AI vs. AI: How to Reshape Defense Faster than Attackers Reshape Offense

Nadir Izrael (Chief Technology Officer and Co-founder · Armis)

RSAC 2026 Conference · Main Stage Keynote

Overview

Nadir Izrael, CTO and co-founder of Armis, delivered a compelling address at RSA Conference, urging a radical transformation in cybersecurity defense strategies. Titled "AI vs. AI: How to Reshape Defense Faster than Attackers Reshape Offense," the talk highlighted the unprecedented shift in enterprise environments where non-human, AI-driven agents are rapidly outnumbering human employees. Izrael posited that the traditional, human-speed, reactive security models are critically ill-equipped to counter the escalating threat landscape dominated by sophisticated, AI-powered offensive capabilities.

Watch on YouTube

Key moments

  1. 0:00 Introduction and Armis's mission to stop attacks
  2. 1:00 Envisioning future enterprises with millions of AI agents
  3. 4:00 Assets, Identity, and Decision Context as key attack dimensions
  4. 4:30 Today's diversified attack surface targeting AI agents and code
  5. 5:30 Specific AI threat model examples: poisoning, evasion, blind spots
  6. 6:40 Rising AI-generated attacks and reactive nature of current defenses

AI vs. AI: How to Reshape Defense Faster than Attackers Reshape Offense

Speakers: Nadir Izrael, Chief Technology Officer and Co-founder, Armis

Conference: RSA Conference

YouTube: https://www.youtube.com/watch?v=X1bbj9EE9Gg

Overview

Nadir Izrael, CTO and co-founder of Armis, delivered a compelling address at RSA Conference, urging a radical transformation in cybersecurity defense strategies. Titled "AI vs. AI: How to Reshape Defense Faster than Attackers Reshape Offense," the talk highlighted the unprecedented shift in enterprise environments where non-human, AI-driven agents are rapidly outnumbering human employees. Izrael posited that the traditional, human-speed, reactive security models are critically ill-equipped to counter the escalating threat landscape dominated by sophisticated, AI-powered offensive capabilities.

The core message emphasized that the battleground has fundamentally changed from human-versus-human to AI-versus-AI. Attackers are already leveraging artificial intelligence to automate exploit generation, craft advanced social engineering campaigns, and identify vulnerabilities at machine speed. Consequently, defenders must abandon outdated manual processes and embrace dynamic, autonomous, and continuously learning AI systems to manage exposure, detect threats, and remediate issues with the necessary agility and scale. This paradigm shift, Izrael argued, is not merely an upgrade but an imperative for survival in the rapidly evolving digital ecosystem.

The talk serves as a critical wake-up call for security professionals, providing practical advice on how to architect future-proof security postures. It underscores the urgency of moving towards proactive, intent-based defense mechanisms that can operate at machine speed, manage vast networks of interconnected agents, and effectively counter the sophisticated, self-evolving threats posed by adversarial AI.

Background

▶ Watch: Introduction and Armis's mission to stop attacks (0:00)

The foundational premise of Izrael's talk is a stark projection of the near-future enterprise landscape. Gartner and other industry estimates predict that within two to three years, the ratio of humans to non-human agents within a typical company will reach an astounding 1:1,000. This means an organization with 1,000 employees, like Armis today, could manage approximately one million agents, while a 10,000-person enterprise would contend with ten million. This exponential growth of autonomous entities fundamentally alters the operational dynamics of an organization, transforming it into something akin to a "city" of interconnected agents, each making decisions and interacting with vast amounts of data and systems.

Managing such an environment necessitates a shift from deterministic, command-based control to a more statistical, infrastructure- and policy-driven approach, similar to how cities are governed. The complexity of decision-making within these agent-centric enterprises presents a profound challenge. Tracing back the origin of a failed operation or a cyber incident becomes incredibly difficult when hundreds or thousands of agents are involved in every decision, with humans potentially serving only as an initial input, if at all. This complexity forms a critical precursor to the cybersecurity challenges.

The attack surface itself is no longer limited to human endpoints. Izrael highlighted three major dimensions that define this new infrastructure and attack surface: Assets (the underlying building blocks), Identity (encompassing both human and non-human entities, crucial for understanding, governing, and controlling the environment), and Decision Context (the abstract but vital understanding of why and how decisions are made by agents). Attackers are now targeting AI agents directly through social engineering and vulnerabilities, AI-generated code (turning supply chain attacks "on steroids" due to numerous avenues of entry), and even Guardian agents—the very security tools designed to protect the environment.

