For decades, one of cybersecurity’s biggest challenges was finding vulnerabilities.
AI may be about to reverse that problem.
What happens when enterprises can suddenly find more vulnerabilities than their security and infrastructure teams can operationalize, test, patch, and mitigate?
This question drove a discussion at the AI Networking Summit 2026 in Dallas that featured Mick Curry of Fidelity, John Feldmayer of eBay, Chris Moretti of Cigna Health, and Tom Gillis of Cisco.
The conversation pointed to a fundamental shift in enterprise security: AI is beginning to operate at a speed that traditional security processes were never designed to match.
For enterprise leaders, that makes security, control, and trust inseparable.
The challenge is no longer just discovering risk. It is determining how quickly organizations can respond to it without creating new risks in the process.
AI’s ability to analyze code, test systems, identify attack paths, and search for weaknesses is advancing rapidly.
During the discussion, Gillis described Cisco’s experience with Project Glasswing. This Anthropic program provided a small group of critical systems vendors with early access to advanced models for security testing.
What Cisco found was significant.
The models were not just faster versions of existing security tools. They could now explore systems in new ways, including testing live systems without access to the underlying source code.
That last point may be the most important.
Many enterprise security processes were intentionally designed to move carefully. Changes are reviewed. Updates are tested. Maintenance windows are scheduled. Application teams conduct regression testing before patches reach production.
Those safeguards exist for good reason.
But AI changes the timeframe those processes must operate in.
The tension is becoming clear: enterprises need to move faster without giving up the controls that protect availability, resilience, and critical systems.
Moretti argued that organizations should already be examining security processes that take days or weeks and asking how they can be compressed dramatically.
That is not simply an argument for faster patching.
It is an argument for a different security operating model.
A vulnerability-management process built around quarterly or monthly cycles cannot simply be accelerated by asking the same teams to work harder. Automation, deployment pipelines, testing, segmentation, access controls, and infrastructure management must evolve with it.
AI’s speed is exposing the limits of processes designed for a different era.
But faster is not automatically safer.
Feldmayer described the issue from an enterprise operator’s perspective at eBay. Even with automated deployment pipelines, moving too quickly introduces its own availability risks.
That means the answer cannot simply be “patch everything immediately.”
This is where control becomes central to the AI security conversation.
The goal is not simply to make infrastructure move at machine speed. It is to create an environment that can move faster without losing the safeguards that keep the business running.
That could mean stronger segmentation, better identity and access management, more automated testing, canary deployments, continuous updates, and more resilient architectures.
It also means accepting that no single security control will solve the problem.
Later in the discussion, the panel returned to this point.
Enterprises already know how to deploy patches quickly. The harder question is how those changes affect availability, resiliency, and the broader technology environment.
That requires looking beyond the patch itself.
That may be the larger lesson for enterprise IT.
AI security cannot be separated from infrastructure strategy.
If threats move faster, networks, security controls, deployment processes, identity systems, and operating models must respond faster, too.
Security becomes less about a single defensive action and more about the resilience of the entire environment.
As AI takes on more operational work, another question follows: How much control should enterprises hand over?
The panel discussed how IT service management itself could evolve as AI agents begin performing work that currently passes through human approvals and checkpoints.
In the near term, those human checkpoints still matter.
The goal should not be automation for automation’s sake. Enterprises need to understand where AI can safely accelerate a process, where controls must remain, and where human judgment is still essential.
That same principle showed up in Cisco’s security testing.
Gillis noted that advanced AI models became significantly more effective when paired with skilled human red teamers. Rather than making those experts obsolete, AI amplified what they could accomplish.
That suggests a useful model for enterprise AI more broadly:
Trust does not require choosing between humans and AI. It requires understanding where each should have authority.
The discussion began with Project Glasswing and Mythos, but it ended much more broadly.
The security challenge is not tied to a particular model or vendor.
As increasingly capable models become widely available—including open-weight models—the ability to analyze and attack systems at unprecedented scale will spread with them.
Gillis closed one audience exchange with what may be the clearest summary of the issue.
That is the shift enterprise leaders need to prepare for.
AI may give defenders extraordinary new capabilities. It may also give attackers many of the same capabilities.
The differentiator will be how quickly organizations can adapt.
The discussion points toward a security model built on several principles.
Speed without control creates risk. Enterprises need faster security processes, but not at the expense of availability and resilience.
Automation has to extend beyond patch deployment. Testing, segmentation, identity, change management, infrastructure operations, and recovery all need to evolve.
Human expertise still matters. Advanced models can dramatically amplify skilled security practitioners, but the panel’s experience suggests human judgment remains critical for filtering results, evaluating risk, and making operational decisions.
Infrastructure is part of the security strategy. Networks, compute, identity, operations, and security can no longer be treated as separate conversations when AI spans all of them.
And perhaps most importantly, the assumptions that governed enterprise IT for decades are changing.
Trust in this new environment will not come from slowing AI down.
It will come from building infrastructure and controls that can keep up with it.
AI can analyze systems, test APIs, identify vulnerabilities, and explore potential attack paths at significantly greater speed and scale. That means enterprises may face more vulnerabilities than existing security processes can quickly address.
Traditional patching and change-management cycles can take days or weeks. As AI accelerates vulnerability discovery, enterprises may need to move toward continuous updates, automated testing, and response cycles measured in hours.
Not entirely. Rapid changes can create availability and resiliency risks. Enterprises also need mitigating controls such as segmentation, identity and access management, automated testing, and resilient deployment practices.
The panel’s experience suggests AI can make skilled security practitioners substantially more effective. Human expertise remains important for directing models, filtering false positives, evaluating recommendations, and balancing security risk against operational risk.
AI-driven security affects much more than individual applications. Networks connect workloads, users, applications, data, and infrastructure, making segmentation, access control, observability, and resilience important parts of an enterprise AI security strategy.
The questions raised in Dallas are only becoming more urgent.
How should enterprises secure infrastructure when vulnerability discovery moves at machine speed? Where should automation take over? Where should human control remain? And what will it take to build AI systems that enterprises can truly trust?
Continue these conversations at the AI Networking Summit 2026 in New York City, where enterprise IT leaders, technologists, and practitioners will explore the infrastructure, networking, security, and operational models required for the AI era.