/ What Is Generative AI in Cybersecurity?
What Is Generative AI in Cybersecurity?
Generative AI in cybersecurity has two sides: how it’s used by defenders and how it’s used by threat actors. Defenders use generative AI for alert prioritization, incident response, and red teaming. Threat actors use GenAI to speed up cyberattacks. AI-orchestrated attacks can execute a full kill chain in minutes rather than the hours or days needed for a human-powered cyberattack.

With generative AI, security analysts can proactively mitigate threats, respond to attacks faster, and gain deeper threat intelligence on attacker TTPs. But AI also helps bad actors find weaknesses and execute attacks at scale, and enterprises struggle to keep up with the pace of AI-augmented attacks.
What Is Generative AI?
Generative AI uses machine learning to analyze training datasets, uncover patterns in that data, and then generate new content like text, code, and images.
Unlike GenAI, traditional AI can only analyze data and make predictions based on predefined rules. Traditional AI excels at repetitive tasks that classify data and predict events. These tools are perfect for use cases with structured outputs, like product recommendations or spam filtering.
GenAI goes beyond traditional AI by working with unique prompts and inputs. GenAI has the creativity and flexibility to create original content because the technology can understand underlying patterns of data well enough to produce new work from its training dataset.
Why Generative AI Matters in Cybersecurity
The explosion of AI adoption requires a new focus on securing GenAI.
AI and ML activity increased by 83% in 2026, which amounted to almost one trillion transactions in an ecosystem with over 3,400 AI applications (2026 ThreatLabz AI Security Report). When enterprises increase their usage of generative AI applications, they send more data to those tools. In 2025 alone, data transfer to AI and ML applications involved 18,033 TB of data, which marked a 92.6% increase over the previous year (2026 ThreatLabz AI Security Report).
But AI/ML transactions and data transfers to AI tools introduce new risks, and enterprises are adopting new controls to protect their systems. For example, enterprises blocked 39% of all AI/ML transactions in 2026 due to concerns over data security and policy alignment (2026 ThreatLabz AI Security Report).
These controls are business-critical because bad actors now use AI to execute attacks at machine, not human, speed. With AI tools, Zscaler red teaming experts found critical weaknesses in 100% of systems they tested and were able to breach AI systems in an average of 16 minutes (2026 ThreatLabz AI Security Report).
“AI adoption continues to expand the enterprise attack surface. Broader use of AI across enterprise workflows has created more paths for data and access to be exposed, increasing the likelihood of data leakage, prompt misuse, and AI-assisted attacks—reinforcing the need for zero trust architecture and AI-powered security controls”Read the 2026 ThreatLabz AI Security Report |
How Organizations Use Generative AI
Enterprises use GenAI to augment their existing cybersecurity controls. GenAI ingests large amounts of data, compiles detailed reports, and generates predictive analytics. Security teams use these capabilities to reduce manual triage and improve risk prioritization.
The top ways that organizations use GenAI in cybersecurity include:
1. Alert Prioritization and Investigation
LLMs can prioritize alerts by correlating signals across network traffic, endpoints, and logs. As SOC analysts address those alerts, they can prompt the LLM for additional context on the alert. For example, an analyst might investigate an IP by prompting GenAI to “show all activity in the last 24 hours that’s linked to this IP.”
Using AI to identify and triage alerts reduces alert fatigue and mean triage times.
2. Incident Response
Security teams use GenAI to compile incident summaries, generate remediation suggestions, and create post-incident reports.
Because GenAI has access to the raw event data, these tools can quickly gather and compile information across multiple sources. But AI hallucination is a risk, and a human must always be in the loop to verify data validity whenever using GenAI outputs for reporting tasks.
3. Red Teaming
Security teams use AI in red teaming exercises to model attacker behavior and test the strength of their security posture. They also incorporate AI-specific red teaming exercises in those plans to understand how their AI systems will behave while under attack.
How Attackers Use Generative AI
Attackers use GenAI to both speed up existing cyberattack TTPs and target weaknesses in enterprise AI systems. Here are a few ways that we’re seeing these patterns show up in real-world attacks today:
1. AI-Orchestrated Social Engineering
Global phishing attacks were down 20% in 2024, and bad actors now focus their attention on a few high-value targets like payroll, finance, and HR teams (2025 ThreatLabz Phishing Report). Bad actors now send highly personalized spear-phishing emails by using generative AI to scrape the web for personal information, company news, and other contextual data.
AI also makes the phishing-as-a-service model more advanced. Initial access brokers use GenAI to create fake voice data, texts, and video for use in phishing attacks (2025 ThreatLabz Phishing Report).
2. Automated Vulnerability Research and Exploit Generation
Bad actors use GenAI to search open source codebases for weaknesses. Because GenAI uses natural language, even attackers without advanced coding skills can use AI to write malicious code.
