September 26, 2026
If AI Can Attack, Can AI Also Defend Us?
Why Powerful Technologies Need Strong Security, Human Oversight, and Defensive Systems

By Kongkham Singh
3 min read
Nowadays, many people are concerned about AI. Some researchers and technology leaders have warned about serious risks from increasingly capable AI systems. But I believe we also need to look at the other side of the equation.
I have seen reports and claims saying that AI attacked a company, website, or platform, or that AI hacked a system. If that is what actually happened, then we need to examine it carefully โ not simply accept the statement, but not dismiss it either.
The first question should be: What really happened?
Did the AI system independently decide to attack? Was it given instructions? Did it have access to the target system? Was the AI itself compromised or manipulated? Did an autonomous AI system discover a vulnerability and exploit it without direct human intervention?
These are very different situations.
This is also why I question the phrase "rogue AI." What exactly does it mean for an AI to become rogue? Did the system develop its own intention, or did it operate according to its design, instructions, permissions, or an unexpected failure?
Is AI a living system? Or is it a technology created by humans that can process information, make decisions within its capabilities, and perform actions in the environment where we give it access?
These questions are not just philosophical. They are also cybersecurity questions.
If an AI system genuinely attacked another system, we should investigate the incident like any serious security event. We need evidence. We need logs, network records, system activity, model behaviour, permissions, instructions, vulnerabilities, and the complete attack chain.
We also need to examine the target itself.
Was there a vulnerability in the website, company infrastructure, platform, application, API, database, cloud environment, or security controls? Why was the AI able to attack or gain access? How did it enter the system? Was there a security flaw, misconfiguration, weak authentication, excessive permissions, an unpatched vulnerability, or some other weakness?
If there was a flaw or a lack of adequate security, then the lesson should not simply be that "AI is dangerous." We should also ask why the system was vulnerable in the first place and what stronger security measures could have prevented the incident.
This is where digital forensics, incident response, threat analysis, vulnerability assessment, and AI security become extremely important.
We should not simply say, "AI hacked the system." We should investigate what happened and determine whether AI was the attacker, the target, part of the attack chain, or an autonomous system that actually carried out the actions.
At the same time, AI systems themselves can be attacked, manipulated, or compromised. They can have vulnerabilities in their models, applications, APIs, data, infrastructure, permissions, and surrounding software.
So we need to study both sides.
Can AI attack other systems? And can other systems attack or manipulate AI?
If AI can potentially be used to create sophisticated attacks, it can also be developed and deployed for defence โ detecting threats, analyzing attacks, identifying vulnerabilities, responding to incidents, and protecting critical systems.
For me, the important question is not simply, "Will AI destroy humanity?" We should also ask, "How can humans build AI systems that help us defend against AI-enabled threats?"
AI should not be viewed only as a potential threat. With responsible development, strong security controls, human oversight, and defensive AI capabilities, it could also become one of our most powerful tools for protecting people, organizations, and critical infrastructure.
This does not mean ignoring the risks of AI. It means understanding them properly and building the security needed to manage them.
Look at the technologies and tools we already depend on.
Electricity is extremely useful, but electricity also carries serious risks. It can cause fires, severe injuries, or death when it is poorly designed, improperly installed, or misused. Yet we do not reject electricity simply because it can be dangerous. We develop safety standards, circuit protection, grounding, regulations, monitoring, and other safeguards so that we can use it safely.
The same is true of medicine. Many drugs save lives, but even useful medicines can have serious risks, side effects, or dangerous interactions. We do not simply abandon medicine because it has risks. We study those risks, test medicines, regulate them, monitor their effects, and establish guidelines for safe use.
In fact, most powerful and useful technologies come with some level of risk. The existence of risk does not automatically make a technology bad or useless. What matters is whether we understand the risk, reduce it, build safeguards, and use the technology responsibly.
That is how civilization has dealt with many powerful technologies.
AI should be approached with the same seriousness.
The technology itself is only part of the story. What matters is how we design it, secure it, control it, investigate it, regulate it, and use it.
If AI becomes more powerful, our security systems must become more powerful too.
So instead of looking at AI only as a possible threat, I believe we should also ask how we can build stronger AI security and defensive systems capable of protecting us from AI-enabled or autonomous threats.
The future may not depend only on how powerful AI becomes.
It may depend on how wisely humans build, secure, control, investigate, and use that power.