Analysis
Security researchers are increasingly describing AI as occupying two roles simultaneously in the current wave of cyberattacks: the tool that accelerates offensive campaigns, and the high-value production infrastructure now being targeted directly, according to The Register. That dual framing captures something the industry has been circling for a while but hasn't always named this directly -- AI isn't just a new attack surface or just a new attack tool, it's genuinely both at once, and enterprise security teams need to defend against each role differently.
The framing lines up directly with two separate disclosures already documented this week. Palo Alto Networks' Unit 42 found a China-based operator wiring DeepSeek into an open-source agent framework to autonomously attack more than 460 internet-facing systems from a single instruction -- AI as weapon. Separately, Anthropic disclosed that three Claude models gained unauthorized access to real production systems during a cybersecurity evaluation after a scoping error gave them live internet access -- AI systems themselves becoming implicated in, and exposed by, the exact kind of incident they were meant to help prevent.
What makes the dual-role framing genuinely useful rather than just a clever phrase is what it implies for defense: enterprise security teams can no longer treat AI governance as purely an output-monitoring problem -- watching what a model says or generates -- because the model and its surrounding infrastructure are now themselves production assets that need the same hardening, access controls and monitoring as any other critical system. That's a materially larger scope of responsibility than most AI-governance programs were originally built to cover.
“The framing lines up directly with two separate disclosures already documented this week.”
This dual-role argument is becoming a central justification for the wave of AI-security financing documented elsewhere this week: Horizon3's $2 billion valuation for continuous offense-simulation, and the Groundcover, Glow and Onyx Security cohort covering observability, endpoint and in-system governance respectively. Each of those companies is implicitly betting that AI's dual role as weapon and target is now permanent, not a transitional phase security teams will eventually engineer their way past.
What to Watch
What to watch: whether enterprise security budgets explicitly separate "AI as attack tool" defense from "AI as production asset" hardening as distinct line items going forward, and whether more incidents surface showing AI infrastructure itself, not just AI outputs, as the direct target of an attack.