Artificial intelligence (AI) is no longer just helping cybersecurity teams find suspicious activity. It is starting to find vulnerabilities, test attack paths and, in some cases, act in ways that stretch the limits of the systems built to contain it. A clear directional signal for the landscape came Friday (Aug. 7), when OpenAI said preliminary tests of its upcoming Astra model were strong enough that the company could not rule out its highest cybersecurity warning level, known as the “Critical” threshold. Under OpenAI’s preparedness framework, that level means a model may be able to independently discover and develop working zero-day exploits against real-world systems or carry out cyberattacks from a high-level objective. The International Monetary Fund (IMF) reached a similar conclusion from a financial-stability perspective in a recent report. The organization’s central argument for its note entitled “Artificial Intelligence and Cybersecurity in the Financial Sector” was that AI does not need to invent fundamentally new forms of cyberattack to change the risk equation. By accelerating vulnerability discovery and exploitation across shared technologies, AI can turn weaknesses that once produced isolated incidents into correlated disruptions affecting multiple institutions simultaneously. That is a major development because the question is no longer only whether AI can write better phishing emails or help security teams sort through alerts. The question is what powerful models can do when given tools, credentials, network access or a poorly configured test environment. For banks, FinTechs, merchants and critical infrastructure operators, that changes AI cyber risk from a security-team concern into an enterprise governance problem. The question is no longer simply whether companies should use AI in cybersecurity. It is how much autonomy those systems should receive, what they should be allowed to touch and whether organizations can contain them when something goes wrong. See more: Wall Street’s New