* [![perspectives](https://www.paloaltonetworks.com/perspectives/wp-content/uploads/2025/02/prespective-icon.png)](https://www.paloaltonetworks.com/perspectives)
* Fighting Back Against Cyberattackers: How to Counter AI with AI

English

* [English](https://www.paloaltonetworks.com/perspectives/how-to-counter-ai-with-ai)
* [Français (French)](https://www.paloaltonetworks.fr/perspectives/how-to-counter-ai-with-ai/)
* [日本語 (Japanese)](https://www.paloaltonetworks.jp/perspectives/how-to-counter-ai-with-ai/)
* [简体中文 (Chinese -Simplified)](https://www.paloaltonetworks.cn/perspectives/how-to-counter-ai-with-ai/)
* [繁體中文 (Chinese -Traditional)](https://www.paloaltonetworks.tw/perspectives/how-to-counter-ai-with-ai/)
* [Deutsch (German)](https://www.paloaltonetworks.de/perspectives/how-to-counter-ai-with-ai/)
* [한국어 (Korean)](https://www.paloaltonetworks.co.kr/perspectives/how-to-counter-ai-with-ai/)

# Fighting Back Against Cyberattackers: How to Counter AI with AI

![Fighting Back Against Cyberattackers: How to Counter AI with AI](https://www.paloaltonetworks.com/perspectives/wp-content/uploads/2024/09/how-to-counter-ai-with-ai.jpg)  
**By [Sam Rubin](https://www.paloaltonetworks.com/perspectives/author/sam-rubin/ "Posts by Sam Rubin")** | **8 min read** |  
![share icon](https://paloaltonetworks.com/content/dam/pan/en_US/cxo-perspectives/images/cxo-share.svg)

* LinkedIn button ![linkedin-icon](https://www.paloaltonetworks.com/content/dam/pan/en_US/microsite/cortex/images/share-linkedin.svg)
* Twitter share button ![twitter-icon](https://www.paloaltonetworks.com/content/dam/pan/en_US/microsite/cortex/images/share-twitter-x-black.svg)
* \[Email share button ![email-icon](https://www.paloaltonetworks.com/content/dam/pan/en_US/microsite/cortex/images/share-email.svg)\](mailto:?subject=Fighting Back Against Cyberattackers: How to Counter AI with AI\&body=Check out this article https%3A%2F%2Fwww.paloaltonetworks.com%2Fperspectives%2Fhow-to-counter-ai-with-ai%2F "Share in Email")
* ![copy-icon](https://www.paloaltonetworks.com/perspectives/wp-content/themes/csp2025/dist/images/icons/icon-share.svg)
  [](https://www.paloaltonetworks.com/perspectives/how-to-counter-ai-with-ai/?pdf=download&lg=en&_wpnonce=8c35f4dfea "Click here to download") MEET THE AUTHOR  
  ![](https://www.paloaltonetworks.com/perspectives/wp-content/uploads/2025/02/samrubin.png)  
  Sam Rubin is Senior Vice President at Palo Alto Networks, leading consulting and threat intelligence for Unit 42. With over 20 years in cybersecurity, he has built and scaled global incident response teams and handled major cyber incidents, including ransomware, supply chain attacks, and state-sponsored threats. Previously, Sam was an executive at The Crypsis Group, helping grow it into a top incident response firm before its acquisition by Palo Alto Networks in 2020. He has testified before Congress on ransomware and AI threats and served as an expert witness in cybersecurity litigation. A recognized thought leader, Sam speaks at industry conferences like GovWare and the Information Security Forum and has contributed to initiatives such as the Ransomware Task Force. His insights have been featured in The Wall Street Journal, Axios, and Bloomberg. Sam holds a B.A. from Emory University and certifications including CISSP, GCFA, and GCCC....

[Learn more](https://www.paloaltonetworks.com/perspectives/author/sam-rubin/)

## IN THIS ARTICLE

Cyberattackers are increasingly leveraging artificial intelligence (AI) and machine learning (ML) to execute more advanced and sophisticated threats, amplifying the scale and impact of their attacks. As a result, the perception among many organizations is that they see the scales tipping in favor of the attackers. In fact, a [recent Enterprise Strategy Group survey](https://www.techtarget.com/esg-global/research-report/generative-ai-for-cybersecurity-an-optimistic-but-uncertain-future-2/) noted a sobering statistic: 76% of organizations believe adversaries benefit the most from generative AI (GenAI), while only 24% think defenders have the upper hand.

