Frontier AI and the Evolving Cyber Security Landscape
Recent insights from industry leaders, including Anthropic and the UK’s National Cyber Security Centre, highlight a rapidly shifting threat landscape where both risks and opportunities are emerging at scale.
Over the past two years, AI capabilities have progressed significantly. What once required deep technical expertise, time and specialised knowledge to uncover, such as software vulnerabilities, can now be identified far more efficiently. Frontier models are increasingly capable of analysing, reasoning and manipulating code, lowering the barrier to discovering and exploiting weaknesses.
In some cases, these models have already identified long-standing vulnerabilities that persisted despite decades of human review and automated testing. This signals a fundamental shift. The challenge is no longer just the existence of vulnerabilities, but the speed at which they can now be found and potentially exploited.
However, the same capabilities also present a powerful opportunity. When applied responsibly, AI can strengthen cyber resilience by identifying and remediating vulnerabilities before they are exploited. Initiatives such as Anthropic’s Project Glasswing demonstrate how frontier models can be leveraged to secure critical software and improve overall system integrity.
What this means for organisations
As AI reshapes the cyber threat environment, organisations must adapt their approach to security and governance. Traditional models, often reactive and manual, are no longer sufficient in an environment where threats can evolve in near real time.
Maintaining a strong cyber security baseline remains essential. Aligning with established frameworks such as the Australian Signals Directorate’s Information Security Manual and the Essential Eight continues to provide a critical foundation for reducing risk.
Key areas of focus include:
- Reducing attack surfaces and pathways by limiting unnecessary system exposure and applying network segmentation
- Adopting a proactive patching approach, recognising that vulnerability discovery will accelerate
- Leveraging AI to strengthen systems, particularly in secure software development practices
- Implementing layered, defence-in-depth architectures that assume breach and prioritise verification
These measures are not new, but their importance is amplified in an AI-enabled landscape.
A governance perspective
For records and information management professionals, this evolution reinforces the growing intersection between information governance and cyber security. As systems become more intelligent and interconnected, the integrity, accessibility and protection of information assets become even more critical.
Strong governance frameworks, clear accountability, and well-managed information environments are essential to ensuring organisations can respond effectively to both emerging threats and regulatory expectations.
Looking ahead
AI will continue to disrupt traditional cyber security approaches, reshaping how organisations defend their technology infrastructure. While the risks are real, so too is the opportunity to use AI as a force multiplier for security and resilience.
In an increasingly AI-enabled world, one principle remains constant: strong, well-implemented cyber security and information governance practices are more important than ever.
Read article on Australian Signals Directorate, "Frontier models and their impact on cyber security", published 9 April 2026