The role of artificial intelligence (AI) in cybersecurity continues to be a critical focus in 2025, shaping both the offensive and defensive strategies in the cyber domain. Experts foresee a dual-edged sword—AI will empower defenders to fortify systems but will also serve as a formidable tool for attackers.
AI: A Tool for Both Attackers and Defenders
Willy Leichter, CMO of AppSOC, predicts that AI will increasingly feature on both sides of the cyber war. Attackers, unconstrained by ethical considerations, are likely to exploit AI for highly targeted phishing, identifying legacy vulnerabilities, and conducting reconnaissance on vast networks. Meanwhile, defenders face stricter legal and practical limitations that may slow the adoption of AI solutions. As Chris Hauk of Pixel Privacy observes, 2025 will be a year of “AI versus AI,” with attackers and defenders leveraging past data to devise new strategies and countermeasures.
The Rising Threat to AI Systems
AI systems themselves will become prime targets for adversaries. Leichter warns of an expanded attack surface as AI applications, rushed to production without robust security, are increasingly exploited. Karl Holmqvist of Lastwall echoes this concern, pointing to the “Wild West” approach to AI deployment, which leaves systems vulnerable to breaches and manipulation. Organizations are urged to adopt transparent AI frameworks and prioritize foundational security measures to mitigate these risks.
Security teams must assume greater responsibility for protecting AI systems, notes Leichter. Many AI projects, initially driven by business or data science teams, often bypass standard security protocols. Bringing such projects under the security umbrella will be crucial to counteract emerging threats.
Software Supply Chains Under Siege
AI will further complicate the already vulnerable software supply chain. The reliance on third-party and open-source components introduces additional risks, as adversaries can poison datasets and manipulate pre-trained models. Michael Lieberman of Kusari highlights the growing prevalence of data poisoning attacks aimed at large language models (LLMs). Incidents like the 2024 Hugging Face malware breach underscore the ease with which malicious actors can compromise AI systems, especially those relying on opaque datasets.
The Rise of AI-Powered Threat Actors
Justin Blackburn of AppOmni foresees an increase in sophisticated attacks enabled by AI. Threat actors, including less-skilled adversaries, will leverage AI-powered bots to execute large-scale attacks with minimal effort. These tools lower the barrier to entry and accelerate the pace of cyberattacks, enabling adversaries to disrupt services and steal sensitive data on an unprecedented scale.
Agentic AI: A New Frontier
The emergence of agentic AI—autonomous systems capable of adapting and making decisions without human input—poses additional challenges. Jason Pittman of the University of Maryland warns that these systems could develop autonomous cyberweapons, identifying vulnerabilities and evolving attack strategies in real time. The potential misuse of agentic AI, coupled with the accessibility of advanced AI tools, could lead to accidental or deliberate releases of powerful cyber threats.
Defensive Innovations in AI
Despite the challenges, AI offers significant opportunities for enhancing cybersecurity defenses. Automated data classification, for example, can help organizations safeguard sensitive information such as personally identifiable information (PII). Rich Vibert of Metomic notes that AI-driven tools will enable businesses to tag and secure sensitive data, reducing the risk of exposure in collaborative workspaces and cloud environments.
Balancing Hype and Reality
While AI holds promise, it may also lead to disillusionment. Cody Scott of Forrester Research predicts that Chief Information Security Officers (CISOs) will deprioritize generative AI initiatives due to a lack of tangible value. The vision of fully autonomous security operations centers remains far from reality, as organizations struggle with limited budgets and unfulfilled expectations.
Conclusion: Preparing for a Dynamic Landscape
The cybersecurity landscape in 2025 is poised for significant transformation as AI becomes more pervasive. Organizations must balance the benefits of AI-driven defenses with the risks posed by AI-enabled threats. Proactive measures, including robust security frameworks, transparent AI development, and continuous monitoring, will be essential to navigate this complex and dynamic environment. As AI continues to evolve, so too must the strategies to secure it, ensuring that innovation does not come at the cost of vulnerability.


