
Meet the Authors
AI cyber risk is changing the calculation around vulnerabilities businesses may previously have been willing to accept.
ERP migrations, cloud programs, and AI deployments are expanding exposure while security teams face patching backlogs and tighter resources.
Faster AI-enabled threats may require enterprises to revisit access, monitoring, remediation, and investment decisions made under an earlier risk environment.
Warnings about frontier AI cyber risk became concrete in April. US financial regulators convened bank leaders over Anthropic’s Claude Mythos Preview. Anthropic said the model could identify and exploit vulnerabilities at unprecedented speed and scale. OpenAI CEO Sam Altman dismissed some of the concern around Mythos as “fear-based marketing.”
June brought government and intelligence warnings. Then came Hugging Face.
In July, OpenAI disclosed that agents used in cybersecurity testing had broken out of an isolated environment and compromised Hugging Face systems.
The scale of what had happened became clearer on August 26. OpenAI said the agents had worked around isolation controls, coordinated with one another, chained vulnerabilities across systems, and reached parts of its own research infrastructure.
It called the incident a “warning shot.”
Days later, more than 150 organizations, including Google, Microsoft, OpenAI, Oracle, and SAP, warned that businesses had a limited window to strengthen cyber defenses before AI-enabled attacks became more widespread and sophisticated.
And the warnings have not stopped there. Former frontier-model researchers are describing existential risk. Policymakers are debating whether AI development needs to slow. Technology companies, meanwhile, are arguing over whether tighter rules would make AI safer or simply make it harder for smaller competitors to survive.
That is a lot to absorb in five months. And as warnings accumulate, each new one becomes harder to separate from the noise. It’s created a new kind of cybersecurity challenge.
What We Know About the Threat Is Material
There is still plenty of uncertainty around frontier AI. But direction is not one of them.
While timing and severity remain open questions, more capable AI will make offensive cyber operations faster, cheaper, and more accessible for threat actors.
Cybersecurity specialists interviewed by SAPinsider were unanimous on the mechanism.
AI reduces how much specialist knowledge and human intervention an attack requires. Agents can find weaknesses, test routes into a system, and adjust when something fails, all without waiting for a person at each step.
Familiar attacks become easier to scale and harder to outrun.
Security vendor warnings have accumulated over the past year. Research, threat alerts, and incident reports increasingly describe the same environment: attackers are moving faster against weaknesses businesses already struggle to fix. More consequentially, it changes the equation for vulnerabilities the business may have been prepared to accept.
Now, cybersecurity teams need to reopen conversations about past decisions.
They need to persuade executives to reallocate time, money, and people toward practical defensive measures in the coming months, at a time when many businesses are already committed to large-scale modernization programs with AI at the center.
ERP migrations leave companies defending old and new environments. Cloud programs spread security across more providers and integration points. AI deployments give machine identities access to processes that carry out core business activity.
Many of those decisions predate the current acceleration in AI-enabled cyber capability. The investment case may still stand, but the security calculation deserves another look.
The Hard Part Is Reopening the Business Plan
Security teams are not entering this period with spare capacity.
SAP is releasing more patches than ever. Deciding what to fix first now requires a broader mix of expertise, from integrations and technical identities to trust relationships and the business processes behind them.
Meanwhile, SAPinsider has found that keeping up with security notes, patches, and updates remains a leading obstacle, with limited resources contributing to patching backlogs. A quarter of respondents said economic conditions were forcing them to scale back planned security investments, while almost as many reported staff reductions.
The organizational challenge is broader still. Security teams do not always have the visibility, ownership, and communication channels they need across the enterprise. And even if leadership sees the risk as credible, they may still lack a clear mechanism for deciding what needs to change and what should give way.
Budgets are committed. Migration dates are set. AI programs already have sponsors and expected returns. Cyber warnings are arriving after those choices have been made, asking leadership to revisit them before the cost of waiting can be measured with much precision.
Cyber teams need to show where the changing threat alters a decision the company owns. In one case, that might be the amount of access given to an AI agent. In another, the level of monitoring around a critical process, or the resources assigned to remediation. The case will vary. The question is whether the new risk justifies a different choice.
There will be more warnings. There will also be more evidence, more incidents, and more disagreement over how quickly the threat is moving.
Cyber teams need to help their organizations become decision ready. Leadership can still choose to stay the course. But it should do so with the new risk accounted for.
What This Means for SAPinsiders
- Decision latency becomes security exposure. If attack capability accelerates faster than executive decisions, organizational delay becomes part of the risk itself. Companies may need to measure how quickly material cyber evidence reaches an owner, a trade-off, and a funded response.
- Cyber risk is becoming a capital-allocation question. Faster-changing threats can alter the expected downside of investments after approval. Leadership may therefore need explicit thresholds for when security evidence is strong enough to reopen spending and resource decisions.
- Modernization programs need security off-ramps. Reassessment becomes harder once budgets, timelines, and sponsors are committed. Pre-agreed checkpoints could let new threat evidence change access, sequencing, controls, or go-live decisions without treating every adjustment as a program failure.