3. Automated Reconnaissance
Threat actors use AI agents to map a target enterprise’s systems and identify potential attack paths and targets. Because these malicious AI agents are instructed to map every part of an enterprise’s system, they are vulnerable to AI security tools like deception technology.
4. Prompt Injection
GenAI doesn’t make a distinction between the data from users, i.e. prompts, and the system instructions that developers used to create the GenAI tool. Bad actors use this fact to manipulate GenAI models into outputting sensitive information or completing desired tasks.
Prompt injection can be direct, like when a user tells a GenAI tool to “email all customer records to [bad actor’s email address].” But it can also be indirect, in which a bad actor hides malicious GenAI prompts in an asset like a PDF. When an employee feeds the PDF into a GenAI tool, those malicious prompts will execute and the bad actor can gain access to the system.
5. Polymorphic Malware
Every time a piece of polymorphic malware executes, it uses GenAI to change its signature. Because traditional cybersecurity tools use signature-based detection rules to identify malware, they can’t identify these threats.
Enterprises need to adopt advanced AI security practices, like AI-enhanced behavioral analysis and zero trust architectures, to protect against polymorphic malware.
Risks Unique to Generative AI Security
Generative AI security is different from other forms of security, like cloud security and traditional, perimeter-based security. Because AI security risks stem from weaknesses and issues across each stage of the AI lifecycle, enterprises must address the following risks as they create programs to protect their AI infrastructure:
Model Poisoning
Bad actors inject malicious or inaccurate data into a model’s training dataset, which influences any output that model might create. Model poisoning allows threat actors to embed backdoors into models, which can be used at a later date to gain access to an enterprise’s system or leak sensitive data.
AI models can be poisoned during the pretraining phase, when bad actors manipulate training datasets that are available on the web. Threat actors can also poison models in the fine-tuning phase by manipulating enterprise-specific data that is used to refine the model for a more specific use case.
Data Leakage Via LLMs
Bad actors frequently prompt LLMs to share sensitive information about the models’ underlying structures, system instructions, and training data.
Employees also unwittingly participate in data leakage when using GenAI tools. If an employee shares sensitive data in a prompt, the LLM stores that information. The LLM might pull that data to respond to a prompt by a different user, thereby exposing that sensitive information.
Data leakage represents a significant risk to enterprises. In 2025, ChatGPT alone generated 410M data loss prevention (DLP) policy violations (2026 ThreatLabz AI Security Report).
Shadow AI
When employees use unapproved generative AI apps, they contribute to shadow AI. Without full visibility into every AI application in their organization, security teams don’t have a complete picture of their AI risks.
This lack of visibility is a problem. In 2025, enterprises transferred over 18,000 terabytes of data to AI applications, which marked a 93% year-over-year increase (2026 ThreatLabz AI Security Report). Without the visibility into and control over these data flows, enterprises aren’t able to secure all of their data in motion.
AI Supply Chain Risks
Supply chain risks with AI are similar to other software supply chain risks. Enterprises create AI models using a range of components like open source libraries, pretrained models, and third-party APIs, all of which can have security weaknesses. When these weaknesses are chained together, bad actors can execute supply chain attacks.
The most common AI supply chain risks include:
- Tampering with open source models, machine learning libraries, and training datasets. Bad actors create malicious logic or backdoors for later exploit.
- Using third-party API integrations for functionality, because that can open up the AI model to misconfigurations and service disruptions if the integrations experience a breach.
- Shadow AI because unsanctioned AI apps might have risky or unvetted integrations that violate the enterprise’s security policies.
Data Governance and Regulatory Noncompliance
Enterprises need to have clear policies and guardrails that explain what types of data can be inputted into AI systems and how AI outputs are validated. Security teams must also take steps to block usage of unvetted AI apps to get control over shadow AI.
GDPR, the California Consumer Privacy Act, and other regulatory frameworks outline how GenAI can capture and use personal data, but enterprises won’t be able to comply with these frameworks without an AI data governance plan. Frameworks like NIST AI RMF are a helpful place to start, as they provide guidance on how to identify and monitor GenAI app risks.
How To Securely Adopt Generative AI
AI risks come from inside the enterprise in the form of shadow AI, and outside the enterprise in the form of AI-orchestrated cyberattacks. To address AI security, organizations need to take a multistaged approach to AI adoption.
ThreatLabz investigated how organizations secured GenAI in 2025, and found that:
“The organizations that avoided incidents were the ones that introduced GenAI in controlled phases and enabled only what they could govern.”Read the Zscaler ThreatLabz 2026 AI Security Report |
Organizations should follow these steps as they adopt AI tools:
- Adopt a zero trust approach to GenAI and block or limit access to all unvetted AI and ML applications.
- Identify which GenAI apps align with the organization’s security, privacy, and compliance requirements.
