For as long as computers have been connected, security has been a cat-and-mouse game — and for most of that history, every security program rested on an assumption it rarely wrote down: most attackers will give up. Not because they lack malice; the internet has never lacked malice. Serious attacks took serious effort — time, language skill, infrastructure, tooling, the discipline to keep trying after the first easy attempt fails — so most attackers stopped early, and even the well-funded ones had to pick their targets. Ordinary people and ordinary businesses were protected by something unglamorous: they were not worth the trouble.

Attackers used to run out of time, skill, and patience. With AI, they don't. That does not make every attacker brilliant, and it does not hand every criminal crew the full intelligence apparatus of a nation-state. What it does is make pieces of that apparatus cheaper, faster, and easier to repeat. Reconnaissance can be automated. Variants can be generated. Phishing copy, translation, log analysis, target profiling, and persistence planning can be assisted at a scale that used to require a much larger team. Ask yourself honestly: are you as focused on using AI to defend as attackers are on using it to attack? For most of us, no — which means AI is currently helping the attacker more than it is helping the rest of us.

Consider an ordinary example: an internal reporting tool protected mostly by the fact that nobody outside the company knows its URL. For years that was a reasonable bet. The people who might stumble onto it lacked the patience to map an unfamiliar workflow. Automated reconnaissance does not lack patience. It maps everything it touches, and it does not get bored.

Many defenses were built around a quiet bargain: known to be limited, but good enough against casual attackers. They stopped opportunistic snooping, lazy credential reuse, a hurried bot. Against a patient, well-resourced adversary, everyone understood they could fail — and that was acceptable, because such adversaries were rare and had better things to do.

Call it little-sister encryption: protection that keeps out a curious sibling, a casual coworker, or a low-effort intruder, but was never a real boundary against someone determined. It is not useless. It reduces everyday risk. The mistake is asking it to carry a threat model it was never designed to carry.

That mistake used to be affordable. If only a state-level team could defeat a weak isolation boundary or an obscure internal service, the exposure could be rationalized as low. The calculation changes when ordinary criminal operators can rent, prompt, buy, or compose enough automation to behave like a far more capable team for the parts of the kill chain that matter.

The result is not that every attacker becomes elite. It is two shifts at once. The number of viable threat actors goes up, dramatically — a weakness that once demanded rare expertise may now demand only a decent toolchain and persistence. That is capability diffusion, the spread of the threat. And for the organizations that were always worth the trouble, the threat has deepened: attackers who already have financing get more attempts, more patience, and probes that run continuously and go deeper than before. Cyber crime is easier to do now than it has ever been. Obscurity, friction, language barriers, and attacker fatigue are all worth less than they were. Controls built for casual attackers cannot be treated as boundaries anymore.

The defensive response follows from the shift. Chasing attacks after they form is a losing race against automation. Stand up the most secure architecture you can, move fast on known vulnerabilities as they emerge, and isolate the information and resources you cannot afford to have reached. Above all, get identity and access right. A compromised identity does not break in — it logs in. The stale credentials and over-broad roles that used to be safe because nobody would bother to find them are exactly what AI is now finding. Real attacks are chains — linked steps toward a target — and AI now automates the patience it used to take to walk them.

What to check now: find the controls whose real justification is that attackers give up. Obscure URLs, weak internal segmentation, reversible masking, client-side enforcement, stale credentials, lightly protected backups, and private documentation that becomes dangerous the day it is discovered.

What to check now: sort your controls honestly. Which ones reduce nuisance, and which can survive a capable adversary? Little-sister controls can stay in the stack, labeled as what they are. They should not be the only thing standing between an attacker and sensitive data, privileged access, production systems, or customer records.

What to check now: reread every threat model that says 'only a nation-state could do this' and ask which part still requires one. If AI-assisted reconnaissance, code analysis, or workflow mapping removes the bottleneck, the defense is already out of date.

Anthus Threat Intelligence exists to study that shift as a practical operating problem: the places where old scarcity assumptions still hold up modern defenses, and the checks worth running while the assumption is merely wrong, and not yet expensive.