# Offensive Security Investments Surge as AI Threats Increase
Enterprise security budgets are shifting toward offensive capabilities as organisations grapple with agentic AI systems emerging as new attack vectors. Omdia analyst Theresa Lanowitz highlighted this trend during recent conversations with Dark Reading, pointing to a fundamental rebalancing in how companies allocate cybersecurity resources.
The pivot reflects a hard reality: traditional defensive postures cannot keep pace with the speed and sophistication of AI-driven threats. Organisations now invest heavily in penetration testing, red teaming, and adversarial simulation tools that leverage agentic AI to stress-test their own defences before attackers do.
Agentic AI differs from conventional large language models. These systems operate autonomously, making decisions and taking actions without human intervention between prompts. In the hands of security researchers, they can automate multi-step attack chains, adapt to defensive measures in real time, and discover vulnerabilities faster than human testers. Red teams deploy these tools to simulate sophisticated adversary behavior. The goal remains legitimate: identify weaknesses before criminals exploit them.
The benefits are concrete. Agentic AI can compress penetration testing cycles from weeks to days. It can run continuous vulnerability discovery, learning from each scan to target increasingly obscure weaknesses. Companies using these tools internally report catching critical flaws that conventional scanners miss. Banks, cloud providers, and financial services firms lead this investment wave.
But the same capabilities create serious risks. Agentic AI tools designed for legitimate red teaming could be repurposed or stolen for actual attacks. A malicious actor who obtains a trained model used internally by a Fortune 500 company inherits months of real-world attack intelligence against that specific target. The knowledge encoded in the model becomes a precise blueprint for exploitation.
Supply chain compromise poses another threat. If the vendors selling agentic AI red-teaming platforms suffer breaches or become compromised, their customers inherit that compromise. A bad update or infected model distribution could arm attackers with tools calibrated against thousands of enterprise defences simultaneously.
Lanowitz noted that organisations must balance aggressive testing with operational security discipline. Using agentic AI requires strict controls: air-gapped environments, careful access controls, and transparency about what the system knows about your infrastructure. Many teams still treat these tools like conventional penetration testing frameworks, which underestimates the risk of autonomous systems learning and retaining sensitive information.
The talent gap compounds the problem. Few security teams understand how to safely operate agentic AI systems. Fewer still know how to defend against them. This asymmetry drives investment but also creates uneven security postures across sectors.
Regulators have begun paying attention. Financial services regulators in multiple jurisdictions now include autonomous testing in their examination playbooks, but they lack clear guidance on acceptable thresholds for agentic AI use. Organisations walk a narrow line between demonstrating adequate security controls and introducing new attack surface through the tools themselves.
The market consequence is predictable: security budgets grow, but efficiency gains remain unproven. Companies spend more because they must match the pace of AI-driven threats. Whether agentic AI red teaming actually reduces breach risk remains an open question. Early adopters see value. Mass adoption could reveal problems now hidden in small-scale deployments.
