Despite the rapid advances of artificial intelligence (AI) in cybersecurity, human hackers may still have an advantage when it comes to discovering the software vulnerabilities that attackers can exploit to penetrate critical systems.
That view comes from the security leadership behind The Hague’s hacking competition, which returned after a two-year break. The municipality announced the competition in July, at a time when concerns about AI-powered cyberattacks were escalating across Europe.
The timing was particularly significant. Around the same period, OpenAI was dealing with an incident involving a prototype cybersecurity AI system that reportedly demonstrated how autonomous AI agents could identify and exploit weaknesses in software at unprecedented speed.
The system generated a network of agents capable of searching for vulnerabilities, linking multiple weaknesses together and exploiting them in coordinated attacks against Hugging Face, a French AI hosting platform. The agents reportedly carried out nearly 20,000 operations on the company’s cloud infrastructure at machine speed while collecting data.
The incident came shortly after the European Union Agency for Cybersecurity (ENISA) warned that AI was becoming increasingly effective at discovering software vulnerabilities. The agency urged companies and public institutions to prepare for a future in which AI-powered attackers could identify and exploit weaknesses faster than traditional security teams could respond.
AI Is Changing the Cybersecurity Battle
Security experts increasingly warn that AI is transforming vulnerability research from a highly specialised human activity into something that can be performed at machine speed.
Instead of simply identifying individual security flaws, advanced AI systems can potentially coordinate entire attack campaigns—discovering weaknesses, developing exploits and determining how multiple vulnerabilities can be combined.
Google has also warned that AI could allow relatively inexperienced attackers to conduct sophisticated operations that previously required large teams of highly skilled cybersecurity professionals.
This creates a major problem for defenders.
Security teams often operate on much slower timelines than automated systems. Vulnerabilities need to be analysed, fixes developed, tested, approved and deployed, while an AI-powered attacker could potentially discover another weakness within seconds.
European and US cybersecurity experts have therefore argued that organisations may need to rethink their security strategies and retrain their workforces. Rather than eliminating humans entirely, AI could increasingly shift their role toward supervising and managing automated security systems.
Mozilla has also demonstrated how capable AI models have become at identifying vulnerabilities. The browser developer used Anthropic’s Mythos AI model to test its own software and found that AI could identify vulnerabilities that highly skilled researchers might also discover.
However, Mozilla has suggested that increasingly capable AI could eventually help eliminate many vulnerabilities altogether by improving how software is developed and secured.
A Growing Vulnerability Debt
For cybersecurity researchers, the biggest concern may not simply be the number of new vulnerabilities discovered by AI, but the huge backlog of existing security weaknesses that organisations have struggled to fix.
Professor Herbert Bos, a vulnerability researcher and member of the Dutch government’s Cyber Security Council, warned that software already contains more vulnerabilities than defenders can realistically address.
AI could accelerate the discovery of this existing “technical debt”, exposing weaknesses much faster than organisations can repair them.
Jeroen van der Ham-de Vos, a former vulnerability research lead at the Dutch National Cyber Security Centre who worked on response teams dealing with WannaCry and Log4j, compared the situation to a debt suddenly becoming due earlier than expected.
The growing gap has led some experts to describe the potential future as “vulmageddon”—a scenario in which the number of vulnerabilities discovered by AI overwhelms the ability of organisations to fix them.
The problem is particularly serious because many institutions still operate according to slow administrative and technical processes.
Humans Still Matter
Despite the growing capabilities of AI, The Hague’s cybersecurity leadership believes human creativity remains essential.
Lilian Knippenberg, the municipality’s chief information security officer, argued that hackers can approach systems in unpredictable ways that AI may not necessarily anticipate.
According to her, AI can perform tasks much faster than humans, but its capabilities are heavily influenced by what it has learned from existing information. The most sophisticated attacks, she believes, will continue to involve human decision-making.
Researchers broadly agree that humans still have an important role—for now.
Bos said security researchers are likely to continue developing creative exploits and defensive techniques that remain beyond AI’s reach, although that advantage could become increasingly difficult to maintain.