The current threat model demonstrates a diverse array of AI-focused attacks. These include model poisoning, where adversaries influence model training data to manipulate outcomes; evasion of logic, enabling inputs to an existing model to expose information or alter its behavior; exploitation of autonomous blind spots in agentive workflows that operate without human intervention; and leveraging the adaptive learning capabilities of models to change and exploit them on the fly. Despite these advanced threats, the prevailing defense posture in most organizations remains largely reactive. Security teams often operate in a human-in-the-loop mode, responding to alerts at human speed, a pace utterly insufficient to counter machine-speed attacks. This creates a significant "detection gap" and an ironic disparity between security teams' confidence and their actual vulnerability levels, as revealed in Armis's recent cyber warfare report.

Key Findings

▶ Watch: Assets, Identity, and Decision Context as key attack dimensions (4:00)

The talk unveiled several critical findings regarding the evolving cyber threat landscape and the current state of defense:

  1. Explosive Growth of AI-Driven Attacks: AI-generated attacks are experiencing a massive surge, utilized by nation-state actors, criminal organizations, and other threat groups. This widespread adoption of AI significantly lowers the bar for launching successful attacks, making sophisticated exploits accessible to a broader range of adversaries.
  2. Accelerated Exploit Development: Attackers are now using AI to code exploits with unprecedented speed. What once took security researchers and intelligence agencies 7-12 days to develop an exploit for a known vulnerability can now be achieved in a matter of minutes using agentic coders like Claude. This drastic reduction in time-to-exploit nullifies traditional response windows.
  3. Emergence of "Flat Networks" through AI Integration: Enterprises are inadvertently creating vast, interconnected "flat networks" by integrating AI with nearly every system and data platform. Tools like OpenClaw, an open-source platform for building agentic bots, have seen rapid, often unsanctioned, adoption within organizations. These bots connect to critical infrastructure, creating a massive, interconnected attack surface that extends to the internet, representing a "security team's worst nightmare" in terms of control and segmentation.
  4. Inconsistent Security of AI-Generated Code: An Armis report highlighted significant disparities in the security quality of code generated by different AI coding engines. When tested against 35 curated tasks reflecting real-world threat actor tactics, some models performed very poorly, producing code riddled with vulnerabilities, while others demonstrated a decent level of security. This finding underscores the need for organizations to implement policies guiding the use of secure AI code generation tools.
  5. Defensive Lag in the AI Era: While offensive AI is already highly advanced and operating at machine speed, defensive strategies remain largely reactive and manual. Most organizations are still stuck in a model of generating alerts and relying on human intervention for monitoring and remediation. This fundamental mismatch in speed and autonomy is unsustainable.
  6. The Imperative of Dynamic, Intent-Based Defense: To counter the dynamic nature of AI-driven attacks, defense must shift from static rules to dynamic, continuous, and intent-based controls. AI agents lack the inherent "self-preservation" instincts of humans and will execute commands that could harm the enterprise, necessitating an autonomous, real-time control mechanism.
  7. Evolution of Security Questions: The fundamental questions CISOs ask have evolved. From "What do I have?" (asset inventory) to "What's important?" (contextual prioritization of vulnerabilities) and "How do I fix it?" (remediation), the new imperative is "How do I agent? How do I scale?" This reflects the need for security to operate autonomously and resiliently at scale. The battle is no longer human-versus-human but unequivocally AI-versus-AI.

Technical Deep Dive

▶ Watch: Today's diversified attack surface targeting AI agents and code (4:30)

The technical underpinnings of Izrael's argument rest on the profound architectural and operational shifts occurring within modern enterprises, driven by the proliferation of AI and autonomous agents. The projected 1:1,000 human-to-non-human agent ratio fundamentally redefines enterprise infrastructure. This isn't merely an increase in devices; it's an explosion of intelligent, often autonomous, entities making decisions, communicating, and interacting with systems. Managing such an environment requires a departure from traditional IT paradigms, moving towards a model where oversight is infrastructural and policy-driven rather than individual command-and-control.

The attack surface itself is characterized by three critical dimensions: Assets, Identity, and Decision Context. Assets encompass the entire spectrum of connected devices, applications, and data stores, which are now increasingly managed or accessed by AI agents. Identity, traditionally focused on human users, must now extend to include non-human identities, requiring sophisticated mechanisms for authentication, authorization, and governance of AI agents. The Decision Context is perhaps the most abstract but vital dimension, referring to the understanding of the rationale and processes behind an agent's actions. In a world where thousands of agents contribute to a single decision, understanding this context is crucial for incident response and accountability.

