AI security in the age of agents: Is the threat real or overhyped?

Two panelists. Two very different answers. That was the security segment of the Dropsolid x Beltug event in Ghent, where Cyril Guilloret and Roeland Delrue disagreed openly, and productively, about just how seriously organizations should be taking AI-driven security risk.

"The vulnerabilities were already there"

Cyril Guilloret's position was measured. In his view, the fragilities that make organizations vulnerable today were already present before AI entered the picture, AI hasn't invented new categories of weakness, it's simply accelerated how quickly existing ones get found and exploited.

His practical conclusion: testing that used to happen occasionally now needs to happen continuously, and patching that used to happen on a comfortable cycle now needs to happen faster. The discipline required has intensified, but the underlying risk profile, in his assessment, hasn't fundamentally changed in kind, only in speed.

"Nobody is ready for this scale"

Roeland Delrue, co-founder of the cybersecurity company Aikido, pushed back hard. In his view, AI-driven security threats have industrialized at a scale the industry has never dealt with before, and most organizations' patching cycles, many still running on a monthly cadence, have effectively been rendered obsolete by the speed at which AI-assisted attackers can now find and exploit vulnerabilities.

But Delrue's most pointed comment wasn't about attackers, it was about the security industry's own incentives. He suggested that some of the loudest voices warning about AI existential risk have a strong commercial interest in generating exactly that fear, pointing to the scale of PR effort some AI labs invest in shaping the public narrative around their own models.

His view was that recent, well-publicized regulatory disruptions to frontier model access function as remarkably effective marketing, creating scarcity and mystique around a product ahead of a public offering. That's not to say he dismissed the underlying technology's capability.

He described conversations with people who'd had hands-on access to some of the most capable models available, who found them roughly comparable in effectiveness to other frontier systems already in wide use, powerful, but not categorically unlike what's already out there.

Attackers have it, but so do defenders

Where Delrue was most constructive was in reframing the security conversation away from fear and toward capability. His argument: yes, AI gives attackers new tools, but it gives defenders the exact same tools, and defenders start from a structural advantage, they already have the context.

A raw AI model becomes genuinely powerful only once it's wrapped in a harness: fed the right context, given the right constraints, and integrated into a workflow that understands the specific system being defended. An organization that builds that harness well can outperform an unsupported, more "powerful" model used without any of that surrounding infrastructure.

He backed this up with Aikido's own numbers. Since launching an AI-powered penetration testing product roughly ten months prior, the company had found that in 95% of cases, their AI system uncovered more issues than a traditional human penetration test, faster, and at meaningfully higher volume, having run more than a thousand tests since launch.

It's become the company's fastest-growing product line, and a clear signal that an industry long considered inherently protected by its reliance on skilled human testers is now being disrupted at real speed.

What AI doesn't change

Delrue made an important clarifying point that cuts through some of the hype on both sides: AI doesn't invent fundamentally new categories of attack. It's still finding injection flaws, cross-site scripting issues, and other well-understood vulnerability classes, it's just far faster and more thorough at finding them than manual methods ever were.

His conclusion was: most successful attacks still come down to organizations neglecting the basics, things as simple as two-factor authentication not being enabled everywhere it should be. AI accelerates the consequences of neglecting fundamentals; it doesn't replace the need to get fundamentals right in the first place.

 

 

Where the disagreement actually lands

Strip away the framing differences, and Guilloret and Delrue weren't as far apart as the debate initially suggested. Both agreed the threat surface and the pace of exploitation have genuinely changed.

Where they diverged was on how much of the current alarm is proportionate versus shaped by commercial incentives on the vendor and lab side, and on whether existing organizational security practices can reasonably keep pace, or whether they need a fundamental overhaul.

The takeaway

For most organizations, the practical guidance from this panel converges regardless of which side of the debate you find more persuasive: patch faster than you used to, treat testing as continuous rather than periodic, don't skip the basics in pursuit of more sophisticated defenses, and, if you have the resources to do so, turn AI's capabilities toward your own defense rather than treating it purely as a threat to defend against. The fire is real either way.

The question this panel leaves open is simply how much of it is being deliberately fanned.

See it live