To change this perception, organizations must adopt a proactive AI-driven defense strategy. This includes developing an AI-integrated cybersecurity plan and implementing business-aligned tactics to counter the growing AI-powered threats.

## Strategies for Leveraging AI in Cybersecurity: Choosing the Right AI Models

Understanding and navigating the complexities of AI can be daunting even for seasoned IT professionals, security experts, and data scientists. The constant state of change in AI methodologies, technologies, risks, and requirements means that deeply specialized knowledge is essential to leverage AI's full potential in cybersecurity.

GenAI stands out among the various forms of AI as the most-talked-about option as well as the most widely adopted in cybersecurity. GenAI's ability to simulate and train on cyberattacks has captured significant attention, making it a crucial tool for enhancing cybersecurity measures. Predictive AI is another emerging approach, helping organizations pinpoint when and where attacks are most likely to happen due to its pattern recognition capabilities. Also, causal AI is gaining momentum because of its ability to map relational patterns between cyberattacks and responses; this allows security teams to anticipate and counter threats with unprecedented speed.

But perhaps the most exciting strategic AI commitment may be [Precision AI](https://www.paloaltonetworks.com/cyberpedia/what-is-precision-ai)^™^. This framework helps create trustful AI outcomes empowering organizations to make mission-critical decisions with confidence. Precision AI uses rich data, honed from years of data capture and analysis by Palo Alto Networks tools and systems to create a security-specific model. This proprietary model is the key to automatically and intelligently detect, prevent, and remediate potential threats.

An important part of Precision AI is its ability to handle these requirements using contextually relevant data. This contextual relevance makes Precision AI a purpose-built AI model for cybersecurity. By combining generative AI, deep learning, and machine learning, Precision AI identifies and utilizes the right data for exactly the right use cases, including threat detection, anomalous behavior analysis, and Zero Trust implementations.

In addition to identifying and implementing the right AI model, an organization's AI-powered cybersecurity strategy should include:

* **Continuous monitoring and threat detection**: Implement AI-driven tools that offer real-time monitoring and detection of emerging threats.
* **AI-specific governance**: Establish clear governance policies to manage AI applications, ensuring compliance and reducing risks.
* Data integrity and protection: Secure sensitive data used in AI training and operations against leaks, poisoning, and unauthorized access.
* **Model auditing and validation**: Regularly audit and validate AI models to ensure accuracy, fairness, and robustness against adversarial attacks.
* **Human-AI collaboration**: Foster a security culture that integrates human expertise with AI capabilities for more effective threat management.

Developing and implementing these strategic steps can't be left solely to the chief information security officer (CISO) and their team. Cybersecurity is a collective effort, requiring vigilance and input across the organization, including even nontechnical stakeholders. Effective AI strategies for cybersecurity must have the unwavering support and active involvement of the C-suite and board members. Creating a collaborative approach ensures that decision-making is well rounded and not unduly influenced by any sole perspective; this is critical for ensuring a comprehensive cybersecurity approach.

## Tactics for Using AI Against the Other Side: Use Cases That Make a Difference

Even when all sides come together, there still are many tactical questions that need to be answered. For instance:

* Should an organization build its own model using its own data, or is it more expeditious to use a third-party, off-the-shelf model?
* Which software tools, frameworks, and methodologies are best?
* Is the right AI infrastructure in place to support compute-intensive applications?
* Are budgets sufficient in size, scale, and flexibility (remember, new AI advances are appearing daily)?
* Does the cybersecurity team possess the appropriate experience and expertise to understand AI-powered threats and leverage AI for more efficient and effective cybersecurity?
* Is there a full understanding of where AI is already being used inside the organization, including "rogue AI" efforts that are surreptitiously launched without official knowledge, backing, and support?

