Cybersecurity in the Age of AI
Download resourcesAbout this session
A Palo Alto Networks speaker (heard through a live English interpretation of an originally French keynote) traces AI in security from 1950s machine-learning roots to today's generative AI, arguing the field has not found smarter algorithms so much as more data to train on. He warns that employees are adopting unapproved generative AI tools at scale, creating shadow-AI blind spots where meeting transcription plugins and chatbots move confidential company data through unvalidated third-party models, and that prompt injection is now considered one of the biggest emerging threats. He calls for securing AI by design across the whole application lifecycle: gain visibility into which AI apps and plugins are in use, validate data flowing in and out of models, set policy on what may be uploaded to external tools like ChatGPT versus internally hosted models, and reduce the attack surface exposed to third parties. The back half quantifies how AI is compressing attacker timelines, citing drops from roughly nine days to under a day for data exfiltration and from nine weeks to about a week for vulnerability exploitation, projecting further shrinkage by 2026, and argues defenders need real-time monitoring and largely automated response to keep pace.
The scale, sophistication and speed of today’s threats is startling; just about every version would surprise most organizations. Compounding the problem: attackers are just getting started with AI. How can organizations protect themselves without hindering their mission? In this session, we will unpack exactly what this new threat landscape demands: an AI-backed high-powered innovation engine and a unique type of platform approach.
Key takeaways
- Inventory which generative AI tools and plugins employees actually use before writing policy; visibility is the first control, not an afterthought.
- Block or restrict uploading confidential, financial or personal documents to public generative AI tools such as ChatGPT; use internally hosted models for sensitive data instead.
- Treat prompt injection as a top-tier emerging threat category for any application that embeds a generative AI feature, not a theoretical risk.
- Validate data entering and leaving every AI plugin integrated into meeting tools (Zoom, Teams) and business apps (Salesforce); many are deployed without that check today.
- Plan for shrinking attacker timelines: exfiltration and exploitation windows are already measured in hours rather than days or weeks, so response needs to become largely automated.
Speakers

With over 15 years of experience, Xavier has made a significant impact on the cybersecurity industry. As a leader of technical teams at Palo Alto Networks and a prominent evangelist in the field, he has consistently driven innovation and strategy… Read moreRead less
With over 15 years of experience, Xavier has made a significant impact on the cybersecurity industry. As a leader of technical teams at Palo Alto Networks and a prominent evangelist in the field, he has consistently driven innovation and strategy. His international expertise has allowed him to assist companies around the globe in tackling complex cybersecurity challenges. A respected public speaker and advisor, Xavier has shared his knowledge at numerous conferences, helping to educate and guide professionals on evolving threats, industry trends, and best practices.
