Jessica Entwistle
August 24 2026
Chris Lehane, a senior leader at OpenAI, has warned that organisations should prepare to defend against "ongoing, persistent" cyber attacks launched or assisted by advanced AI models. Speaking to The Guardian, Lehane explained that as AI systems gain more sophisticated planning and execution capabilities, they will increasingly be used to automate reconnaissance, vulnerability discovery and offensive operations. OpenAI announced this week that it has paused development of its most advanced internal models amid rising safety concerns, and Lehane emphasised the need for new safety standards and defensive measures as AI capabilities continue to advance. Critics have accused AI firms of acting recklessly by releasing powerful models without adequate safeguards, raising questions about the balance between innovation and security.
This development is significant because it signals a shift in how AI is understood within the security community, from a defensive tool to a dual-use technology that can significantly lower the barrier to entry for attackers. AI-powered automation could enable less skilled adversaries to conduct sophisticated attacks at scale, while nation-state actors could use AI to accelerate reconnaissance, exploit development and evasion techniques. For UK organisations, this means that the threat landscape is likely to become more dynamic, with attackers able to adapt and iterate faster than traditional manual methods allow. AI models could be used to generate convincing phishing content, identify zero-day vulnerabilities, automate lateral movement within networks, or evade detection by learning from defensive responses. This also raises questions about how organisations should govern the use of AI internally, particularly in environments where AI agents have access to sensitive systems, data or decision-making processes. The risk is not only external but also internal, as poorly governed AI tools could be misused or exploited by insiders or through supply chain compromise.
UK businesses should review how AI tools are being used internally, whether appropriate access controls and monitoring are in place, and whether security teams have the capability to detect and respond to AI-assisted attacks. Consider whether your threat intelligence and detection capabilities are designed to handle faster, more adaptive adversaries who may use AI to automate reconnaissance or exploit development. Review whether your organisation has governance policies in place for AI use, including who can deploy AI agents, what data they can access, and how their activity is logged and monitored. Ensure that security operations teams are trained to recognise the characteristics of AI-assisted attacks, such as unusually rapid reconnaissance, adaptive evasion techniques or automated social engineering. Consider whether your organisation has tested its ability to respond to attacks that evolve in real time based on defensive actions. Finally, review whether your organisation has a clear understanding of where AI is being used across the business, including shadow AI deployments that may not be centrally managed or secured.
Source: The Guardian