Addressing each of these questions from a tactical perspective is essential in using AI for good in cybersecurity. But perhaps the key tactical decisions to get the most from deploying AI for cybersecurity come down to selecting the most appropriate "high gain" use cases and applications. According to industry researcher [Enterprise Strategy Group](https://www.techtarget.com/esg-global/research-report/generative-ai-for-cybersecurity-an-optimistic-but-uncertain-future-2/), AI already is invaluable in use cases that "improve security team productivity, accelerate threat detection, automate remediation actions, and guide incident response."

One of the key benefits in using AI for a wide range of use cases is its ability to limit and even overcome the negative effects of both the cybersecurity skills gap and the AI skills gap. Each on its own has been a major drain on organizations' efforts and a bottleneck in getting the job done right. Filling in those two gaps has created a challenge of Grand Canyon-esque proportions, requiring executive commitment to allocating the proper resources.

This doesn't mean that organizations should jettison their hiring plans for both AI experts and cybersecurity engineers simply because AI adoption provides tangible benefits. Plenty of both will still be needed, but leveraging the key AI use cases for cybersecurity will rely heavily on the technology's innate automation and contextual awareness.

Here are a few specific use cases where AI will make a big difference in cybersecurity effectiveness (getting the job done in any way possible) and, especially, efficiency (doing so as quickly, frictionlessly, and cost-efficiently as possible) that should be in the consideration set for your tactical plan:

* **Advanced malware detection**: Cybercriminals are getting more creative in their use of AI to create and launch malware attacks. Cyber defenders, on the other hand, can use signature-based detection to extend the capabilities of traditional antivirus software, using signature data that leverages data on emerging threats.
* **Threat intelligence**: Even though most organizations subscribe to one or more threat intelligence services, the impact of AI on hackers' ability to introduce new threats faster than ever means threat intelligence tactics must similarly move ahead. AI provides more accurate and precise data analysis based on huge data volumes, as well as offering predictive analytics to spot problems before they emerge and to have the right response and remediation plans in place.
* **Real-time threat monitoring**: Continuous monitoring of system logs, network traffic behavior, user activity, and security infrastructure health is essential and AI makes that an integral part of overarching cybersecurity frameworks.
* **Anomaly detection**: AI algorithms---especially those with contextual awareness, such as Precision AI---are great at rooting out and surfacing abnormal, unexpected data or user behavior that could signal a vulnerability, threat, or active attack.

## Next Steps Toward Successful Use of AI in Cyberdefense

While many organizations are already taking steps to use AI for cybersecurity-related use cases, the strategies and tactics are fluid, dynamic, and always changing. But here are a few tips to help you get started---or to improve your chances of success:

1. **Cybersecurity is a strategic initiative**, so AI-powered cybersecurity absolutely must be a critical aspect to an overarching cybersecurity framework.
2. **Don't wait to get started**. If you haven't put a plan in place, you're already way behind the curve, and your risk profile is expanding by the minute. Conveying a sense of urgency is critical throughout the organization, including at the C-suite level and with the board of directors.
3. **Make sure you have the right people on the strategy team**. They should represent the full spectrum of the organization, not just the technical side. And strategy development must include representatives from business units, such as sales, marketing, legal/compliance, finance, and operations.
4. **Your strategic plan for AI in cybersecurity should be a living document**, evaluated and updated regularly and frequently to reflect the breakneck pace of technological improvements and the frightening speed with which new AI-powered attacks are launched.
5. **Don't try to boil the ocean when it comes to use cases**. Especially in your early stages of introducing AI for cybersecurity, pick a few use cases that will be relatively easy to implement and learn from, balanced with a handful of more challenging but big-impact use cases that really move the needle toward cybersecurity resilience.

Learn more about how to fight AI with AI at [paloaltonetworks.com/precision-ai-security](https://paloaltonetworks.com/precision-ai-security).

* [AI](https://www.paloaltonetworks.com/perspectives/all-articles/?cat=ai)
* [Staying Ahead of Evolving Threats](https://www.paloaltonetworks.com/perspectives/all-articles/?cat=staying-ahead-of-evolving-threats)

## Related Content

![](https://www.paloaltonetworks.com/perspectives/wp-content/uploads/2026/03/Securing-the-Wrong-Layer-featured.jpg) BLOG

### Staying Ahead of Evolving Threats

**Cybersecurity in 2026: What we predicted, what surprised us, and what's next**

At Palo Alto Networks, we are privileged to sit at the intersection of cybe...

