TL;DR: AI security is shifting faster than defenders can absorb it, with mean time-to-exploitation falling from 2.3 years in 2018 to 1.6 days in 2026 and open-weight models lagging frontier systems by four to seven months on cyber tasks, according to AccuKnox and Irregular’s analysis. The buying test is no longer whether a control finds issues, but whether it helps defenders more than it helps attackers with the same output.
NHIMG editorial — based on content published by AccuKnox: The End-State Fallacy and How to Buy AI Security – Evaluation Guide
By the numbers:
- Mean time from disclosure to exploitation fell from 2.3 years in 2018 to 1.6 days in 2026.
Questions worth separating out
Q: What breaks when AI tools create more AppSec findings than teams can triage?
A: Teams lose the ability to separate exploitable issues from harmless noise, so remediation slows and real risk can sit in the queue behind lower-value alerts.
Q: Why do AI agents increase non-human identity risk?
A: AI agents increase non-human identity risk because they can execute many actions quickly once they inherit a credential or tool permission.
Q: How do organisations know whether controls for AI-generated code are actually reducing risk?
A: They should look for fewer vulnerable patterns reaching the repository, blocked attempts to introduce unsafe configuration, and a lower volume of remediation work in review and production.
Practitioner guidance
- Score controls for defensive asymmetry Rank AI security capabilities by whether they improve defender containment more than attacker reconnaissance, exploitation, or reuse of the same output.
- Map every AI system to an identity boundary Inventory models, agents, datasets, tool connections, and secrets as governed identities and dependencies.
- Separate detection from containment in design reviews Require each AI control to answer two questions: what it finds and what it can stop.
What's in the full article
AccuKnox's full article covers the operational detail this post intentionally leaves for the source:
- Side-by-side evaluation logic for finding versus containment controls in AI security
- The DDCA framework applied to real purchasing decisions and control selection
- AccuKnox's mapping of AI-SPM, red teaming, and runtime containment to the transition problem
- The detailed reasoning behind per-tool-call scoping and kernel-enforced refusal paths
👉 Read AccuKnox's evaluation guide on buying AI security for the transition period →
AI security buying under the end-state fallacy: are controls keeping up?
Explore further
AI security buying is now a red-versus-blue allocation problem. Controls that only help a defender after a problem is found do not change the attacker’s economics fast enough. The useful question is whether the same output gives the attacker equal value, or whether it meaningfully improves containment for the defender. That is where differential defensive acceleration becomes a practical lens for procurement and architecture decisions.
A question worth separating out:
Q: Should organisations prioritise containment or discovery in AI security?
A: Containment should come first when AI systems can reach sensitive tools, secrets, or production actions. Discovery is still necessary, but it is not enough when exploitation can happen in hours or days. The right sequence is visibility, then runtime enforcement, then deeper optimisation.
👉 Read our full editorial: AI security buying is being reshaped by the end-state fallacy