Key Takeaways

- AI is increasing the speed and scale of cyber threats, often by making it easier to exploit vulnerabilities that already exist.
- Cybersecurity is a business risk, not just an IT issue. An incident can affect operations, customers, contracts, insurance obligations, confidential information and intellectual property.
- Basic protections such as timely security updates, appropriate access controls, authentication and monitoring become even more important as AI accelerates cyber activity.
- Third-party vendors can introduce additional cyber risk, making security requirements, breach notification, liability and data handling important considerations in vendor agreements.
- Businesses should establish incident-response responsibilities before a problem occurs, including who makes decisions, when legal counsel is involved and how potential incidents should be reported.
- Business leaders do not need to become cybersecurity experts, but they do need to make sure qualified professionals are involved and that the company’s legal and business practices keep pace with changing risks.
Artificial intelligence is changing how companies work. It is also changing how quickly bad actors can find and exploit weaknesses in the systems businesses depend on.
That became particularly clear when Anthropic, the company behind Claude, disclosed a cyber espionage campaign in late 2025in which attackers manipulated its AI tools to help carry out intrusions against organizations around the world. According to Anthropic, AI was used not just to provide information to the attackers, but to perform substantial portions of the operation.
Since then, the picture has continued to evolve. Anthropic’s more recent threat research has found AI being used by state-sponsored groups, financially motivated criminals, and individual actors to conduct reconnaissance, identify vulnerabilities, develop tools, exploit systems, and process stolen information. In some cases, work that previously required multiple skilled people can now be performed much faster and across multiple targets at once.
For businesses, the important takeaway isn’t the technology behind the attacks. It’s that the speed of cyber risk is changing.
Cybersecurity Is a Business Risk
BRAWW Law is not a cybersecurity firm, and businesses should rely on qualified IT and cybersecurity professionals to determine what technical protections they need.
But cybersecurity is no longer an issue that belongs exclusively to the IT department. A successful attack can interrupt operations, compromise confidential information, affect customers, expose intellectual property, and trigger obligations under contracts, insurance policies, and applicable laws. For technology companies in particular, a security incident can also affect the very products and services their customers rely upon.
That makes cybersecurity part of a company’s broader risk-management responsibilities. The National Institute of Standards and Technology (NIST) makes this point explicitly in its Cybersecurity Framework 2.0. It emphasizes that cybersecurity risk should be considered alongside other enterprise risks and organizations should establish clear strategies, expectations, policies, roles, and responsibilities for managing it. In other words, the people responsible for the business need to be part of the conversation.
Faster Threats Put More Pressure on Basic Protections
AI hasn’t necessarily created an entirely new set of vulnerabilities. In many cases, it is making it easier and faster for attackers to exploit weaknesses that already exist.
Anthropic’s recent threat research found attackers using AI against unpatched internet-facing systems, exposed services, and stolen credentials, among other familiar vulnerabilities. The difference is the speed and scale at which those activities can now occur.
That makes basic cybersecurity practices increasingly important: installing updates and security patches promptly, controlling access to systems and data, using appropriate authentication, monitoring for unusual activity, and paying attention when technology providers identify a vulnerability or recommend an update.
Businesses also need to understand that an update intended to address one problem can occasionally create another. Software changes can affect compatibility, slow systems, or cause temporary disruptions. That can be frustrating, particularly when a business depends heavily on technology to operate. But delaying important security updates because they are inconvenient can carry its own risk.
The technical decision about when and how to implement a particular patch belongs with the company’s IT or cybersecurity professionals. Management’s responsibility is to make sure someone is paying attention, that there is a process for responding quickly, and that cybersecurity isn’t being handled only when something goes wrong.
Your Vendors Are Part of the Equation
A company’s cyber risk doesn’t end with the systems it directly controls. Businesses increasingly rely on cloud platforms, software providers, outsourced IT companies, payment processors, and other third parties that may have access to systems, customer information, or other sensitive data. For technology companies, those relationships can be especially interconnected.
The Federal Trade Commission recommends addressing security expectations directly in vendor contracts, including how vendors will protect information and update their security controls as threats change. NIST similarly treats cybersecurity supply-chain risk as an important part of an organization’s overall cybersecurity program.
That means vendor agreements deserve attention beyond pricing and service levels. Depending on the relationship and the information involved, businesses may need to consider issues such as security requirements, access to data, incident notification, responsibilities following a breach, insurance, indemnification, limitations of liability, and what happens to company or customer data when the relationship ends.
Those provisions can’t prevent a cyberattack. They can, however, make responsibilities considerably clearer when one occurs.
Don’t Wait for an Incident to Figure Out the Plan
The same principle applies internally. If a company experiences a cyber incident, who has authority to make decisions? Who contacts the cybersecurity provider? When does legal counsel become involved? What contractual notification requirements may apply? Who communicates with customers, employees, insurers, or other parties? What records need to be preserved?
That preparation also needs to extend beyond the people responsible for managing an incident. Regular employee training can help people recognize phishing attempts, suspicious requests, and other warning signs, but training should also reinforce what to do when something goes wrong. Employees need to know how and where to report a potential incident quickly, even if they clicked a link, shared information, or made a mistake that they’re embarrassed to admit. Fear of getting in trouble can cost valuable time. The sooner the right people know there may be a problem, the sooner the company can investigate and respond.
NIST recommends that organizations establish incident-response responsibilities in advance and understand how confirmed incidents will be communicated to customers, business partners, regulators, law enforcement, and others when required by law, contract, or policy.
The specifics will vary considerably depending on the company, its industry, the information it handles, and the laws and contracts that apply. The important point is to have those conversations before they become urgent.
AI Is Moving Fast. Businesses Need to Keep Pace.
The cybersecurity arms race isn’t new. Attackers find vulnerabilities, defenders respond, software companies issue patches, and attackers look for another way in.
AI is accelerating that cycle. Businesses don’t need to become cybersecurity experts themselves, nor should they try. They do need qualified professionals watching the technology, leadership that takes their recommendations seriously, and legal and business practices that reflect the reality that cyber incidents can create consequences far beyond the network.
This is a good time to review not only whether your business’s technology is protected, but whether contracts, vendor relationships, insurance coverage, internal responsibilities, and incident-response plans have kept pace with the changing risk.
BRAWW Law works with technology companies and other businesses on the legal issues that surround their operations, contracts, and risk management. When an issue requires specialized technical cybersecurity expertise, we can work alongside the appropriate professionals to help clients understand and address the broader business and legal implications.