[Haider Pasha](https://www.paloaltonetworks.com/perspectives/author/haider-pasha/ "Posts by Haider Pasha")
[](https://www.paloaltonetworks.com/perspectives/cybersecurity-in-2026-what-we-predicted-what-surprised-us-and-whats-next/)  
![](https://www.paloaltonetworks.com/perspectives/wp-content/uploads/2026/03/Why-Cybersecurity-KPIs-Are-Changing-featured.jpg) BLOG

### AI

**Why Cybersecurity KPIs Are Changing (And What This Means for Security Leaders)**

True cyber resilience is impossible to achieve without strategic and tactic...

[Helmut Reisinger](https://www.paloaltonetworks.com/perspectives/author/helmut-reisinger/ "Posts by Helmut Reisinger")
[](https://www.paloaltonetworks.com/perspectives/why-cybersecurity-kpis-are-changing-and-what-this-means-for-security-leaders/)  
![](https://www.paloaltonetworks.com/perspectives/wp-content/uploads/2026/03/Weaponized-Intelligence-featured.jpg) BLOG

### AI

**Weaponized Intelligence**

We are building the foundation that makes defense possible....

[Nikesh Arora](https://www.paloaltonetworks.com/perspectives/author/nikesh-arora/ "Posts by Nikesh Arora")
[](https://www.paloaltonetworks.com/perspectives/weaponized-intelligence/)  
STAY CONNECTED

## Connect with our team today

Job Level  
Sign me up to receive news, product updates, sales outreach, event information and special offers about Palo Alto Networks and its partners.  
By submitting this form, I understand my personal data will be processed in accordance with Palo Alto Networks [Privacy Statement](https://www.paloaltonetworks.com/legal-notices/privacy?ts=markdown) and [Terms of Use](https://www.paloaltonetworks.com/legal-notices/terms-of-use?ts=markdown).  
This site is protected by reCAPTCHA and the Google [Privacy Policy](https://policies.google.com/privacy) and [Terms of Service](https://policies.google.com/terms) apply.
Reach out  
{#footer} Products and Services

* [AI-Powered Network Security Platform](https://www.paloaltonetworks.com/network-security?ts=markdown)

* [Secure AI by Design](https://www.paloaltonetworks.com/ai-security?ts=markdown)

* [Prisma AIRS](https://www.paloaltonetworks.com/ai-security/prisma-airs?ts=markdown)

* [AI Access Security](https://www.paloaltonetworks.com/sase/ai-access-security?ts=markdown)

* [Cloud Delivered Security Services](https://www.paloaltonetworks.com/network-security/security-subscriptions?ts=markdown)

* [Advanced Threat Prevention](https://www.paloaltonetworks.com/network-security/advanced-threat-prevention?ts=markdown)

* [Advanced URL Filtering](https://www.paloaltonetworks.com/network-security/advanced-url-filtering?ts=markdown)

* [Advanced WildFire](https://www.paloaltonetworks.com/network-security/advanced-wildfire?ts=markdown)

* [Advanced DNS Security](https://www.paloaltonetworks.com/network-security/advanced-dns-security?ts=markdown)

* [Enterprise Data Loss Prevention](https://www.paloaltonetworks.com/sase/enterprise-data-loss-prevention?ts=markdown)

* [Enterprise IoT Security](https://www.paloaltonetworks.com/network-security/enterprise-device-security?ts=markdown)

* [Medical IoT Security](https://www.paloaltonetworks.com/network-security/medical-device-security?ts=markdown)

* [Industrial OT Security](https://www.paloaltonetworks.com/network-security/ot-security-solution?ts=markdown)

* [SaaS Security](https://www.paloaltonetworks.com/sase/saas-security?ts=markdown)

* [Next-Generation Firewalls](https://www.paloaltonetworks.com/network-security/next-generation-firewall?ts=markdown)

* [Hardware Firewalls](https://www.paloaltonetworks.com/network-security/hardware-firewall-innovations?ts=markdown)

* [Software Firewalls](https://www.paloaltonetworks.com/network-security/software-firewalls?ts=markdown)

