AI has moved from enabling attackers to operating attacks, running live intrusions with minimal human direction, compressing the time defenders have to respond and opening new attack surfaces across an enterprise, even as companies adopt technology at a pace that outstrips that of governance controls.