TL;DR: AI is compressing the time between exposure and exploitation, and the ECB has told major European institutions to submit action plans for AI-enabled cyber threats by October 31, according to Horizons.ai. The real shift is that security is becoming an evidence problem, not a visibility problem, because defenders now need proof of exploitability and remediation impact before attackers move.
NHIMG editorial — based on content published by Horizons.ai: Cybersecurity Needs a New Operating Model
Questions worth separating out
Q: How should security teams respond when AI compresses the window between exposure and compromise?
A: Teams should move from periodic review to continuous containment.
Q: Why do AI-driven attacks change the way organisations plan cyber resilience?
A: AI-assisted attackers compress the time between exposure and exploitation, so organisations have less time to detect and contain incidents before recovery begins.
Q: What do organisations get wrong about AI-driven cyber risk?
A: They often assume the main change is autonomous attackers, when the immediate change is faster and more variable abuse of existing identity pathways.
Practitioner guidance
- Adopt continuous exploitability validation Test whether critical weaknesses are actually reachable in your environment, then confirm remediation by retesting after each change.
- Tie identity controls to proof of current risk Require evidence that privileged access, service accounts, and API credentials are still necessary and not merely documented.
- Shorten the credential exposure window Reduce the time secrets, tokens, and certificates remain usable by enforcing rotation and revocation based on actual exposure, especially where automation or AI-driven attack paths can move faster than human review.
What's in the full article
Horizons.ai's full blog covers the operational detail this post intentionally leaves for the source:
- The ECB supervisory letter language and the exact six priorities it set for significant institutions.
- Horizon3.ai's evidence-based operating model for validating exploitability, context, verification, and continuous operation.
- NodeZero implementation framing for teams that need to operationalise continuous security evidence.
- The article's discussion of why this regulatory shift may extend beyond European banking.
👉 Read Horizons.ai's analysis of AI-driven cyber resilience and the ECB letter →
AI-driven cyber resilience: are existing security models keeping up?
Explore further
AI has turned cyber resilience into an evidence discipline. The article is right to frame the problem as a collapse in decision time, not simply a rise in adversary capability. Security teams can no longer rely on the assumption that they will have enough time to detect, assess, and respond in sequence. For identity and NHI governance, that means access and privilege controls must prove current safety, not historical compliance. The practitioner conclusion is clear: measure what can be abused now, not what was once approved.
A question worth separating out:
Q: Who is accountable when AI-enabled attacks bypass legacy access controls?
A: Accountability sits across IAM, security operations, and application owners because the failure spans authentication, telemetry, and abuse response. Frameworks such as the NIST Cybersecurity Framework 2.0 and Zero Trust architecture expect shared ownership of identity assurance, detection, and containment.
👉 Read our full editorial: AI is forcing a new cyber resilience operating model