* [Strata Cloud Manager](https://www.paloaltonetworks.com/network-security/strata-cloud-manager?ts=markdown)

* [SD-WAN for NGFW](https://www.paloaltonetworks.com/network-security/sd-wan-subscription?ts=markdown)

* [PAN-OS](https://www.paloaltonetworks.com/network-security/pan-os?ts=markdown)

* [Panorama](https://www.paloaltonetworks.com/network-security/panorama?ts=markdown)

* [Secure Access Service Edge](https://www.paloaltonetworks.com/sase?ts=markdown)

* [Prisma SASE](https://www.paloaltonetworks.com/sase?ts=markdown)

* [Application Acceleration](https://www.paloaltonetworks.com/sase/app-acceleration?ts=markdown)

* [Autonomous Digital Experience Management](https://www.paloaltonetworks.com/sase/adem?ts=markdown)

* [Enterprise DLP](https://www.paloaltonetworks.com/sase/enterprise-data-loss-prevention?ts=markdown)

* [Prisma Access](https://www.paloaltonetworks.com/sase/access?ts=markdown)

* [Prisma Browser](https://www.paloaltonetworks.com/sase/prisma-browser?ts=markdown)

* [Prisma SD-WAN](https://www.paloaltonetworks.com/sase/sd-wan?ts=markdown)

* [Remote Browser Isolation](https://www.paloaltonetworks.com/sase/remote-browser-isolation?ts=markdown)

* [SaaS Security](https://www.paloaltonetworks.com/sase/saas-security?ts=markdown)

* [AI-Driven Security Operations Platform](https://www.paloaltonetworks.com/cortex?ts=markdown)

* [Cloud Security](https://www.paloaltonetworks.com/cortex/cloud?ts=markdown)

* [Cortex Cloud](https://www.paloaltonetworks.com/cortex/cloud?ts=markdown)

* [Application Security](https://www.paloaltonetworks.com/cortex/cloud/application-security?ts=markdown)

* [Cloud Posture Security](https://www.paloaltonetworks.com/cortex/cloud/cloud-posture-security?ts=markdown)

* [Cloud Runtime Security](https://www.paloaltonetworks.com/cortex/cloud/runtime-security?ts=markdown)

* [Prisma Cloud](https://www.paloaltonetworks.com/prisma/cloud?ts=markdown)

* [AI-Driven SOC](https://www.paloaltonetworks.com/cortex?ts=markdown)

* [Cortex XSIAM](https://www.paloaltonetworks.com/cortex/cortex-xsiam?ts=markdown)

* [Cortex XDR](https://www.paloaltonetworks.com/cortex/cortex-xdr?ts=markdown)

* [Cortex XSOAR](https://www.paloaltonetworks.com/cortex/cortex-xsoar?ts=markdown)

* [Cortex Xpanse](https://www.paloaltonetworks.com/cortex/cortex-xpanse?ts=markdown)

* [Unit 42 Managed Detection \& Response](https://www.paloaltonetworks.com/cortex/managed-detection-and-response?ts=markdown)

* [Managed XSIAM](https://www.paloaltonetworks.com/cortex/managed-xsiam?ts=markdown)

* [Next-Generation Identity Security](https://www.paloaltonetworks.com/idira?ts=markdown)

* [Privileged Access Management](https://www.paloaltonetworks.com/idira/human/privileged-access-management?ts=markdown)

* [Identity and Access Management](https://www.paloaltonetworks.com/idira/human/identity-and-access-management?ts=markdown)

* [Endpoint Privilege Manager](https://www.paloaltonetworks.com/idira/human/endpoint-privilege-manager?ts=markdown)

* [Identity Governance](https://www.paloaltonetworks.com/idira/human/identity-governance?ts=markdown)

* [Workforce Password Management](https://www.paloaltonetworks.com/idira/human/workforce-password-management?ts=markdown)

* [Agentic Identities](https://www.paloaltonetworks.com/idira/agentic?ts=markdown)

* [Secrets Management](https://www.paloaltonetworks.com/idira/machine/secrets-management?ts=markdown)

* [Unified Secrets Governance](https://www.paloaltonetworks.com/idira/machine/unified-secrets-governance?ts=markdown)