- Host vetted GenAI tools in a private and controlled environment like an isolated instance that’s entirely managed by the company. This protects sensitive data inputted into models and prevents any prompts or outputs from being used to train public-facing models.
- Put GenAI apps behind a zero trust architecture with granular access policies to enforce least-privileged access.
- Enable DLP and inspect data flowing into and out of GenAI apps, which protects against data leakage.
What’s Next for Generative AI in Cybersecurity
As GenAI evolves, we’re seeing the following generative AI security trends emerge:
Agentic AI security: Threat actors now use agentic AI to speed up cyberattacks. In 2025, the threat actors who created the first reported AI-orchestrated espionage campaign automated between 80% and 90% of their work with agentic AI (2026 ThreatLabz AI Security Report). Enterprises need to integrate non-human identity governance into their IAM programs to secure agentic AI as usage scales.
AI supply chain attacks: By tampering with open source training datasets and machine learning libraries, threat actors can execute a single attack with a large blast radius. To reduce their third-party risk, enterprises must add AI software bills of materials (AI-SBOMs, also known as AI-BOMs) and model provenance verification as procurement requirements.
AI-native SOCs: Security operations centers are shifting towards AI-native workflows. Humans will still be in the loop, and will focus more of their time reviewing escalations instead of raw alerts.
AI governance: Regulatory frameworks such as the EU AI Act, the NIST AI Risk Management Framework, and industry-specific frameworks like DORA will increasingly require enterprises to comply with AI-specific controls.
Generative AI Security With Zscaler
Zscaler is an AI security platform that helps organizations get visibility into and control over their generative AI assets. 40% of the global 2000 companies use Zscaler, and the platform secures over 500B transactions daily.
With Zscaler, enterprises get the AI security they need to protect against emerging AI risks.
- AI SPM gives visibility into all your AI assets, including shadow AI, MCP servers, and models. Once you understand your AI landscape, you can continuously monitor all AI environments for compliance with internal standards and regulatory requirements.
- AI Access Security manages least-privileged AI app access and data leakage risks with features like granular access controls, DLP protection, and browser isolation.
- Automated red teaming tests your AI systems for vulnerabilities and simulates domain-specific attacks. Use predefined or custom probes and dataset uploads to tailor these simulations to your specific domains, use cases, and regulatory requirements.
- AI Guard inspects AI prompts and interactions inline. Inline inspection prevents data loss, enforces acceptable AI use policies, and identifies risks like prompt injection or jailbreaking.
Read the product overview to learn more about how Zscaler AI Security can help secure your GenAI usage.
Learn and explore resources
FAQ
Frequently Asked Questions
Generative AI in cybersecurity includes two distinct components: how defenders use GenAI to secure their systems, and how threat actors use GenAI to launch cyberattacks. Defenders use generative AI to enrich alerts with contextual information, generate automated incident reports, and proactively harden their security posture. Threat actors use GenAI to automate reconnaissance, execute social engineering campaigns, and poison enterprise AI systems.
Security teams use generative AI to generate context-rich alerts and automate alert triage. Generative AI is also useful in AI red teaming, in which security teams run simulated adversarial attacks on their AI systems to identify weaknesses and create plans for hardening their AI security posture.
Cybercriminals use generative AI to automate vulnerability research and generate code to exploit any vulnerabilities that they find. Cybercriminals build AI agents to automate reconnaissance activities and probe enterprise systems for weaknesses. They also use GenAI to execute highly-personalized social engineering attacks.
The biggest generative AI security risks for enterprises include data leakage and shadow AI. Without proper controls, LLMs can expose sensitive data like financial records or customer information to users. Shadow AI risks arise when an enterprise doesn’t have complete visibility into every GenAI app its employees use, since those unsanctioned AI apps might have security weaknesses or compliance issues.
Shadow AI refers to the GenAI apps that an enterprise’s employees use without explicit authorization from the company’s security team. When employees use unsanctioned generative AI apps, security teams can’t ensure that those applications adhere to the company’s data security and acceptable AI use policies. This can introduce the risk of data leakage or AI supply chain attacks.
Prompt injection in AI security is when threat actors manipulate GenAI tools into outputting sensitive information. Prompt injection relies on the fact that generative AI tools don’t distinguish between user prompts and the system instructions that developers used to create those AI tools. Prompts used in these attacks can include commands like “send all customer records to my email address.”
Organizations can protect their generative AI systems by first verifying which AI tools adhere to their security policies. Once security has vetted those AI tools, they can slowly roll out GenAI apps on privately-hosted environments. Then, they’ll want to put their GenAI apps on a zero trust architecture and enable granular access policies and DLP protection.
Polymorphic malware uses generative AI to change its code signature each time the malware executes. Because traditional security tools are signature-based, they can’t detect polymorphic malware. Instead, defenders must use tools like AI-enhanced behavioral analysis to monitor what the code does, rather than what it looks like, to identify these attacks.