tech

The next phase of AI cybersecurity still needs humans

The new phase of AI-powered cybersecurity depends on how effectively humans can direct these models.

The next phase of AI cybersecurity still needs humans

TL;DR

  • AI models like Anthropic's Mythos and OpenAI's GPT-5.5-Cyber are powerful tools for finding software bugs and writing exploits.
  • Companies testing these models found a significantly higher number of bugs compared to their usual rates.
  • These AI systems are effective at linking low-severity vulnerabilities into workable attack chains.
  • Despite their power, the AI models require human expertise to validate findings, guide workflows, and assess the practical significance of vulnerabilities.
  • A false positive rate of around 30% was observed, which decreased as models were trained on specific environments.
  • Cisco's blueprint for AI security suggests instructing models to make 'checkable' claims and verify their own findings to manage unreliable output.
  • While attackers may not face the same learning curve, human oversight remains crucial for effective and reliable use of AI in cybersecurity.