* [Application Credentials Delivery](https://www.paloaltonetworks.com/idira/machine/application-credentials-delivery?ts=markdown)

* [Vendor Privileged Access](https://www.paloaltonetworks.com/idira/human/vendor-privileged-access?ts=markdown)

* [Threat Intel and Incident Response Services](https://www.paloaltonetworks.com/unit42?ts=markdown)

* [Prepare for Emerging Risks](https://www.paloaltonetworks.com/unit42/frontier-ai-defense?ts=markdown)

* [Strengthen Your Defenses](https://www.paloaltonetworks.com/unit42/strengthen-your-defenses?ts=markdown)

* [Build Your Security Strategy](https://www.paloaltonetworks.com/unit42/build-your-security-strategy?ts=markdown)

* [Understand the Adversary](https://www.paloaltonetworks.com/unit42/threat-intelligence?ts=markdown)

* [Respond to a Cyber Attack](https://www.paloaltonetworks.com/unit42/respond?ts=markdown)  
  Company

* [About Us](https://www.paloaltonetworks.com/about-us?ts=markdown)

* [Careers](https://jobs.paloaltonetworks.com/en/)

* [Contact Us](https://www.paloaltonetworks.com/company/contact-sales?ts=markdown)

* [Corporate Responsibility](https://www.paloaltonetworks.com/about-us/corporate-responsibility?ts=markdown)

* [Customers](https://www.paloaltonetworks.com/customers?ts=markdown)

* [Investor Relations](https://investors.paloaltonetworks.com/)

* [Location](https://www.paloaltonetworks.com/about-us/locations?ts=markdown)

* [Newsroom](https://www.paloaltonetworks.com/company/newsroom?ts=markdown)  
  Popular Links

* [Blog](https://www.paloaltonetworks.com/blog/?ts=markdown)

* [Communities](https://www.paloaltonetworks.com/communities?ts=markdown)

* [Content Library](https://www.paloaltonetworks.com/resources?ts=markdown)

* [Cyberpedia](https://www.paloaltonetworks.com/cyberpedia?ts=markdown)

* [Event Center](https://events.paloaltonetworks.com/)

* [Manage Email Preferences](https://start.paloaltonetworks.com/preference-center)

* [Products A-Z](https://www.paloaltonetworks.com/products/products-a-z?ts=markdown)

* [Product Certifications](https://www.paloaltonetworks.com/legal-notices/trust-center/certifications?ts=markdown)

* [Report a Vulnerability](https://www.paloaltonetworks.com/security-disclosure?ts=markdown)

* [Sitemap](https://www.paloaltonetworks.com/sitemap?ts=markdown)

* [Tech Docs](https://docs.paloaltonetworks.com/)

* [Unit 42](https://unit42.paloaltonetworks.com/)

* [Do Not Sell or Share My Personal Information](https://panwedd.exterro.net/portal/dsar.htm?target=panwedd)
  ![Palo Alto Networks Logo](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/pan-logo-dark.svg)

* [Privacy](https://www.paloaltonetworks.com/legal-notices/privacy?ts=markdown)

* [Trust Center](https://www.paloaltonetworks.com/legal-notices/trust-center?ts=markdown)

* [Terms of Use](https://www.paloaltonetworks.com/legal-notices/terms-of-use?ts=markdown)

* [Documents](https://www.paloaltonetworks.com/legal?ts=markdown)

Copyright © 2026 Palo Alto Networks. All Rights Reserved

* [![Youtube](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/social/youtube-black.svg)](https://www.youtube.com/user/paloaltonetworks)
* [![Podcast](https://www.paloaltonetworks.com/content/dam/pan/en_US/images/icons/podcast.svg)](https://www.paloaltonetworks.com/podcasts/threat-vector?ts=markdown)
* [![Facebook](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/social/facebook-black.svg)](https://www.facebook.com/PaloAltoNetworks/)
* [![LinkedIn](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/social/linkedin-black.svg)](https://www.linkedin.com/company/palo-alto-networks)
* [![Twitter](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/social/twitter-x-black.svg)](https://twitter.com/PaloAltoNtwks)
* EN  
  Select your language
