Artificial intelligence is rapidly reshaping the cybersecurity landscape, giving defenders new capabilities while simultaneously arming cybercriminals with unprecedented levels of speed and automation. According to Meriam ElOuazzani, Vice President for Middle East, Turkey, and Africa at Censys, organizations are entering an era where traditional security approaches are struggling to keep pace with AI-powered adversaries capable of operating at machine speed.
Cybersecurity has always been a race against time. What’s new is the scale that speed now operates at. Frontier AI models and agentic tools can now autonomously monitor infrastructure, probe services, test for vulnerabilities, and launch full attack campaigns, without any human hands on the keyboard. 96% of senior security leaders worldwide already consider AI-enabled cyberattacks as posing a serious threat to their organizations. Attackers and defenders have always been at odds, but today’s attacker isn’t just fast, it can run as a thousand parallel versions of itself, working smarter and faster than any single adversary before it.
For the UAE, this shift arrives at a particularly charged moment. The country is now fending off around 600,000 cyberattacks per day, three times the volume recorded before recent regional tensions, with state-linked actors increasingly leveraging AI tools to execute more layered, coordinated campaigns. At the same time, the speed of digital transformation across the Emirates through rapid AI adoption, smart city integration and significant cloud migration has created a rapidly expanding attack surface, complicated by a “digital debt” problem, with nearly 50% of exploited vulnerabilities in the country being more than five years old.
The combination of a wider attack surface, older unpatched vulnerabilities and adversaries equipped with AI automation is precisely the environment where traditional reactive security postures fall short.
The risk hiding in plain sight
Most organizations have a reasonable grasp of their approved, visible infrastructure. What they tend to underestimate is the sprawl that exists around it. Subsidiaries, contractor-managed systems, forgotten test environments, AI tools spun up by data science teams, GPU instances provisioned for a week and left running are some that don’t show up neatly in a CMDB or a cloud console. But they are reachable and that is all attackers need.
Most organizations realistically cannot remediate them all and it no longer takes expert talent to be an attacker, just an AI model and a willingness to probe at scale as highlighted in the Fortinet FortiGuard Labs. It reported 36,000 scans per second, a 16.7% year-over-year increase in 2025, showing how automated probing is happening at machine speed rather than requiring expert-only effort.
“Cybersecurity has always been a race against time. What’s new is the scale that speed now operates at. Today’s attacker isn’t just fast, it can run as a thousand parallel versions of itself, working smarter and faster than any single adversary before it.”
Meriam ElOuazzani, Vice President for Middle East, Turkey, and Africa, Censys
When vulnerability discovery is this automated, the organizations that will feel the impact first are those that don’t know what they’re exposing.
This is why exposure management, involving the continuous practice of finding, validating, and prioritizing internet-facing risk has moved from a security best practice to an operational necessity.
Shadow AI: same risk, new disguise
Organizations are grappling with the rapid adoption of AI tools and the associated risk of employees sharing sensitive data with public chatbots, which has been termed “shadow AI.” According to a survey conducted by Red Hat, 70% of UAE organizations are experiencing a “shadow AI” problem.
This is the exposure problem in miniature. A data scientist provisions a tool that allows the sharing of live code, visualizations, mathematical equations, and descriptive text to test a model. An engineer stands up a local LLM interface for a demo. A product team spins up an AI workflow on a non-standard port. Each of these may be legitimate in isolation. None of them may be monitored, approved, or visible to the security team. And all of them are potentially reachable from the internet.
The more important question security teams need to be asking is whether those tools are being operated in a way that creates unmonitored exposure. Detecting this requires visibility beyond standard ports and known services, into the full public-facing footprint of an organization.
Live threats need live intelligence
One of the more durable lessons of the AI-enabled threat era is that static defenses age badly. An IP blocklist, a known-bad domain feed, a one-time vulnerability scan are useful but insufficient when adversaries can rotate infrastructure, mutate campaigns and redeploy at machine speed.
The share of security leaders expecting agentic AI to run core functions like threat detection is set to roughly double within two years according to EY’s study released in March 2026. If attackers are using automation to move faster, defenders need equally dynamic intelligence, but continuously updated context about what is exposed and what adversarial infrastructure looks like right now.
Organizations that are most suited to adapt to this kind of situation are those that consider security not as an intermittent activity but treating it as a continuous operational function. That means live visibility into what they expose, the ability to act quickly when a new vulnerability is disclosed and intelligence about attacker infrastructure that updates as fast as the threat does.
Regional stakes remain high. The Middle East, primarily the UAE and Saudi Arabia, consistently ranks second globally for average breach costs, with the latest IBM findings putting the figure at $7.29 million per incident. That cost pressure alone makes the case for shifting from reactive patching cycles to continuous, live visibility into what an organization is exposing at any given moment.
The UAE has built real cyber resilience. Despite sustained exposure to phishing links and other malicious campaigns across 2025, malware execution rates in the UAE fell progressively over the year, indicating that local defenses are maturing and more attacks are being blocked earlier in the kill chain. The next challenge is ensuring that resilience extends to the parts of the attack surface organizations don’t yet know they have.
