Artificial intelligence is no longer just another tool inside the security operations center. It is increasingly being used on both sides of the fight. Thales CEO Patrice Caine warned at a cybersecurity gathering that attackers are using AI to move faster and automate more sophisticated operations, while defenders need to invest just as aggressively in AI-assisted protection. Reuters described Caine’s message simply: security teams increasingly have to fight AI with AI.
The warning lands at a moment when cybersecurity is being reshaped by automation. AI can help attackers write convincing phishing messages, search for exposed services, analyze code, scale reconnaissance, generate malicious variations, and coordinate bot activity. At the same time, defenders can use AI to triage alerts, correlate telemetry, identify abnormal behavior, prioritize vulnerabilities, and react at machine speed.
AI-Enabled Bot Attacks Are Already Scaling
Thales’ own 2026 Bad Bot Report gives the warning a measurable backdrop. Based on 2025 traffic analyzed by the company, AI-enabled bot attacks increased 12.5× year over year. Thales says bots accounted for 53% of internet traffic in its dataset, bad bots alone represented 40%, and its systems blocked 17.2 trillion bad-bot requests during the year.
That does not mean every bot is malicious or that AI has suddenly replaced human attackers. It means automation changes the economics of attack. A threat actor can test more targets, generate more variations, and repeat an operation more cheaply. The same pressure already shows up in areas such as phishing and zero-day exploitation, where speed and scale can determine how much damage occurs before defenders respond.
The Defender Advantage Is Context
AI-powered defense is not simply a contest over who has the larger model. Defenders have an advantage attackers usually do not: internal context. They know which users should access which systems, what normal traffic looks like, where sensitive data lives, what software is approved, and which business processes are legitimate.
Google Cloud made the same argument in an October 1 security briefing, saying attacks that once took weeks can increasingly be compressed into hours or minutes and that defenders need automation capable of operating at similar speed. The practical goal is not to hand control of the network to an autonomous model. It is to let AI process huge volumes of telemetry while established controls—identity, authorization, segmentation, encryption, logging, human approval, and incident-response policy—define what actions are allowed.
That makes existing infrastructure more important, not less. firewalls and security processors, endpoint controls, identity systems, network telemetry, and cloud logs still provide the signals that automated defenders need to make useful decisions.
Thales and Google Cloud Are Securing AI Agents
The defensive side is also expanding beyond conventional malware detection. On September 28, Thales announced an expanded collaboration with Google Cloud to connect its AI Security Fabric with Gemini Enterprise. The companies say the integration is designed to add visibility, policy enforcement, and runtime protection around interactions among users, models, tools, enterprise data, and AI agents.
That matters because agentic systems can do more than answer a question. They can call APIs, move information, invoke tools, make decisions, and take actions across business systems. Thales lists prompt injection, sensitive-data leakage, unsafe outputs, unauthorized actions, and agent-to-agent interactions among the risks that need new controls. BitcoinVersus.Tech has already tracked the same shift from passive chatbots toward agents with broader permissions, including Google’s gated Gemini cybersecurity rollout.
In its announcement, Thales said the security layer is intended to keep agents inside authorized boundaries, restrict what data they can reach, and block inappropriate actions in real time. Google Cloud likewise says security has to span identity, network, endpoint, data, cloud, and application layers rather than treating the AI model as an isolated component.
AI Is Becoming a New Kind of Insider Risk
Thales’ broader 2026 Data Threat Report describes AI as a potential “new insider threat” because agents can be granted legitimate access to sensitive systems while still behaving in unintended ways. The company reports that 70% of respondents ranked the rapid pace of change in the AI ecosystem among their top three AI-security risks, while 61% said their AI applications were being targeted by attackers.
The data problem is especially important in the cloud. Thales says credential theft is increasing as an attack technique against cloud infrastructure and that only about half of sensitive cloud data is encrypted. As businesses connect more models and agents to multicloud infrastructure, every new permission and integration can become another path that must be monitored and constrained.
What “Fight AI With AI” Actually Means
The phrase sounds dramatic, but the operational idea is straightforward. AI can reduce the time between detection and response. A model can summarize thousands of alerts, correlate suspicious behavior across systems, rank likely attack paths, identify abnormal account activity, suggest containment steps, and help analysts investigate faster. The defensive value comes from combining that speed with trustworthy data and hard security boundaries.
- Use AI for triage, not blind authority. High-impact actions should still have defined approval paths.
- Keep identities and permissions narrow. An agent should receive only the access required for its task.
- Log agent activity. Security teams need a record of what an autonomous system accessed, requested, changed, or attempted.
- Protect the data layer. Encryption, tokenization, masking, and access controls matter more as AI systems can discover and combine information quickly.
- Assume attackers automate too. Detection and response processes designed for slow manual attacks will increasingly fall behind.
The Bottom Line
Thales’ message is less about replacing security professionals than changing their leverage. AI gives attackers more speed and scale, but it can give defenders the same advantages when paired with strong identity, visibility, data protection, and policy enforcement. The organizations that benefit most will probably be the ones that treat AI as another controlled security capability—not as an autonomous substitute for the controls they already need.
Primary reporting and technical background are available from Reuters, the Thales–Google Cloud announcement, the 2026 Thales Bad Bot Report, and Google Cloud’s security partner briefing.
BitcoinVersus.Tech
Advertisement: Explore more reporting and explainers in the BitcoinVersus.Tech Computer Security archive.
Editor’s Note
AI-assisted cybersecurity claims can blur together product marketing, threat research, and measured incident data. This story separates Thales’ observed traffic statistics from broader predictions about how autonomous attacks and defenses may evolve.
We volunteer daily to ensure the credibility of the information on this platform is Verifiably True. If you would like to support to help further secure the integrity of our research initiatives, please donate here: 3C9o19EH5HSiwEPyCTmEKzxhNCbo2X6TTb
BitcoinVersus.tech is not a financial advisor. This media platform reports on financial and technology subjects purely for informational purposes.

Leave a comment