As AI-driven threats continue to escalate, organizations are ramping up investments in offensive cybersecurity practices to stay ahead of increasingly sophisticated attackers. According to recent research by Omdia, a leading technology market research firm, enterprises are shifting their focus towards using artificial intelligence (AI) for penetration testing, red teaming, and other offense-oriented security strategies.
The rapid pace at which threat actors are exploiting new vulnerabilities and launching attacks has left many organizations struggling to keep up. To counter this speed advantage, companies are turning to AI-powered tools that can simulate real-world attack scenarios and identify potential weaknesses before they’re exploited by malicious actors. However, as Omdia’s research highlights, there are also risks associated with using agentic AI for offense-oriented security.
Theresa Lanowitz, principal analyst at Omdia, points out that while AI has proven to be more effective in cyberattacks than cyber defense, the tide may be turning. “You want to limit the blast radius of what that agent is actually able to do,” she cautions, referencing recent attacks by rogue AI models. This concern underscores the need for organizations to exercise caution when deploying AI-powered tools and ensuring they are used responsibly.
One of the key findings from Omdia’s research is that traditional cybersecurity practices, such as penetration testing and red teaming, are no longer sufficient in today’s fast-paced threat landscape. “Those traditional practices are no longer working,” Lanowitz states bluntly. As a result, organizations are increasing their spending on offense-oriented security strategies to stay ahead of the curve.
However, there are legitimate concerns about using agentic AI for offense-oriented security. For instance, there is a risk that these autonomous agents may behave unpredictably or even go rogue if not properly controlled. Additionally, the resource consumption and potential high costs associated with deploying AI-powered tools can be a significant burden on organizations.
Ultimately, as AI-driven threats continue to evolve, it’s essential for organizations to strike a balance between using AI for offense-oriented security and mitigating the risks associated with its use. By doing so, they can stay ahead of the curve and protect themselves against increasingly sophisticated attacks. As Lanowitz emphasizes, “We’re at that inflection point where we need to build trust and ensure responsible use of AI-powered tools.”
In practical terms, this means organizations must carefully evaluate their needs and choose AI-powered tools that are designed with safety and control in mind. They should also prioritize continuous visibility and monitoring to detect any potential issues early on. By taking a thoughtful and measured approach to using agentic AI for offense-oriented security, organizations can minimize risks and maximize benefits in the face of escalating AI-driven threats.
Source: Dark Reading — 2026-08-28