targets, faster. Anthropic published a report in late 2025 on the first AI-orchestrated cyber espionage campaign. The threat actor, codename GTG-1002, achieved over 80% automation across the kill chain while successfully targeting multiple organizations in parallel, with human oversight limited to authorizing exploit execution, approving credential harvesting, and deciding on what crown jewels to bring back from the victims. Anthropic’s researchers wrote in their conclusion that “the techniques we're describing today will proliferate across the threat landscape.”
The danger in this proliferation lies in the asymmetry between threat actors like GTG-1002 and the defenders in the SOC. While the bad guys apply exponentially improving intelligence across every step of their attack, the defenders are using solutions that can apply large language models (LLMs) only at the tail end of their workflow. The asymmetric application of AI will drive a generational shift in defensive strategy.
It’s important to understand that this asymmetry is inherent in how tools like EDR work. Only the most basic or well-known attacks are blocked in real-time. Nearly all meaningful detections depend on millions of events being collected, filtered locally, correlated over a time window in the cloud, and flagged in an alert. Defenders can use an AI agent to help with faster alert triage, but even the smartest AI can’t triage an alert that was never generated.
So threat detection is not a good use case for LLMs, while attacks will accelerate with exponential improvement in autonomy and exploitation. As a result, we can expect to see attackers able to break in more consistently, achieve their objectives more quickly, and do it across more targets. The D&R model that worked well for over a decade will increasingly be called into question.
When will it happen?
The recent lab breakouts at OpenAI and Anthropic are a wake-up call. Both major frontier labs reported in recent weeks that advanced models escaped from what was supposed to be a contained testing environment. With one hand tied behind their back, these models hacked into dozens of victim organizations and evaded detection on both sides. Neither the testers nor the victims noticed what was happening.
Notably, these attacks used techniques ranging from vulnerability exploits, to supply-chain compromises, and SQL injections. The models proved adept at attacks and even completed objectives such as credential theft and database access. In other words, Mythos and its peers have proven their ability to plan and carry out stealthy cyber attacks. Fortunately, the American frontier labs are buying us time by enforcing strict guardrails in models like Fable and delaying releases of even more advanced models.
Can we count on the responsibility of model providers for much longer? The likely answer is no. A recent report by the SANS Institute and the Cloud Security Alliance projected that open-weight Mythos-class models will become publicly available between November 2026 and May 2027. The report states that “If comparable offensive capabilities emerge in other frontier models within months, and in open-weight models within six months to a year, the defensive advantage conferred by early access becomes time-limited by definition.”
In fact, unofficial statements from AI lab security leaders at the recent Black Hat conference compressed the timeline down to just 3-6 months from now. The responsible working assumption is that by the spring of 2027 we will be facing threat actors with weaponized Mythos-class AI.
An urgent shift back to prevention
As attackers learn to apply powerful new AI models across the kill chain, defenders will come under increasing pressure to apply the same class of models for protecting their organizations. This is where the asymmetrical AI alignment will come into play. Today’s “assume breach”, detect and respond, strategy will fall short as exponential gains in intelligence are limited to late-stage triage work. The priority will be to adopt new practices where LLM technology can effectively be applied.
This is where defenders will rediscover the prevention-centric approach: don’t give them an inch. In a world where vulnerabilities can be discovered and weaponized in minutes, proactive risk reduction will be the focus. Instead of detections and alerts, policies and issues will be at the heart of the security operation. And the good news is that LLMs and AI agents are great at proactive risk reduction. Preventing risk does not carry the AI asymmetry of detecting threats.
Expect to see a concerted effort at shrinking the organization’s attack surface, for example through aggressively eliminating app sprawl and unvetted software. Supply chain risks that are today freely introduced by developers and “citizen developers” empowered by local agentic tools will be increasingly restricted. And shadow AI will be heavily curtailed, with guardrails enforced across every AI tool that may unwittingly serve as an entry point for its malicious cousins in the wild.
These proactive measures will be carried out by specialized defensive AI agents that take preventative actions without introducing friction to end-users or overhead to the defenders. We may see that, as a side effect, SOC teams deal with significantly less noise than before. This new normal would mean less stress and burnout for security teams, with greater flexibility and savings around premium EDR and MDR solutions.
Start preparing today
The most valued security leaders are the ones that prepare the organization before the storm. If you believe there’s a reasonable chance that asymmetrical alignment with AI improvement will challenge today’s reactive defense strategies, there are steps you can already take.
First, inform your team and leadership on why AI advances are not distributed evenly. Explain that GenAI is much better at carrying out attacks than detecting them. Discuss the importance of aligning strategies and toolsets with the vector of AI advancement. And finally, identify how that can be achieved in practice.
For most organizations, the shift to prevention will involve a significant ramp up on policy definition, risk reduction, and controls enforcement. The good news is that these proactive steps are a great fit for GenAI and will quickly get easier and more automated. A new generation of security products will emerge to deliver AI-powered prevention off-the-shelf. At Glow, we’ve been working with many security teams to start this process of shifting left from detection to prevention. D&R may struggle to keep up with Mythos-class attacks, but applying AI proactively can deliver a safer, more predictable, and cost-efficient security program for the business.






