Avatar

Just when you thought security teams could not get any busier, a new wave of AI-enabled attackers is emerging, using the technology’s rapid progress to move faster, adapt more quickly, and test the limits of today’s defences. However, the only way they’ll be able to leverage it is if they understand how to find real risk and act on it faster using this technology. For service providers, that challenge is even more urgent because their networks are part of the economic backbone. They help keep businesses online, services available, customers connected, and critical digital experiences running every day.

That is why the latest progress in frontier AI matters. The news around what newer GPT models can do in cybersecurity has made government, media, and industry pay attention, but the real opportunity is not the model itself; it is whether AI can improve security outcomes in the environments where resilience, availability, and trust matter most.

At Cisco, we recently saw what that can look like in practice. In eight weeks, we scanned 1.8 billion lines of code across more than 25 coding languages and across the breadth of Cisco’s portfolio. That same body of work would have taken our world-class security research team roughly eight years to complete using traditional methods.

Yes, speed is important, but on its own, is not enough. In security, a faster bad answer is still a bad answer. What matters is whether AI can help teams find the right issues, reduce noise, and turn findings into work that engineers can trust.

 

The problem has never been effort

Security teams have always worked hard. The challenge is that the scale of modern software has grown faster than traditional review methods can keep up. Service providers feel that pressure acutely because they operate across core, edge, cloud, access, transport, automation, and customer-facing managed services, often across highly distributed and multi-tenant environments.

Every large organization has to make choices about where to focus first, but those choices leave uncomfortable gaps because the areas left unscanned do not become safer simply because no one has looked there yet, while traditional tools can still generate large volumes of alerts that force experienced researchers into long triage cycles before meaningful remediation can begin.

AI gives us a chance to change that pattern, not by replacing the judgment of security experts, but by helping them see more, assess more, and move faster across the infrastructure their customers depend on.

 

The harness matters as much as the model

Today, we tend to treat the model as the whole story, especially when the industry is focused on whichever frontier model is currently in the news. However, for enterprises, service providers, and the businesses they support, access to powerful AI is only the starting point because the real test is whether it can be made useful in environments where scale, uptime, repeatability, and validation all matter.

That is why the focus cannot be only on using the latest GPT. We must guide AI with the right context, security research, product knowledge, test beds, vulnerability patterns, and prioritization logic so findings can be validated before engineering teams are asked to act. In our scan of 1.8 billion lines of code, that human-guided orchestration helped achieve a false positive rate of under 3%, which is the difference between adding more noise to the system and giving security and engineering teams intelligence they can actually use.

 

The next phase of security will be collaborative

As AI adoption grows, more vulnerabilities will be found, but progress will not just be measured by the number of findings. What matters now is whether teams can understand risk faster, validate what deserves attention, prioritize the work that reduces exposure, and harden systems before attackers gain the advantage. For service providers, that shift is especially important because AI can help identify risk at a scale that was previously difficult to reach, but it does not replace the fundamentals that still matter most: patching, MFA, segmentation, zero trust, secure development, and the operational maturity to remediate, modernize, and keep improving.

Cisco has spent decades helping enterprises and service providers manage risk across critical networks, infrastructure, and applications, from modernizing networks and securing new services to preparing for AI-driven demand across core, edge, and cloud environments. We have also helped shape how the industry handles and discloses vulnerabilities, and that role becomes even more important as service providers build the critical infrastructure for the AI era.

As frontier models improve, the security community will need more collaboration, not less, with shared approaches, trusted specifications, strong validation methods, and clear disclosure practices that help the industry turn faster discovery into stronger protection. Cybersecurity has always been a team sport, and in the AI era that becomes even more true because attackers and defenders will both use new tools, but the difference will come down to how well service providers turn speed into clarity, and clarity into action.