The awkward part of AI security is no longer the demo where a model summarizes suspicious logs. It is the production system behind the demo: the API key, the agent workflow, the usage meter, the software package, and the contract nobody has reopened since procurement said yes. CrowdStrike’s latest warning flips the usual story. AI is not only watching the network; it is now part of the network that needs watching. ## The policy object changed, according to ZDNET and The Tech Buzz ZDNET’s Charlie Osborne reports that CrowdStrike describes artificial intelligence as "an adversary tool and target." The Tech Buzz reported that CrowdStrike’s warning was published on Aug 3, 2026, and framed AI systems as both network defenders and new attack surfaces. That is the sentence builders should put in plainer language: an AI deployment is no longer just a security capability. It is a governed asset with credentials, logs, usage patterns, dependencies, and failure modes. That distinction matters because governance programs often start with model behavior, fairness testing, and acceptable use language. Those still matter, but CrowdStrike’s framing pushes the work closer to operations. If an AI system can trigger alerts, call tools, access a frontier-model API, or pull from a software dependency, then policy has to cover who may invoke it, what it may reach, how usage is monitored, and who can shut it off. The compliance file is not complete if it describes the model and forgets the plumbing. ## Who is affected, according to The Register and ZDNET The Register reported that attacks by AI-enabled adversaries rose 89 percent in 2025, according to CrowdStrike, and quoted Adam Meyers, senior vice president of counter adversary operations at CrowdStrike, saying, "AI is both the weapon and the target." That does not put only security vendors in scope. It puts any organization using AI agents, model APIs, AI-assisted development environments, or AI components in production into the group that has something attackers may try to exploit. ZDNET reported one especially unsubtle example: LLMJacking generated nearly 200,000 API calls in two minutes. The Register also described LLMJacking as the theft of corporate credentials to access frontier-model APIs, and cost harvesting as deliberate inflation of a victim’s AI usage to run up its bill. Translate that into control language and the finance dashboard becomes a security signal. A sudden usage spike is not merely a budget anomaly; it may be credential abuse with an invoice attached. ## What changes in practice, according to CyberScoop and SecurityBrief Asia CyberScoop reported that AI generates 2.5 signals for every human-triggered signal CrowdStrike has to assess. It also reported that CrowdStrike’s threat hunting team and systems triaged an average of 14 million detection leads daily, resulting in about 36,000 customer alerts during the one-year period ending in June. That is a useful corrective to the clean vendor diagram where automation makes everything quieter. Automation may reduce manual work per event, but it can also increase the number of events that need classification, escalation, and evidence retention. SecurityBrief Asia reported that CrowdStrike’s 2026 Threat Hunting Report found AI embedded across modern adversary operations, with attackers shortening the gap between public vulnerability disclosure and exploitation while targeting AI systems and software supply chains. For builders, the resulting obligation is concrete rather than philosophical. Model access should be scoped like production infrastructure access. API keys need rotation, anomaly detection, and rate limits. Agent permissions should be narrow enough that a compromised workflow cannot wander through systems like an overconfident intern with root access. Vendor contracts also need to catch up. The clauses worth checking are not decorative: logging availability, incident notification, credential handling, tenant separation, abuse reporting, usage caps, dependency disclosures, and responsibility for unauthorized consumption. If the vendor cannot say what happened when a model API was abused, your incident report will contain a long paragraph titled "unknown." Auditors dislike that paragraph. So do customers, although they usually express it with shorter words. ## The compliance lesson, according to The Register and CyberScoop The Register reported that CrowdStrike sees patch windows shrinking to 48 hours as attackers use AI through the attack chain. CyberScoop separately reported that attackers are using AI to weaponize vulnerabilities faster than companies can patch them. The practical policy response is not to write a longer AI principles page. It is to connect AI governance to vulnerability management, identity management, procurement review, logging, and incident response. That means the owner of an AI feature should know which model endpoint it calls, which credentials authorize the call, which dependencies feed it, what usage looks like on an ordinary day, and who approves emergency suspension. Security teams should treat unusual AI usage as an alert class, not a quarterly cost review. Compliance teams should ask for evidence: access records, rate-limit settings, vendor notice terms, and dependency inventories. Builders do not need mysticism here. They need the same dull controls that already keep databases, cloud workloads, and payment systems from becoming someone else’s playground. The next item to watch is whether AI governance programs become operational enough to survive contact with deployed systems. CrowdStrike’s warning is useful because it moves the conversation from abstract model risk to the infrastructure around the model. If your AI security plan only says how AI helps defend you, it is missing the second half of the sentence. The tool is now also the target. ## Sources - CrowdStrike: AI Now Both Top Cyber Weapon and Prime Target | The Tech Buzz
- AI is both a cyber weapon and a massive target, CrowdStrike warns
- AI is 'both the weapon and the target' in latest wave of ...
- CrowdStrike says AI is now central to cyberattacks
- CrowdStrike: AI is now both the weapon and the target in ...
Sources
- CrowdStrike: AI Now Both Top Cyber Weapon and Prime Target | The Tech Buzz
- CrowdStrike Threat Hunting Report: AI Is Tool, Target
- AI is both a cyber weapon and a massive target, CrowdStrike warns
- AI is 'both the weapon and the target' in latest wave of ...
- CrowdStrike report: AI is rewriting rules of cybersecurity
- CrowdStrike: AI is changing cyber threats with AI and faster attacks
- AI is both a cyber weapon and a massive target, CrowdStrike warns
- CrowdStrike says AI is now central to cyberattacks
- AI Is Both a Cyber Weapon and a Massive Target, CrowdStrike Warns
- CrowdStrike: AI is now both the weapon and the target in ...