TL;DR: AI-enabled intrusions are now compressing reconnaissance, credential harvesting, and exfiltration into machine-paced operations, while generative AI has driven phishing volume up 1,265% according to Sentire’s analysis. The operating lesson is that security programmes must collapse offense, defense, and governance into one controlled loop before attackers do.
NHIMG editorial — based on content published by Sentire: AI Attacks Now Move With Little Human Involvement. Controlled Autonomy Is How Defense Moves Just As Fast
Questions worth separating out
Q: What breaks when identity review is still manual in environments with many machine identities?
A: Manual review breaks when the number of service accounts, APIs, and AI-driven identities grows faster than the team can verify ownership, purpose, and necessity.
Q: Why do AI-driven attacks increase the risk from valid credentials?
A: AI-driven attacks increase risk because valid credentials bypass many perimeter controls and let the attacker operate like an authorised user.
Q: How should security teams measure whether autonomous defense is working?
A: They should measure time-to-engage signal, containment success, and reversibility.
Practitioner guidance
- Map identity containment to machine-speed workflows Define which identity actions can be executed automatically, such as session revocation, token invalidation, or temporary account disablement, and require explicit policy for each.
- Instrument time-to-engage signal Track the interval from first suspicious identity event to enforced containment, not just detection and alerting.
- Reduce standing access that AI can abuse Review privileged accounts, service identities, and delegated access paths for unnecessary breadth, especially where automation or third-party integrations can reach sensitive systems.
What's in the full article
Sentire's full blog covers the operational detail this post intentionally leaves for the source:
- The article’s discussion of AI-operated offense and defense loops across detection, containment, and remediation.
- The specific examples used to show how fast AI-assisted attacks can move from signal to action.
- The company’s framing of controlled autonomy as an operating model for SOC and response teams.
- The broader commentary on how human accountability is preserved while automation accelerates response.
👉 Read Sentire’s analysis of AI attacks moving with little human involvement →
AI attacks moving with little human involvement: what teams must change?
Explore further
AI-driven intrusion compresses the governance window that identity teams rely on. When a campaign can move from access to exfiltration in minutes, the assumptions behind manual review, change approval, and after-the-fact ticketing stop holding. The practical consequence is that identity governance must account for automated decision speed, not just who owns the account or token. That shifts the control objective from periodic oversight to runtime containment.
A question worth separating out:
Q: Why do identity and SOC teams need to coordinate on AI-driven attacks?
A: AI-driven attacks often start with identity abuse, move through lateral access, and end in rapid execution, so the SOC cannot contain them alone. Identity teams control revocation, session termination, and privilege changes, while the SOC controls detection and orchestration. Shared playbooks are essential because speed determines whether containment happens in time.
👉 Read our full editorial: AI attacks now move faster than human defense workflows