In 2025, artificial intelligence (AI) stands at the forefront of cybersecurity discussions. Experts anticipate a cyber battleground where both defenders and attackers leverage AI, but with attackers likely gaining a more significant edge.

The Dual Role of AI in Cybersecurity

AI is a double-edged sword in the cybersecurity realm. According to Willy Leichter, CMO of AppSOC, attackers will exploit AI for malicious purposes more aggressively than defenders can deploy it for protection. “Attackers face fewer constraints—they aren’t burdened by concerns over ethics, accuracy, or unintended consequences,” he notes. This lack of restriction allows threat actors to use AI for hyper-personalized phishing attacks and probing networks for vulnerabilities in legacy systems.

Defensively, while AI offers enormous potential, its adoption is slowed by legal, ethical, and operational hurdles. Chris Hauk, a privacy expert at Pixel Privacy, predicts that cybersecurity in 2025 will become a battlefield of AI versus AI, where attackers continuously refine their tactics while defenders enhance their AI-driven countermeasures.

Rising Threats to AI Systems

With AI increasingly integrated into critical systems, cyber adversaries are expected to target AI infrastructure itself. Leichter warns of an expanding attack surface that includes AI models, datasets, and machine learning operations. He highlights the risks when AI applications are hastily moved from experimental labs to live production environments without thorough security vetting.

Karl Holmqvist, CEO of Lastwall, underscores the consequences of deploying AI tools without proper safeguards. “Inadequate privacy measures and weak security frameworks will leave these systems vulnerable to breaches and manipulation,” he explains. To combat this, Holmqvist advocates for robust security foundations, transparent AI governance, and continuous monitoring of AI deployments.

The Supply Chain Attack Vector

AI’s adoption further complicates the software supply chain, presenting new opportunities for attackers. Leichter points out that complex software ecosystems relying on third-party and open-source components are ripe for exploitation. The emergence of AI adds layers of complexity, creating novel vectors of attack on AI datasets and models. Managing the integrity of these datasets and ensuring the security of AI models will be a top priority in 2025.

The Growing Risk of Data Poisoning

Michael Lieberman, CTO of Kusari, foresees a surge in data poisoning attacks aimed at large language models (LLMs). Malicious actors may introduce compromised models into the supply chain, similar to the 2024 incident on the Hugging Face platform where backdoored LLMs were discovered. Given that most organizations rely on pre-trained models, Lieberman emphasizes the need for greater transparency in model provenance to prevent such attacks.

Lieberman also cautions that a significant supply chain breach—on par with the SolarWinds Sunburst incident—may be required to galvanize the industry into taking AI threats more seriously. Without proactive measures, attackers could maintain their advantage, especially as defenders struggle with budget constraints and a lack of immediate return on investment in security.

The Emergence of Autonomous Cyber Threats

2025 may also witness the rise of agentic AI—autonomous systems capable of making independent decisions and evolving their tactics. Jason Pittman, a cybersecurity professor at the University of Maryland Global Campus, warns of the dangers posed by such AI-driven threats. Unlike traditional systems that require human input, agentic AI can identify vulnerabilities, infiltrate networks, and adapt in real time without human oversight.

Pittman likens the potential impact of agentic AI to the Morris Worm of the late 1980s, emphasizing that even an accidental release of such technology could have catastrophic consequences. With open-source AI tools readily accessible, the likelihood of autonomous cyber weapons emerging is no longer a distant possibility.

AI’s Role in Data Security

Despite the threats posed by AI, it also holds promise for enhancing data security. Rich Vibert, CEO of Metomic, highlights how AI can help protect sensitive data, such as personally identifiable information (PII). His research reveals that 40% of files on Google Drive contain PII, exposing businesses to potential breaches.

In response, companies are expected to deploy AI-driven tools for automated data classification, ensuring sensitive information is identified, tagged, and secured. This approach will enable organizations to manage the growing volume of data while minimizing unnecessary exposure.

Managing Expectations and the AI Hype

While AI offers potential for innovation in cybersecurity, not all expectations will be met. Cody Scott, a senior analyst at Forrester Research, predicts that CISOs will deprioritize generative AI use in security operations by 2025 due to disappointing results. Despite initial enthusiasm, many organizations are likely to experience disillusionment as practical outcomes fail to materialize.

Scott notes that while AI-driven security operations centers have been heavily marketed, the reality is far from the vision. Budget constraints, combined with the difficulty of achieving tangible benefits, will likely lead to a decrease in AI deployments within cybersecurity.

Conclusion: Preparing for an AI-Driven Cyber Future

As we look ahead to 2025, it’s clear that AI will play a pivotal role in shaping the cybersecurity landscape. While it offers powerful tools for defending against cyber threats, it also presents new risks that require careful management. Organizations must strike a balance between leveraging AI for innovation and safeguarding against its misuse.

By prioritizing robust security frameworks, enhancing transparency in AI deployments, and fostering industry-wide collaboration, we can hope to mitigate the risks and harness AI’s potential to create a safer digital world.

PTSI Editorial Team

Support Line: Phone: +1 646-535-HELP (4357) Email: helpdesk@progressny.com Support web: helpdesk.progressny.com