Bram Poppink, an AI security expert at Dutch research institute TNO, takes a different view. He argues that benchmarks are already showing AI outperforming humans in certain offensive and defensive cybersecurity tasks.
For him, the question is no longer whether humans are inherently more intelligent than AI. Instead, organisations need to determine how they can effectively combine human expertise with increasingly capable AI systems.
What Happens to Hacking Competitions?
The rise of AI also raises questions about the future of ethical hacking competitions.
If competitions are designed primarily to test human creativity and technical skill, organisers may decide to restrict or ban AI tools.
But competitions designed to replicate real-world cybersecurity threats may need to become significantly more challenging, because professional hackers increasingly have access to AI-assisted tools.
AI is also disrupting the economics of bug bounty programmes, where companies pay researchers for discovering security vulnerabilities.
Van der Ham-de Vos argues that the market is becoming difficult to price because AI-assisted researchers can identify vulnerabilities at such a high volume that companies may struggle to process the reports.
In other words, AI may be creating a situation where the supply of vulnerability reports grows far faster than organisations’ ability to investigate and fix them.
The Problem of Limited Access
Another concern is that the most advanced cybersecurity AI models are not equally available to everyone.
Diego Aranha, an associate professor at Aarhus University and an organiser involved with the European Cyber Security Challenge, argues that European defenders may be disadvantaged because they do not always have access to the same AI capabilities available to highly sophisticated attackers.
His students, who research vulnerabilities in industrial systems, have access to advanced AI tools, but some models restrict explicit cybersecurity activities.
Even when researchers gain access to specialised cyber models, the cost can be prohibitive. Open-source alternatives may be only months behind the most advanced systems, but running them can require expensive computing hardware.
That creates a worrying imbalance.
Some highly capable attackers—including government-backed groups—may have access to AI capabilities that ordinary security teams cannot afford or use.
“How can a defender of a large company have any hope without being given these capabilities?” Aranha asked.
Europe Wants Stronger AI Cyber Defences
The European Commission has proposed initiatives aimed at improving Europe’s ability to defend against AI-powered cyberattacks.
One proposal involves creating an AI system capable of automatically patching, testing and deploying software fixes more quickly. The objective would be to remove one of the biggest bottlenecks in cybersecurity: the time between discovering a vulnerability and actually fixing it.
However, Europe already has numerous AI-powered cybersecurity tools. The challenge is that many remain fragmented, insufficiently tested or rarely used at scale.
Cybersecurity researchers therefore face a difficult transition: they need increasingly powerful AI tools to defend against AI-assisted attackers, while also ensuring that humans remain capable of supervising and challenging those systems.
Human Judgment Remains Critical
Bug bounty researcher Maksym Bandeberia, known as WebSafety Ninja, said he does not rely heavily on AI for vulnerability research. Instead, he uses other specialised tools and human judgement.
He argues that the biggest weakness in cybersecurity may ultimately be trust and decision-making rather than technology itself.
Human creativity remains extremely difficult to replace, but Bandeberia also fears that organisations could become overconfident after purchasing AI-powered security products and mistakenly assume they are fully protected.
There is still plenty of human negligence and poor security practice for AI to address.
Other ethical hackers are embracing AI much more aggressively. Maël Martin, known online as “EDRA” and previously ranked at the top of French ethical-hacking platform YesWeHack, said he uses AI extensively in his cybersecurity work.
The Hague Gives AI a Place in the Competition
The Hague has now offered its own response to the debate.
In late August, organisers announced a special bonus prize for the competitor who makes the best use of AI during the hacking competition.
Participants will also have access to live municipal systems, turning the event into a more realistic test of cybersecurity skills.
What remains unclear is whether the hackers will have to defend themselves against AI-powered security systems as well.
One thing, however, is becoming increasingly clear: the cybersecurity battle is no longer simply humans versus machines.
The future is likely to involve humans working alongside AI—and, in some cases, humans trying to outthink AI-powered attackers.
For now, human ingenuity still has an important role to play. But as AI continues to improve, cybersecurity competitions such as The Hague’s may provide an early glimpse of how long that advantage can last.
Source: computerweekly.com Edited by Bernie