AI-specific attack vectors are already prevalent and becoming more sophisticated:

  • Model Poisoning: This involves adversarial manipulation of the data used to train AI models. By injecting malicious or skewed data, attackers can influence the model's learning process, leading to biased, incorrect, or exploitable outcomes. This can manifest in anything from a security model misidentifying legitimate activity as benign to a predictive maintenance system failing to flag critical equipment issues.
  • Evasion of Logic: Attackers craft specific inputs designed to bypass a model's intended security controls or trigger unintended behaviors. This could involve crafting adversarial examples for image recognition systems or inputting specific text sequences into an LLM to elicit sensitive information or execute unauthorized commands.
  • Autonomous Blind Spots: As agents operate with increasing autonomy, they create workflows that may lack human oversight. Attackers exploit these blind spots, targeting agent-to-agent communication, automated data flows, or decision-making loops where human intervention is absent, allowing for prolonged undetected activity.
  • Adaptive Learning Exploits: AI models are designed to learn and adapt. Attackers can leverage this by feeding the model carefully constructed data over time, gradually "teaching" it to behave in a malicious way or to ignore specific threats, effectively turning the defensive AI against itself.

A prime example of the emerging threat landscape is OpenClaw, an open-source platform enabling the creation of agentic bots. Its rapid adoption within organizations, often without the knowledge or sanction of security teams, has led to a proliferation of bots connecting to various systems and data platforms. The inherent vulnerabilities within OpenClaw's open-source repositories, combined with its widespread, unmanaged deployment, create a "complete corporate flat network." This scenario undoes decades of network segmentation efforts, connecting sensitive internal systems to the internet through these AI agents, presenting an unparalleled attack surface.

Further illustrating the technical challenge, Armis's recent report on AI coding engines revealed significant security disparities. The study involved running various AI coding engines (such as Claude) on 35 curated tasks that mimic tactics used by threat actors against AI. The generated code was then scanned for vulnerabilities actively exploited in the wild. The findings indicated that not all models are created equal; some produced code with a high number of vulnerabilities, while others performed more securely. This highlights a critical supply chain risk where developers, attempting to accelerate development, may inadvertently introduce significant security flaws by using less secure AI coding assistants. This necessitates a "policymaking and infrastructure" approach to guide organizations toward using more secure AI development tools.

The speaker stressed that the response to these technical challenges must be equally sophisticated. The current reliance on static rules for identity privileges, environmental monitoring, and incident response is obsolete. Instead, security must become dynamic, continuous, and intent-based. This means systems must understand the intent behind an agent's actions, continuously evaluate its behavior, and adapt controls in real-time. The core technical shift required is embracing machine-speed automation for defensive actions, moving beyond the fear of relinquishing control to autonomous systems, as human speed is simply no longer sufficient to counter the pace of AI-driven attacks.

Demo / Proof of Concept

▶ Watch: Specific AI threat model examples: poisoning, evasion, blind spots (5:30)

While the talk did not feature a live demonstration or a proof of concept, Nadir Izrael referenced an Armis report detailing the security performance of various AI coding engines. This report, which runs coding engines on 35 curated tasks mirroring threat actor tactics and then scans the resulting code for vulnerabilities, serves as a practical illustration of the risks and disparities in AI-generated code, providing empirical evidence for the claims made about supply chain vulnerabilities.

Defensive Implications

▶ Watch: Rising AI-generated attacks and reactive nature of current defenses (6:40)

The insights presented by Nadir Izrael demand a fundamental re-evaluation and overhaul of current cybersecurity defensive strategies. The era of reactive, human-speed defense is over; the future necessitates an AI-driven, proactive, and adaptive security posture.

