The Window Is Open. Will Security Teams Walk Through It?

There is something fundamental shifting in how companies are built, operated, and protected and it is happening at a pace that is outrunning most organizations' ability to respond. We are in the early stages of an AI transition that will touch every corner of the enterprise, and we believe that security teams sit at the center of it.
The question today is whether they lead or lag.
The scale of the change is hard to overstate
The confluence of rapid AI adoption, untested boundaries, non-existent norms around AI security and safety, and existing cybersecurity risk is requiring a fundamental change to how companies approach digital security. This is not a vendor talking point but rather it is the conclusion of every major security research organization looking at the data right now. Cisco Blogs
The numbers back it up. AI-related vulnerabilities hit a record high in 2025, accounting for 4.42% of all CVEs, up 34.6% year over year, and projections for 2026 suggest between 2,800 and 3,600 AI-specific CVEs, a 31 to 69% increase driven by the rapid adoption of agentic systems and expanding LLM ecosystems. Meanwhile, AI-powered attacks are no longer experimental. Attackers are using AI-generated phishing in 37% of breach attempts, deepfakes in 35%, and the average cost of an AI-driven attack now exceeds the global mean at $4.49 million per incident. Trend MicroStationX
The threat surface is not just growing instead it is changing shape entirely.
The organizational gap is widening
At the outset of 2025, while 83% of organizations planned to deploy agentic AI capabilities into their business functions, only 29% felt they were truly ready to leverage these technologies securely. Organizations rushed to integrate AI into critical workflows, often bypassing traditional security vetting in favor of speed. Cisco Blogs
The result is a growing gap between what companies have deployed and what they actually govern. Only 12% of organizations have formal AI security testing programs, despite 78% having deployed AI in production. Governance has not kept pace with adoption. And the skills to close that gap are scarce: 95% of organizations report cybersecurity skills gaps, and 59% face critical or significant shortages of skilled security professionals. CybersecurityswitzerlandFortinet
What this means for builders
This is where the opportunity lies, and it is a significant one for anyone building security programs today.
For too long, security has been architected around a relatively stable set of assumptions: known perimeters, known assets, known identities. AI dismantles all three simultaneously. The attack surface now includes models, agents, pipelines, third-party integrations, and the data flowing between all of them. You cannot defend what you cannot see, and right now most organizations cannot see most of it.
That means security builders need to think differently about what they are actually building. Detection and response tooling designed for human-speed attacks is being outpaced by threats that move at machine speed. Organizations using AI and automation identify and contain breaches 98 days faster than those relying on manual methods, saving an average of $2.22 million per incident. The gap between teams that have rearchitected around this and those that have not is growing fast. Fortinet
It also means the role of the security builder is expanding. The people who will have the most impact in the next few years are not purely technical specialists working in isolation. They are engineers who understand policy, practitioners who can work across product and infrastructure, and leaders who can bring security into the design of AI systems before those systems ship, not after an incident forces a retrofit.
The organizations that treat AI as a capability to be governed rather than just a checkbox to be ticked will be the ones still standing in 5 years. Building that kind of program requires people who understand how AI systems fail as well as how they work, and who can build at the pace the business demands without sacrificing the fundamentals.
This is genuinely new territory and the playbooks are being written in real time, by people doing the work.
Come build with us
Builders & Breakers is not a conference you attend once a year and forget about. It is an ongoing conversation between the people actually doing this work: security builders and leaders living this reality every day, vendors building the next generation of tooling, and researchers working at the cutting edge of AI security.
Our goal is simple. We want to give you practical shortcuts. To filter the noise, talk to the people building and researching what is coming next, and translate that into things you can actually implement in your organization. Not theory or vendor pitches. Real signal on what matters and what does not.
We will keep the conversation going long after any single gathering: sharing what we learn, surfacing what is relevant, and helping you stay ahead of a landscape that is not slowing down.
The window is open. Hop on the ride with us.
Comments