Artificial intelligence is making cyberattacks faster, more convincing and harder to distinguish from legitimate activity, forcing companies to rethink how they defend themselves, according to Abnormal AI CEO Evan Riser.
Riser told NYSE in a video posted on X that the rise of AI-generated attacks is exposing the limitations of traditional cybersecurity tools, which have historically relied on identifying known malicious files, websites and emails.
"The cybersecurity world used to run on threat intelligence, a list of bad stuff, but now every attack is unique," Riser said. But as AI makes attacks more sophisticated and individualized, that approach is becoming less effective, he said.
Read Also: Anthropic’s New Institute Chief of Staff Will Probe AI’s Impact
"They don’t really look like attacks. They kind of look like normal behavior," Riser said. That means companies will need to shift toward understanding what normal activity looks like and identifying anomalies in real time.
AI allows attackers to operate at machine speed rather than human speed while making phishing attempts and other attacks more convincing. Some AI-generated attacks may not resemble traditional threats at all, making them difficult for conventional systems and human security teams to identify.
"The real takeaway is that enterprises have to shift the cybersecurity paradigm for how they’re trying to stop this generation of cyberattacks," Riser said.
That shift is at the center of Abnormal’s expansion beyond its core email-security business. The company is moving into AI security, insider threats and identity security, using behavioral AI to monitor activity across employees and digital identities, including AI agents.
The distinction could become increasingly important as AI agents gain access to corporate systems and data. Companies will have to determine not only whether employees are behaving appropriately, but also whether software agents are acting within expected boundaries.
Riser said AI security is one of Abnormal’s biggest areas of focus for the second half of 2026. The company is also working with customers adopting AI internally and looking to monitor how those tools and digital identities behave.
The expansion reflects a broader shift in the cybersecurity industry as companies race to keep pace with AI-powered threats while securing their own adoption of the technology.
For enterprises, the challenge is increasingly two-sided: AI can help employees automate work and improve productivity, but the same technology can give attackers new ways to scale and personalize attacks.
Riser said defending against these threats will require more than simply adding AI to existing security products. Companies may need to change how they detect attacks — from looking primarily for known threats to understanding what normal behavior looks like and identifying when something deviates from it.
As AI makes attacks more individualized and harder to predict, that behavioral approach could become a central part of how companies protect their networks, employees and growing population of AI-driven digital identities.
Photo: Shutterstock
Read Also: Databricks Raises $5 Billion at $190 Billion Valuation Amid AI Frenzy