The global and independent platform for the SAP community.

When AI Becomes a Cyber Capability

In June 2026, U.S. export controls on powerful Frontier models such as „Fable“ and „Mythos“ made clear what many companies had previously underestimated: Leading AI capabilities for cyberattacks and cyberdefense are no longer a freely available resource.
David Urlhart, MHP
Benedikt Bauer, MHP
September 18, 2026
avatar
avatar

AI models are evolving so rapidly that they themselves are becoming an operational security factor. The Federal Office for Information Security (BSI) points out that AI is fundamentally changing the cybersecurity landscape. While AI enables attackers to analyze, automate, and scale more quickly, defenders remain constrained by real-world operational limitations—such as testing efforts, approval processes, maintenance windows, vendor dependencies, and limited personnel capacity.

More Than Just an AI Model

AI is no longer just a tool that supports security professionals. It is increasingly evolving into a standalone cyber capability. In this context, “cyber capability” does not refer to a single model or application. Rather, it refers to the interplay of agent-based capabilities: identifying vulnerabilities, analyzing code, deriving exploit logic, validating attack vectors, operating tools, and scaling these activities across large system landscapes. It is precisely this combination that is fundamentally changing the dynamics of the digital security landscape.

Many companies are not yet prepared for this development. While executive boards continue to discuss AI pilot projects, proofs of concept, and isolated efficiency gains, the foundation of digital defense capabilities is already shifting. AI no longer merely supports existing security processes; it is becoming an operational factor in cyber operations.

AI capabilities are growing

What matters here is not the individual model, but the combination of multiple capabilities that reinforce one another. AI systems are increasingly able to integrate technical tasks into coherent workflows: from analysis and validation to scalable application across complex IT landscapes. This changes the pace, scope, and repeatability of both attacks and defenses.

This significantly shortens the time window between when a vulnerability is discovered and when it can be exploited. Weeks become days; days become hours. For companies, the question is no longer simply, „Are we secure?“ Rather, the crucial question is, „Can we respond quickly enough when AI dictates the speed of the attack?“

This development is fundamentally changing the logic of cybersecurity. In the past, the focus was often on introducing better tools, hiring more experts, and optimizing existing processes. Today, this approach is no longer sufficient. When attacks and defenses are prepared, prioritized, and partially automated at machine speed, traditional planning and decision-making cycles can become a structural disadvantage.

Those who continue to rely on manual review, sequential ticket prioritization, and long escalation chains lose time precisely where speed becomes a critical security resource.

New Strategic Interdependencies

Added to this is a new form of strategic dependency. Those who base their defense capabilities on just a few models or providers tie their own defense to factors beyond their control: access to models, terms of use, geopolitical decisions, export controls, and provider strategies. If access to key models is restricted, the ability to analyze vulnerabilities, simulate attacks, or quickly assess incidents is immediately diminished. This risk cannot be offset by higher security budgets alone.

The past few weeks have shown that this development is no longer a distant prospect. Vendors are specifically releasing cyber-enabled Frontier models, such as GPT-5.5-Cyber, for verified security professionals. With MDASH, Microsoft is introducing a solution in which multiple specialized AI agents work together to automatically find and validate vulnerabilities across large codebases and demonstrate their exploitability. At the same time, governments are responding to these new cyber-relevant AI capabilities with export controls. The key point is this: The ability to deploy powerful frontier models in a targeted manner and integrate them with existing security processes is itself becoming a critical cyber capability. As a result, dependence on model access, vendor strategies, and regulatory frameworks is becoming a strategic risk factor for companies.

This is precisely where the real management challenge lies. In the age of agent-based AI, cybersecurity is becoming not only more technical but also more strategic. It’s not about indiscriminately implementing AI everywhere. Companies must build their defensive capabilities in such a way that they remain capable of acting even amid new dependencies, faster speeds, and increasing volumes of findings.

Three Fundamental Changes

Three fundamental changes are needed:

First, security must not depend on a single model—companies need model-agnostic security architectures, multi-vendor strategies, and clear fallback options. If a company loses access to a leading model tomorrow, it must not simultaneously lose the ability to analyze vulnerabilities, simulate attacks, or assess incidents.

Resilience does not come from the best single model, but from a resilient ecosystem. It is crucial that companies be able to combine different models, providers, and security tools in such a way that core defense processes remain operational even when the availability of individual AI capabilities is limited.

Second, response processes must be designed to keep up with the speed of AI: Many security organizations today are still designed for the processing speed of humans. That won’t be enough. Companies must understand where their response processes are too slow, which decisions can be prepared automatically, and where human approval remains absolutely necessary.

