Mayank Upadhyay, chief security and trust officer at Snowflake, told industry reporters that the rapid adoption of artificial intelligence is giving cyber-criminals a new accelerator. The result is a wave of attacks that can discover and exploit software flaws in hours rather than weeks, leaving many companies unprepared.
AI-driven threats accelerate
Enterprises that once followed a predictable patch schedule, weekly, monthly or quarterly, now face an attack surface that generates massive volumes of data from networks, laptops, cloud services and user logins. According to Upadhyay, human analysts cannot triage this flood without assistance from AI, and attackers are already using the same technology to scan codebases, generate exploits and, in some cases, deploy them automatically.
"Everybody needs to be on a war footing right now," Upadhyay said.
The speed of AI-enabled vulnerability discovery means that threats can be weaponised within hours, outpacing the traditional batch-style approach to software updates. Companies that continue to rely on manual patching risk exposing critical systems to exploits before a fix can be applied.
Defensive AI tools
Industry leaders argue the answer is to fight AI with AI. Anthropic has released a model called Mythos, currently available to a limited set of partners. Steve Schmidt, chief security officer at Amazon, said the model helps not only to patch individual bugs but also to close entire classes of weaknesses.
"Everything we've seen has shown that we are far more effective using AI as defenders than adversaries are using it for attacks," Schmidt explained.
Schmidt warned, however, that the technology must be paired with experienced engineers. When left to operate alone, even advanced AI can generate a high volume of false alarms, causing developers to lose confidence in the alerts.
Rising workforce risk
The economics of attacks are also shifting. Hugh Thompson, executive chairman of the RSA Conference, noted that AI lowers the cost and skill barrier for customised attacks, making even small and midsize firms attractive targets.
Beyond technical exploits, AI is amplifying social engineering. Phishing emails can now mimic a colleague's writing style, and deep-fake audio or video calls can impersonate senior executives. In a recent high-profile case, criminals used an AI-generated video of a finance chief to persuade an employee to transfer around $25 million.
Research from Charlemagne Labs, an AI-security startup, shows that publicly available models can sustain believable multi-turn conversations, a capability that could enable fully automated scams within a year. Jeremy Philip Galen, former Meta product manager and CEO of Charlemagne Labs, warned that social engineering remains the genesis for most attacks and has received too little attention.
"You can't really train people, and that's scary. You can't teach people to identify threats, which means we're entering a new era of workforce risk," Galen said.
Charlemagne Labs is developing a system called Charley that monitors incoming messages and warns users of likely scams, acting as an always-on filter.
Preparing for an AI-fast response
Upadhyay says Snowflake's security teams now run daily "war room" exercises that bring together application security, cloud infrastructure, IT and security-operations staff. The goal is to break down silos and react at "AI speed" by using the same AI-powered tools that attackers employ.
He outlines a four-step cycle powered by AI: set up defenses, monitor for breaches, contain and remediate any incidents, and build new controls to prevent recurrence. Automating this entire lifecycle, he argues, is essential for any organisation that wants to stay ahead of AI-driven threats.
For European businesses, the message is clear: the same technology that promises efficiency and insight also creates a new frontier of risk. Companies must adopt AI-enhanced security, invest in continuous training, and integrate defensive tools into every layer of their operations if they are to survive the coming wave of AI-accelerated cyberattacks.

