Artificial intelligence has compressed the window between cyberattack discovery and data theft to as little as 25 minutes, according to security professionals cited in a new report from InformationWeek. Fernando Maymi, vice president of professional services and training at cybersecurity firm Anomali, said the timeframe that once stretched across days, weeks, or months has now contracted to the point where it can be counted in minutes. The acceleration is forcing chief information officers and chief information security officers to overhaul how they identify and repair software weaknesses without causing major operational disruptions.
The traditional security operations center rhythm—where teams had breathing room between a patch release and its required installation because attackers needed time to figure out how to weaponize a flaw—has evaporated as AI helps threat actors move with unprecedented speed. Brian Wilson, chief information security officer at enterprise software company SAS, said the core worry isn't AI itself but rather the mismatch between machine velocity and the human pace of governance, patching, and internal compliance procedures. He's asking his executive team for flexibility because situations now demand rapid patching first and questions later, replacing the testing windows and gradual update rollouts that were standard practice. Wilson also noted a rise in updates and patches from third-party software vendors, while SAS itself is testing its own software more frequently for customers. AI's capacity to link together multiple low-severity vulnerabilities means security teams will need to treat minor risks as aggressively as critical ones, potentially ending the 30-60-90-day patch timeline that compliance agencies typically recommend for high-, medium-, and low-risk flaws.
Advanced AI models can now bundle several low-level vulnerabilities with medium-level ones to manufacture a critical exploit, explained Wally Dalrymple, chief information security officer at Educational Testing Service and PSI. Attackers historically targeted high-severity weaknesses first, but AI is reshaping the landscape by creating new exploits from lower-tier flaws. Atticus Tysen, senior vice president and CISO at Intuit, confirmed that sophisticated models are combining smaller vulnerabilities into larger problems, though he characterized this threat as early-stage. Peter Bailey, senior vice president and general manager at Cisco Security, predicted that threat actors will eventually share their AI-driven exploitation techniques the same way they now sell ready-made ransomware platforms. "We're expecting that the weaponization of frontier AI will also be productized in that way, so that every common criminal could be doing pretty advanced things," Bailey said.
Security leaders are deploying the same technology for defense, using AI tools to analyze, triage, and prioritize risks at accelerated speeds. Both Wilson's and Tysen's security operations centers rely on the technology to sort vulnerabilities, with Tysen's team using AI to examine tier 1 alerts and eliminate false positives so investigators can concentrate on genuine tier 2 and tier 3 issues. Tysen's team also scans for application misconfigurations and overly broad access permissions, and has built AI agents to help review AI-generated code. Dalrymple said enterprises can't wait for scheduled patch releases like Microsoft's Patch Tuesday anymore—they have to move as fast as AI and accelerate remediation because delays are no longer an option. Moving quickly carries its own hazards, including the risk of breaking an application if a patch is rushed, but Dalrymple said that simply means improving processes, testing, and quality control after deployment.
The shift to AI-driven offense and defense represents a fundamental change in the economics of enterprise security, one where the traditional risk calculus—balancing patch urgency against operational stability—no longer holds. Organizations that can't adapt their governance structures to support machine-speed decision-making may find themselves perpetually behind adversaries who face no such institutional constraints.

