Generative AI in Threat Exposure Management: Speed for Defenders, Guardrails for Everyone
- Muruganandam Venkatachalam, M.Sc Digital Business, University of Salford, UK

- Aug 6
- 4 min read
Introduction
Generative AI has gone from novelty to boardroom fixture in three years: 88 percent of organisations now use it regularly in at least one business function, up from 78 percent a year earlier (McKinsey & Company, 2025). Nowhere is that shift more consequential than in cybersecurity, where a discipline called threat exposure management is being reshaped by generative AI faster than almost any other corner of the business.
A discipline built to keep up with a moving target
Threat exposure management, formalised by Gartner as Continuous Threat Exposure Management (CTEM), continuously scopes, discovers, prioritises, validates and remediates the weaknesses most likely to be exploited, rather than patching every vulnerability a scanner reports (ArmorCode, 2026). The need is acute: connected assets were projected to reach 50 billion in 2025, and roughly 80 percent remain unseen or unmanaged by traditional tools (Armis, 2025). Point-in-time scans cannot keep pace with an attack surface that changes by the hour.
Where generative AI earns its keep
Generative AI closes that gap three ways. It unifies the flood of findings, deduplicating data from hundreds of disconnected tools and cutting review volume by as much as fifty to one (Armis, 2025). It reasons in natural language, turning walls of alerts into prioritised, plain-English summaries (Armis, 2025; Wiz, 2026). And it traces attack paths, combining exploitability, asset criticality, identity context and network reachability to compress ten thousand critical Common Vulnerabilities and Exposures (CVEs) into the dozen paths an attacker could realistically walk, a pattern that consistently shows around three percent of findings account for roughly eighty percent of real risk (ArmorCode, 2026; Wiz, 2026). AI agents now extend this further, drafting remediation guidance within minutes of disclosure (ArmorCode, 2026).
“The organisations getting real value are not the ones deploying AI fastest, but the ones treating human oversight as part of the system rather than a constraint on it.” |
The other side of the arms race
That speed is not optional. Attackers use the same tools to compress the gap between disclosure and exploitation: Google's Threat Intelligence Group reported the first AI-developed zero-day exploit, and found that 28.3 percent of disclosed CVEs are now exploited within 24 hours, a threshold that used to take weeks (Google Cloud, 2026). Armis Labs has separately tracked multiple state-affiliated groups using AI to accelerate reconnaissance and exploitation (Armis, 2025). Exposure management has become an arms race in which the faster reasoner wins.

Figure 1: Reported gains and risks of generative AI in threat exposure management (Armis, 2025; Google Cloud, 2026; McKinsey & Company, 2025; Wiz, 2026). Green bars are defensive gains; red bars are risk factors, showing that the same speed cuts both ways.
Red, blue, and purple teams, reinvented as continuous AI
Exposure management borrows useful vocabulary from elsewhere in security: red teams that simulate attackers, blue teams that defend, and purple teams that connect the two. That collaboration used to happen a few times a year and went stale quickly (InfoWorld, 2026). Generative AI makes it continuous: threat-intelligence-driven simulations mapped to frameworks such as MITRE ATT&CK now run automatically, often triggered by the same infrastructure changes that create new exposure (InfoWorld, 2026). Some platforms build this in as dedicated agents rather than human exercises: Wiz pairs a Red Agent that reasons like an attacker with a Blue Agent that validates real impact, logging every decision for review (Wiz, 2026). That is purple teaming compressed into a background process, exactly the validation CTEM calls for: not whether a finding is theoretically vulnerable, but whether an attacker could walk that path right now.
Using it ethically: Practices that matter
Using generative AI responsibly here is not a compliance afterthought; it is what keeps the technology trustworthy enough to act on. Keep a human in the loop for anything irreversible, including an AI agent reasoning like an attacker against production: changes, account lockouts, credential revocation and firewall rule changes should never execute on AI output alone (Wiz, 2026). Ground AI reasoning in real environmental data through retrieval-augmented approaches and dual verification, since adversarial prompts have demonstrated jailbreak success rates as high as 97 percent within a handful of turns (Wiz, 2026). Treat the organisation's own AI deployment as part of the attack surface it protects, since careless hosting or prompting can leak sensitive data (Wiz, 2026). Build for auditability: agentic recommendations should operate within pre-approved scopes with a transparent chain of thought (ArmorCode, 2026). The EU AI Act's high-risk obligations become fully applicable in August 2026, alongside frameworks such as the NIST AI Risk Management Framework and ISO 42001 (Wiz, 2026).
The deciding factor is discipline, not adoption speed
The same properties that make generative AI valuable, speed, pattern recognition and natural-language reasoning, are exactly what make it dangerous without guardrails. In a discipline where attackers already use AI to move faster, the question is not whether to adopt it, but whether to do so with the same discipline expected of any other system with the power to act on the business's behalf.
References (Harvard style)
Armis (2025) The age of generative AI in cyber exposure management. Available at: https://media.armis.com/wp-age-of-generative-ai-en.pdf (Accessed: 5 August 2026).
ArmorCode (2026) The ultimate guide to Continuous Threat Exposure Management (CTEM) in 2026. Available at: https://www.armorcode.com/learning-center/the-ultimate-guide-to-continuous-threat-exposure-management-ctem (Accessed: 5 August 2026).
Google Cloud (2026) Adversaries leverage AI for vulnerability exploitation, augmented operations, and initial access. Available at: https://cloud.google.com/blog/topics/threat-intelligence/ai-vulnerability-exploitation-initial-access (Accessed: 6 August 2026).
InfoWorld (2026) Using continuous purple teaming to protect fast-paced enterprise environments. Available at: https://www.infoworld.com/article/4166799/using-continuous-purple-teaming-to-protect-fast-paced-enterprise-environments.html (Accessed: 7 August 2026).
McKinsey & Company (2025) The state of AI in 2025: agents, innovation, and transformation. Available at: https://www.mckinsey.com/capabilities/quantumblack/our-insights/the-state-of-ai (Accessed: 6 August 2026).
Wiz (2026) Using generative AI for cybersecurity: a 6-phase practitioner's guide. Available at: https://www.wiz.io/academy/ai-security/generative-ai-for-cybersecurity (Accessed: 6 August 2026).


Comments