Agent-based cyber capabilities continue to evolve.

An AI Response Readiness Assessment can highlight precisely these gaps. It reveals where manual handoffs, unclear responsibilities, fragmented information, or lengthy approval processes slow down response capabilities. A response automation roadmap then translates these insights into concrete actions—ranging from automated finding aggregation and risk-based prioritization to prepared decision templates for critical security incidents.

Third, companies must understand their exposure across the entire ecosystem—the relevant attack surface does not end at their own corporate boundaries. Often, suppliers, third-party components, cloud services, legacy systems, and external interfaces are the actual vulnerabilities in the system. When AI agents identify these interconnections faster than the organization itself, a dangerous imbalance arises.

An Enterprise Exposure Map and an AI Security Governance Framework provide transparency, prioritization, and manageability in this area. They help companies understand which systems, dependencies, and interfaces are particularly critical, how AI can be used in security processes, and what governance is necessary to manage risks across the entire digital ecosystem.

More than just another tool

The good news is: Artificial intelligence can shift the balance in favor of defense—but only for companies that lay the groundwork now. Those who view AI merely as another tool in the security stack are missing the mark. What matters is not the introduction of individual features, but the transformation of defensive capabilities: moving away from manual response toward intelligent prioritization, automated preparedness, and strategic resilience against dependencies on specific models and vendors. This isn’t about knee-jerk reactions, but about the ability to act. Companies must now understand which models and providers their defenses depend on, where their response processes are too slow, and where they lack transparency regarding their own exposure.

Those who address these questions early on will be able to view agent-based artificial intelligence not merely as a risk, but to leverage it strategically to strengthen their own defensive capabilities. The central challenge in the coming years will therefore not be merely whether companies deploy AI in cybersecurity. What will be crucial is whether they structure their defenses in a way that allows them to cope with the speed, scale, and interdependence of an AI-driven cyber reality.

To the partner entry:

avatar
David Urlhart, MHP

Cybersecurity Manager


avatar
Benedikt Bauer, MHP

Senior Cyber Security Consultant


Write a comment

Working on the SAP basis is crucial for successful S/4 conversion. 

This gives the Competence Center strategic importance for existing SAP customers. Regardless of the S/4 Hana operating model, topics such as Automation, Monitoring, Security, Application Lifecycle Management and Data Management the basis for S/4 operations.

For the fourth time, E3 magazine is organizing a summit for the SAP community in Salzburg to provide comprehensive information on all aspects of S/4 Hana groundwork.

Venue

FourSide Hotel Salzburg,
Trademark Collection by Wyndham
Am Messezentrum 2, 5020 Salzburg, Austria
+43-662-4355460

Event date

Wednesday, June 10, and
Thursday, June 11, 2026

AI experience workshop only on June 11, 2026 (limited places)
Bonus: Access to all lectures on June 11, 2026

Regular ticket

Lectures, evening event and, depending on availability, the AI workshop on June 11, 2026
Places at the AI experience workshop are limited and registration is required.

Subscribers to the E3 Magazine Ticket

reduced with promocode CCAbo26

Students*

reduced with promocode CCStud26.
Please send proof of studies by e-mail to office@b4bmedia.net.
*The first 10 tickets are free of charge for students. Try your luck! 🍀
EUR 305 excl. VAT.
EUR 590 excl. VAT
EUR 390 excl. VAT
EUR 290 excl. VAT

Venue

Hotel Hilton Heidelberg
Kurfürstenanlage 1
D-69115 Heidelberg

Event date

Wednesday, April 22 and
Thursday, April 23, 2026

Tickets

AI onlyExperience workshop on April 23, 2026 
Bonus: Access to all lectures on April 23, 2026
Regular ticket
April 22, 2026: Lectures and evening event
April 23, 2026: Lectures and AI workshop
EUR 305 excl. VAT
EUR 590 excl. VAT
Subscribers to the E3 magazine
reduced with promocode STAbo26
EUR 390 excl. VAT
Students*
reduced with promocode STStud26.
Please send proof of studies by e-mail to office@b4bmedia.net.
EUR 290 excl. VAT
*The first 10 tickets are free of charge for students. Try your luck! 🍀
The event is organized by the E3 magazine of the publishing house B4Bmedia.net AG. The presentations will be accompanied by an exhibition of selected SAP partners. The ticket price includes attendance at all presentations of the Steampunk and BTP Summit 2026, a visit to the exhibition area, participation in the evening event and catering during the official program. The lecture program and the list of exhibitors and sponsors (SAP partners) will be published on this website in due course.