
Artificial Intelligence (AI) is undeniably weaponized now. But the human is still the adversary. AI changes the speed, scale, sophistication, and autonomy of cyberattacks, while in most AI-enabled attacks a human still defines the objective, determines the desired outcome, directs or delegates activity to the technology, and benefits from success.
AI has changed cybersecurity at extraordinary speed. Attackers now use AI as both a force multiplier and a capability multiplier. They can accelerate reconnaissance, generate and refine malware, build highly targeted phishing campaigns, impersonate executives, analyze enormous volumes of stolen data, discover relationships between data points, identify exploitable weaknesses, and increasingly execute sequences of actions through autonomous agents.
Yet those capabilities do not eliminate the human element. AI may execute the action. An agent may navigate the application. A model may create the campaign material. But behind most malicious AI activity, a human still defines the objective, decides what outcome matters, and benefits when the operation succeeds. Last I checked there wasn’t some AI technology cashing out some Bitcoin from a ransom and partying on a yacht.
Consequently, understanding The Adversarial Mindset matters more today than in the past.
Does AI Eliminate Human Intent From Cyberattacks?
No, AI does not eliminate human intent from cyberattacks. It can dramatically change how an attack is executed while a human adversary still defines the objective the technology is pursuing.
Too often, it feels like we talk about AI-powered attacks as though AI itself has suddenly become the adversary.
That framing can be misleading.
Consider the difference between traditional Generative AI (GenAI) and Agentic AI.
With traditional GenAI, the relationship remains relatively obvious. A human asks a model to do things such as identifying vulnerabilities, improving code, analyzing data, translating messages, performing research, or solving some other element of an operation.
The system provides the power. The human provides the objective.
Agentic AI creates more distance between those two elements.
Instead of asking AI to perform one task, a human can increasingly define an objective and allow an agent to determine how to accomplish it. The agent can browse websites, invoke tools, query data, make decisions, evaluate responses, select subsequent actions, and continue working toward a defined goal.
In other words, the human moves farther away from each individual action.
However, distance from execution does not automatically remove intent.
That distinction matters enormously for cybersecurity.
An attacker does not need to personally enumerate every endpoint, craft every request, write every line of malicious code, or send every social-engineering message to remain the adversary behind an operation.
AI gives that nefarious actor both abstraction and leverage.
Agentic AI gives that same human a certain level of delegation.
Neither automatically removes the human from the equation.
Who Is Acting When an AI Agent Accesses a Computer?
When an AI agent accesses a computer on a user’s behalf, the human user can remain the party performing the access. In the Ninth Circuit’s August 2026 Perplexity decision, the court treated the AI assistant as a tool and the human user as the party accessing Amazon’s systems for purposes of the federal Computer Fraud and Abuse Act (CFAA).
The dispute involved Perplexity’s Comet browser and its AI Assistant. Users could direct the Assistant to perform tasks on Amazon.com. Amazon argued that Perplexity’s technology accessed Amazon’s systems without authorization and sought relief under the CFAA, and its California counterpart (the Comprehensive Computer Data Access and Fraud Act – CDAFA).
The Ninth Circuit rejected Amazon’s theory at the preliminary-injunction stage.
More importantly, the court focused on a remarkably significant question:
Who actually accesses the computer?
On the record before it, the court concluded that the AI Assistant functioned as a tool. The court described the Assistant as a “tool, not a person for statutory purposes.” It then concluded that the user accessed Amazon’s computers while using the Assistant to carry out specific actions.
The decision marks the first federal appellate ruling addressing whether AI agents acting on behalf of users can legally access online platforms.
That distinction carries enormous significance beyond this particular dispute.
The court did not treat the AI agent as an independent legal actor simply because it could perform actions on behalf of a user. Instead, it looked through the technology to determine who actually performed the access for purposes of the statute.
At the same time, something important surfaced by way of a limitation.
The Ninth Circuit DID NOT create a sweeping legal doctrine that makes humans universally responsible for everything an AI system does. In fact, the opinion expressly states that it does not establish a new legal regime for agentic AI. The court limited its holding to the CFAA and CDAFA “access” issue, the technology at issue, and the factual record before it. Different facts, different levels of control, different laws, or different AI architectures could produce different outcomes.
Nevertheless, from a cybersecurity perspective, a much broader lesson remains powerful: technology can sit between a human and some action without rendering the human irrelevant (or innocent by default).
Should Security Programs Defend Against AI or the Adversary?
Security programs should defend against the adversary, not AI in isolation. AI mechanisms such as prompt injection, model poisoning, tool abuse, and MCP attacks matter, but they do not explain who wants to attack you, why they are targeting you, or how they will adapt.
The industry has become obsessed with AI security. Both RSAC and BlackHat this year showcased that obsession with great fanfare.
To answer the questions of who, why, and how, you need to understand the adversary, not just the technology at hand.
For example, imagine two attackers with access to exactly the same AI model and exactly the same agentic capabilities.
One is a teenager experimenting, testing boundaries.
The other operates inside an organized cybercriminal enterprise with millions of stolen identities, infostealer logs, credential collections, years of operational experience, and a clear understanding of how to monetize access.
The AI may be identical.
The threat is not.
The adversary behind the technology creates that difference.
Should Analysts and Frameworks Define a Security Program?
No, analysts and frameworks should not define a security program or its security strategy. They can inform both, but market intelligence about technologies, vendors, categories, and industry trends is not the same as understanding the adversary targeting your organization.
An industry analyst publishes some analysis. Vendors push categories. A maturity model emerges. Boards ask where the company sits relative to peers. CISOs then purchase technologies to fill perceived gaps. Eventually, the organization builds an architecture that looks remarkably similar to the architectures of dozens of other companies that consumed the same analyst research. And along the way end up with tons of tools whose true capabilities are not fully utilized.
