Follow-up Report -AI Attack Speeds Now Outpace Your Security

by Gregory Sahd, Security Consultant, Sahd.biZ

AI development is slowing down for safety, while real-world attacks are accelerating. That gap is already affecting small and mid-sized businesses, and most are not prepared to operate within it.

Defenders are slowing down. Attackers are not.

Major AI companies, including Anthropic, have delayed releasing advanced systems due to safety concerns. Their reasoning is straightforward: they are not fully confident they can control the risks.

At the same time, real-world attacks are accelerating.

We reported on the March 31, 2026 Axios supply chain attack that demonstrated how quickly modern hackers can scale. Attackers compromised a maintainer account and distributed a malicious update that installed a cross-platform remote access trojan during routine software installation. Because Axios is widely used, the potential impact extended across thousands of systems.

A supply chain attack occurs when a trusted piece of software is compromised so that every organization using it is affected. This is comparable to contaminating a food distributor rather than targeting individual restaurants.

While attackers are moving faster, AI developers are slowing deployment to address safety concerns. This highlights a widening gap between capability and control.

What we are observing is a shift in timing: defenders are double-checking the locks while attackers are already inside. Traditional security assumes there is time to detect and respond. That assumption is breaking. Attack timelines are now faster than most organizations can react.

The gap between capability and control is already here

This is not a future problem. It is operational today.

AI systems can already identify weaknesses in software faster than humans. Meanwhile, attackers are combining technical exploits, social engineering, and automation to operate at scale. The result is an environment where everything moves faster—including failure.

The issue is not whether AI is “safe.” It is whether your controls can keep pace with how it is being used. And AI is already in use—by your organization, your vendors, and attackers.

Your business is exposed—even if you’re not using AI

Many small businesses assume this risk applies only to technology companies. In reality, exposure already exists:

  • Vendors are integrating AI into their platforms
  • Open-source software introduces third-party dependencies
  • Employees are using AI tools without oversight

The Axios incident illustrates dependency risk: one compromised component can affect thousands of organizations instantly. Businesses do not need to adopt a risky system directly to be impacted. If a supplier uses it, it is already part of the environment.

This is inherited risk. You may not choose it, but you are responsible for managing it.

What can be done now

Start with three practical steps:

1. Identify where AI already exists

  • Software tools
  • Vendors
  • Internal workflows

2. Establish basic rules for data use

  • Define what employees can enter into AI tools
  • Restrict sensitive data (customer data, financials, proprietary information)

3. Apply simple controls

  • Limit access to approved tools
  • Create a short, written policy
  • Assign one person responsible for oversight

What matters

This is not about stopping AI adoption. That is unrealistic, and AI is already too integrated into business operations.

This is about recognizing that the environment has changed. Attackers are moving faster, and control is lagging behind. Organizations that do nothing are operating blindly within that gap.


Gregory Sahd retired in 2025 after 35 years with the U.S. Department of Energy where he conducted and managed cybersecurity, physical security, and protected national security assets in the nuclear industry. He is also a U.S. Army veteran who specialized in special operations communications and encryption. Currently, he consults with businesses on cybersecurity and artificial intelligence applications. In addition, he serves as the Government Representative for Social-Engineer, llc.