AI and Cybersecurity: Weapon, Shield or Target?
- Jul 21
- 5 min read
Artificial Intelligence is not only changing how industrial companies design, manufacture and maintain products—it is also changing how they are attacked and how they defend themselves. Organizations that adopt AI without considering cybersecurity may close an efficiency gap while simultaneously opening a security gap.
AI has become an integral part of industrial value creation, from generative design and process automation to predictive maintenance. However, every AI system introduced into engineering, operations or products also changes the security landscape. AI and cybersecurity are no longer separate disciplines—they continuously influence one another.
The fundamental principle is simple: capability is symmetrical. The same capability that strengthens an attacker can also strengthen a defender and vice versa.
For engineering-driven industries, where failures can have physical and safety-critical consequences rather than simply causing software bugs, this creates a threefold challenge. AI becomes a weapon in the hands of attackers, a shield for defenders, and—once embedded into development processes or products—a target itself. Organizations that fail to distinguish these three dimensions risk implementing the wrong security measures.
Anatomy of a New Threat Landscape
Contrary to popular belief, AI does not invent entirely new cyberattacks. Instead, it industrializes existing ones. Expensive human expertise is increasingly replaced by inexpensive computing power.
The result is not a new class of attacks, but a dramatic increase in their volume, quality and scale.
In engineering environments, this primarily appears in three forms:
Deception Beyond Traditional Detection
AI enables perfectly written phishing emails and Business Email Compromise (BEC) attacks in virtually any language. Voice cloning and deepfake videos can convincingly impersonate executives, suppliers or trusted business partners.
Attacks at Machine Speed
AI agents can autonomously map networks, identify vulnerabilities and even generate exploit code—often faster than security teams can respond.
AI Becoming the Target
Once AI models are integrated into engineering workflows or products, they become attack surfaces themselves through prompt injection, poisoned training data or compromised software supply chains.
The barrier to sophisticated cyberattacks has therefore become significantly lower.
It is equally important, however, to recognize AI's current limitations. Today's models still hallucinate, fabricate facts and frequently overestimate their own success. Fully autonomous, reliable cyberattacks remain relatively rare.
The correct strategic response is therefore not to defend against today's snapshot—but against tomorrow's trend, assuming attacker capabilities will continue to improve.
Strategic Risks for Industrial Organizations
1. When Identity Can No Longer Be Trusted
Seeing and hearing are no longer reliable methods of authentication.
One of the most prominent examples occurred in 2024, when an employee of global engineering company Arup transferred approximately USD 25.6 million after participating in a video conference where every participant except himself was a deepfake—including the company's supposed Chief Financial Officer.
No systems were hacked.
No malware was installed.
The attack exploited a purely human assumption.
The lesson is clear: verification matters more than detection.
Automatic deepfake detection tools lose significant accuracy under real-world conditions, especially in live scenarios.
Effective protection is achieved through business processes rather than technology alone:
Call back using a verified phone number.
Apply the four-eyes principle.
Define mandatory approval thresholds for financial transactions.
2. When AI Becomes Part of Your Product
Once AI is embedded into software, products or engineering workflows, the risk shifts from "attacks against us" to "vulnerabilities inside what we build."
Prompt Injection
Ranked as the number one risk in the OWASP Top 10 for Large Language Model Applications, prompt injection manipulates an AI system by embedding malicious instructions into inputs.
These instructions may be hidden inside content the model is expected to process, such as websites, PDFs or emails.
There is currently no complete technical solution. Only layered security controls can reduce the risk.
Data Poisoning
Research published in 2025 demonstrated that roughly 250 carefully crafted documents can implant hidden backdoors into an AI model—largely independent of model size—which remain dormant until activated by a secret trigger.
Insecure AI-Generated Code and "Slopsquatting"
A considerable share of AI-generated code contains security vulnerabilities.
Independent studies have shown that approximately one in five AI coding recommendations references software packages that do not actually exist.
Attackers register these fictitious package names with malicious code, causing unsuspecting developers to install malware.
The rule is straightforward:
AI-generated code should always be treated as untrusted third-party software and undergo the same rigorous review as any external dependency.
3. The Liability Question
The EU AI Act (Regulation (EU) 2024/1689) assigns responsibilities according to organizational roles—a distinction often overlooked in practice.
The Provider develops the AI system and carries the most extensive legal obligations.
The Deployer implements and operates the system under its own responsibility.
The User simply interacts with its outputs.
A common misconception arises when companies customize, fine-tune or rebrand third-party AI models. In many situations, they legally become the Provider, inheriting all associated documentation, conformity assessment and compliance obligations.
Legal classification depends on facts—not contractual wording.
In addition, Article 4 of the AI Act introduces a universal requirement for AI literacy: anyone working with AI systems must possess appropriate knowledge and training.
From Restriction to Enablement
Blanket bans on AI are ineffective.
They simply encourage employees to adopt unauthorized "shadow AI" solutions.
Leadership must therefore move beyond a purely defensive mindset and instead focus on strategic enablement.
The symmetry principle applies equally to defenders.
AI helps overwhelmed security teams prioritize alerts, correlate weak signals into meaningful attack patterns and accelerate incident response.
Yet this does not create a permanent competitive advantage.
The real differentiator remains what AI cannot provide by itself:
Robust processes
Independent verification
Effective governance
Skilled people
Defense in Depth
Effective cybersecurity requires multiple layers of protection.
No single control can completely eliminate risks such as prompt injection or data poisoning.
Organizations should therefore implement several complementary safeguards:
Verify Rather Than Trust
High-impact actions—including payments, access changes and system configurations—should always be confirmed through an independent communication channel.
Human-in-the-Loop
A qualified person must remain responsible for safety-critical calculations and decisions.
AI should support human judgment—not replace it.
Zero Trust for Inputs and Outputs
Treat all AI inputs and outputs as potentially untrusted.
Isolate external content, enforce least-privilege permissions for AI agents and validate generated outputs before further processing.
Governance That Keeps Pace with Innovation
Governance frameworks must evolve as quickly as AI adoption.
Four principles are particularly important for industrial organizations:
Role Clarity
Document whether your organization acts as the Provider or the Deployer for every AI system.
Responsibilities, compliance obligations and security controls depend on this distinction.
AI Literacy
Provide mandatory training covering real-world AI risks—from deepfake fraud to prompt injection and AI supply chain attacks.
Verification and Red Teaming
Every AI-generated technical output should undergo the same rigorous review as human-generated work.
Internal AI models and pipelines should be actively attacked and tested before adversaries do.
AI Supply Chain Hygiene
Verify the origin of AI models and datasets, maintain an AI Bill of Materials (AI-BOM) and validate dependencies before deployment.
Make Cybersecurity the Foundation of Your AI Strategy
Implementing AI is not merely an efficiency initiative—it is a security decision.
The good news is that capability is symmetrical. Sustainable competitive advantage does not come from having the most powerful AI model, but from building the strongest governance around it.
At cross-ING, we combine state-of-the-art AI capabilities with the stringent cybersecurity and compliance requirements of industrial engineering—from threat analysis and secure AI architecture to governance frameworks and workforce training.
Don't let your AI initiative become your organization's weakest link.
Would you like to build a secure, compliant AI framework for your engineering workflows?
Get in touch with our AI specialists at ai@cross-ing.ch.
Would you like to explore the topic in more detail?
Book an expert consultation today and receive tailored advice from our specialists.
Want to learn more about the AI Competence Center at cross-ING?
Discover how our interdisciplinary team solves complex engineering challenges and develops secure, future-ready AI solutions..




Comments