To be clear, industry analysts provide value.
They can deliver market intelligence, technology comparisons, vendor analysis, spending benchmarks, maturity models, and useful observations about where the industry is heading.
However, organizations make a serious mistake when they use analyst research as the foundation of a security program.
Market intelligence is not adversary intelligence.
An analyst may understand the cybersecurity industry exceptionally well while possessing little firsthand understanding of the people trying to defeat your security program.
They may understand industry sectors, products, categories, vendors, differentiators and even what other CISOs are spending on.
Yet none of those things necessarily means they understand how a real adversary thinks.
More importantly, an adversary does not care whether your program aligns with an analyst’s reference architecture.
The adversary cares whether your defenses prevent the desired outcome.
Therefore, security leaders should never stop at this question:
What does the industry say a modern security program should contain?
They must also ask:
If I were a competent, cunning, determined attacker targeting this organization, how would I defeat what we have built?
What Blind Spot Do Many CISOs Have?
The blind spot many CISOs have is a limited understanding of the real adversaries their security programs are supposed to defeat. Managing risk, compliance, architecture, technology, and incident response is not the same as understanding how a determined adversary thinks, adapts, combines weaknesses, and pursues an objective.
I am not referring to understanding ethical hackers, penetration testers, or red-teamers. These professionals absolutely add value, but they ultimately operate within constraints established by rules of engagement.
I am talking about a real adversary with ill intent, whose motivations may be financial, ideological, geopolitical, personal, or simply opportunistic; and who feels no obligation to respect rules, scope, policy, business hours, budgets, architecture diagrams, or organizational boundaries.
That distinction matters.
A penetration tester typically asks whether something can be compromised within an agreed scope.
An adversary asks a very different question:
How do I achieve my objective despite everything this organization has done to stop me?
That question requires a fundamentally different way of thinking.
Why Should Defenders Start With the Human Behind the Machine?
Defenders should start with the human behind the machine because AI amplifies adversarial capability without automatically replacing adversarial intent. Less sophisticated attackers can now access capabilities that once required specialists, while sophisticated adversaries can operate faster, analyze more data, uncover hidden relationships, and adapt more efficiently.
As an example, consider that AI technologies create conditions in which enormous quantities of stolen identity data can be ingested and analyzed, revealing relationships humans would otherwise miss.
It can perform actions such as:
- transforming OSINT into targeted and strategic intelligence
- generating individualized social-engineering content based on attackable profiles across thousands of targets
- creating strategic campaigns rapidly
- refining malicious code
- analyzing defensive responses and adaptively creating alternatives
But it does so at the request of some human element. Consequently, we should stop thinking only in terms of “AI attacks.” What we increasingly face are human adversaries with machine-scale leverage.
That represents a much more consequential problem.
How Does The Adversarial Mindset Change Security Strategy?
The Adversarial Mindset changes security strategy by making the adversary, not the framework, product, analyst, or compliance requirement, the starting point. Security leaders first ask what an adversary wants, what that adversary already knows, which assumptions and relationships can be exploited, and how the attacker will adapt when defenses interfere.
Ask questions like:
- Who would want what we possess?
- What exactly would they want?
- What information about our people, systems, suppliers, executives, and customers do they already possibly have?
- Which assumptions are we making that they would immediately challenge?
- Where do identities, relationships, privileges, and trust create nefarious opportunities?
- How could they combine several individually minor weaknesses into one viable attack path?
- How would they adapt after encountering resistance to their techniques?
- How could AI make each of those steps of adaptability cheaper, faster, or more precise?
At that point, you begin designing security from the adversary backward.
That is the essence of The Adversarial Mindset.
Moreover, this approach does not require organizations to abandon frameworks, compliance obligations, analyst research, or established security architectures. Those tools still serve important purposes.
However, they should support your security strategy rather than define it.
The adversary should help define it.
Why Does AI Make The Adversarial Mindset More Important?
AI makes The Adversarial Mindset more important because it gives human adversaries greater speed, scale, precision, leverage, and increasingly autonomous execution. Security teams therefore need to understand not only what AI can do, but what a motivated adversary can now accomplish because those capabilities exist.
The cybersecurity industry will inevitably spend enormous amounts of time debating how autonomous AI will become.
That discussion absolutely matters.
Eventually, increasingly autonomous systems may force us to confront genuinely difficult questions about intent, accountability, responsibility, control, and attribution.
However, that conversation leaves gaps. Organizations cannot afford to wait for those philosophical and legal questions to reach resolution. This is especially so for larger organizations that are not exactly agile.
Today, humans are discovering what AI can do for them.
Some of those humans are defenders, others are researchers, and still others are innovators.
Realistically, some are adversaries.
The last group does not care whether your AI strategy appears in an analyst report. They do not care which security technologies occupy a leader quadrant, or how mature your program looks against some industry benchmark.
They care whether they can accomplish their objective.
The Ninth Circuit’s Perplexity decision gives us an important legal manifestation of a broader technological reality: an intelligent tool can become increasingly capable while still operating in service of human direction.
Therefore, defenders should resist the temptation to focus exclusively on the technology.
That distinction changes the questions security leaders should be asking.
“What can AI do?”
This has to start migrating towards something like:
“What can an adversary now do because AI exists?”
Those are very different questions.
Ultimately, the second question is the one our security programs need to answer. AI is undeniably weaponized now. The human is the adversary.
Note: This article discusses the cybersecurity implications of Amazon.com Services, LLC v. Perplexity AI, Inc. and does not provide legal advice. The Ninth Circuit’s August 4, 2026 decision concerned a preliminary injunction and a specific interpretation of “access” under the CFAA and CDAFA based on the record before the court.