  1. Shift to Adaptive Offense (Defense-Oriented): Defenders must transition from merely detecting and reacting to threats to adopting an "adaptive offense" mindset within their own networks. This means leveraging AI to understand the attacker's perspective, proactively identify weaknesses, and rapidly implement countermeasures. The entire security infrastructure must "sing together" to enable rapid, proactive action rather than just reactive alerts.
  2. Comprehensive Exposure Management: This concept must move beyond a buzzword to become the central pillar of defense. Organizations must focus obsessively on closing gaps and stopping attacks before they happen, not just managing them during or after. This involves continuous assessment of the entire attack surface, understanding contextual risk, and prioritizing remediation based on actual exposure. Defender AI has a significant "home court advantage" here, as it can be trained on internal network specifics and vulnerabilities.
  3. Unified and Comprehensive Platforms: The current landscape of disconnected security tools is no longer viable. To operate at machine speed and scale, security platforms must be unified and comprehensive, allowing for seamless data sharing, correlated threat intelligence, and orchestrated response across all layers of the environment. The privilege of having siloed tools will disappear as the threat accelerates.
  4. Embrace Autonomous Action: The most critical shift is from manual response to autonomous action. Security teams must overcome the historical fear of machine automation and empower AI systems to take dynamic, continuous, and intent-based actions. This includes automated remediation, dynamic policy enforcement, and real-time privilege adjustments, all operating at machine speed to match the pace of attackers.
  5. Continuous Learning in Defense: Just as offensive AI learns and adapts, defensive AI must engage in continuous learning. This involves constantly updating threat models, refining detection algorithms, and adapting response strategies based on new attack patterns and environmental changes. This adaptive capability is essential for building resilient security systems.
  6. Eliminate All Blind Spots: The notion that blind spots in an organization's environment might be safe because attackers don't know about them is obsolete. An attacker's AI platform can "rattle all defenses at once," leverage social engineering against security teams, and autonomously discover unmanaged assets, shadow IT, and other blind spots. Therefore, maintaining an exhaustive, real-time inventory and understanding of all assets—managed, unmanaged, and IoT/OT—is no longer a luxury but an absolute must.
  7. Move Beyond Recommendations to Action: Current security tools often provide recommendations through chatbots or agents. This is no longer sufficient. Defensive AI must move past mere suggestions to automated, actionable enforcement. The goal is not to generate more alerts or advice, but to autonomously reduce exposure and fix issues in real-time.
  8. Strategic Policymaking for AI Adoption: Organizations must implement clear policies regarding the use of AI tools, particularly for code generation. As demonstrated by the Armis report, the security quality of AI-generated code varies significantly. Policymakers should guide the selection and use of AI models that adhere to higher security standards, effectively managing this new form of supply chain risk at an infrastructural level.

In essence, the defensive imperative is to reshape security into a dynamic, intelligent, and autonomous system that can not only keep pace with but also anticipate and neutralize AI-driven attacks before they can inflict damage.

Key Takeaways

  • The Enterprise is Transforming: Organizations are rapidly shifting to an agent-centric model, with non-human AI agents soon outnumbering humans by a factor of 1,000:1, demanding a complete re-architecture of security.
  • Offensive AI is Already Dominant: Attackers are leveraging AI to automate exploit generation and develop sophisticated attacks at machine speed, creating exploits in minutes, rendering traditional human-speed responses obsolete.
  • Defense Must Evolve to AI Speed: Cybersecurity defense must transition from reactive, manual, and alert-driven processes to dynamic, autonomous, and continuously learning AI systems that operate at machine speed.
  • Exposure Management is Paramount: Proactive exposure management—focused on closing gaps and preventing attacks before they happen—is critical, requiring comprehensive visibility into all assets and the elimination of blind spots.
  • Unified Platforms and Autonomous Action are Essential: Disconnected security tools are no longer viable; unified platforms and the empowerment of AI for autonomous action (beyond mere recommendations) are necessary to match attacker agility.
  • The Fight is AI vs. AI: The future of cybersecurity is fundamentally a battle between defensive AI and offensive AI, and organizations must embrace and accelerate their AI adoption for defense to stand a chance.

About the Speaker(s)

Nadir Izrael is the Chief Technology Officer and co-founder of Armis. Armis's mission is centered on helping organizations manage their risk and exposure to effectively stop attacks before they can materialize. Izrael's insights are rooted in his extensive experience in cybersecurity and his company's focus on understanding and securing the evolving threat landscape driven by interconnected devices and AI.

Reviews

Dr. Zero (Offensive Security Researcher) — WEAK

Nadir Izrael delivers a polished RSA-style keynote that is fundamentally a marketing vehicle for Armis's platform narrative. The '1:1,000 human-to-agent ratio' framing is Gartner-borrowed and speculative, the technical claims about AI-generated exploits are asserted without rigorous supporting evidence, and the 'defensive implications' section reads like product positioning copy. There is no original research here — no novel attack primitives, no published methodology, no reproducible findings. The 'OpenClaw' reference and the 35-task coding engine benchmark are the closest things to empirical claims, but neither is presented with enough rigor to evaluate. This is a sophisticated awareness…

Heather Calloway (CISO) — WEAK

Nadir Izrael raises a real and urgent structural problem — the explosive growth of non-human agents in enterprise environments is genuinely changing the attack surface and rendering human-speed defense inadequate. But the talk never escapes the gravitational pull of its own vendor positioning. The governance questions this shift demands — who owns non-human identity risk, how boards should think about autonomous action authorization, what regulatory exposure looks like when an AI agent causes a breach — go entirely unasked. What's left is a well-produced threat briefing that tells operators the world is on fire without giving them anything to do about it that doesn't involve buying a…

→ Top-rated talks at RSAC 2026 Conference

All talks from RSAC 2026 Conference