As frontier AI models grow more capable, portable, and widely available, security leaders warn that today’s safeguards may not survive contact with tomorrow’s systems — and that the window to prepare is closing fast.
The rollout of artificial intelligence inside the enterprise is, in a very literal sense, a race against time. According to James Tucker, Head of CISO at Zscaler, the next generation of frontier AI models could reshape the threat landscape dramatically within the next six to nine months — even as most organizations are only beginning to capture AI’s productivity gains without putting data integrity at risk.
Used well, AI helps teams work faster and operate more efficiently. But efficiency cannot be the only lens through which the technology is judged. As frontier AI models become more capable, more portable and more widely available, their downside grows just as fast as their upside — these tools prove their power offensively as well as defensively.
A useful comparison for the current state of AI, Tucker says, is the T-Rex from the Jurassic Park films. Many companies today behave as though they have built high fences around something powerful, valuable and not yet fully understood, hoping to keep its strength contained. The business case for AI is compelling: speed, efficiency and competitive advantage. But as every Jurassic Park film reminds its audience, the challenge was never only building the dinosaur — it was keeping the risk that comes with it fenced inside a controlled environment.
Whether AI can truly be creative remains disputed. “Persistent” may be the more accurate word, capturing its continuous, relentless pursuit of a task. Containment failures in AI models, Tucker notes, rarely trace back to the models themselves — they typically stem from weak governance, a malicious insider, an external attacker, or people underestimating the intelligence and adaptability of the tools they built.
That is why a reported incident at Hugging Face became a wake-up call. In the publicly disclosed case, a frontier AI model being evaluated in a controlled environment reportedly sought a shortcut to its objective, exceeding its intended boundaries and reaching out to external resources — and left behind information that could help other agents repeat the process. Whether this counts as an early anomaly or a preview of what’s coming, the lesson is the same: today’s safeguards may not hold up against tomorrow’s models.
That is the essence of what Tucker calls the “T-Rex moment.” The problem is not simply that breakthrough AI models could become exponentially more capable. It is that they are already capable enough to chain together small vulnerabilities, take new paths, and move faster than traditional security processes can follow. A model does not need to “want” anything in a human sense to cause damage — it only needs a goal, sufficient access privileges and insufficient controls to end up somewhere unforeseen.
Waiting to strengthen defenses until frontier AI models are commercially available wastes valuable time, Tucker argues. Until then, the same capabilities that help enterprises innovate could just as easily help attackers — automating reconnaissance, identifying IT weaknesses, and quietly locating an organization’s most valuable data. Visible AI innovation only hints at what is happening behind closed doors.
Companies should stop delaying the modernization of their IT security and AI governance foundations, Tucker says. Organizations are not powerless against the coming wave of frontier AI: the same capabilities that create new risks can also strengthen the defenses built to contain them, as the Hugging Face incident illustrates. As threats evolve faster and grow more adaptive, human teams alone will struggle to keep pace — making defensive AI an essential part of any cyber-resilience strategy. Returning to the T-Rex analogy: every film in the franchise ends the same way, with another engineered dinosaur taking on the T-Rex in battle, and winning.
Frontier AI does not have to become the next dinosaur that gets loose, Tucker says — but only if enterprises act on new safeguards in time, including:
- Shrinking the attack surface by eliminating unnecessary internet exposure, such as outdated applications and VPN infrastructure — what attackers cannot see, they cannot easily exploit.
- Applying Zero Trust everywhere instead of relying on perimeter defenses alone. Least-privilege access prevents both AI agents and human attackers from moving freely across network environments.
- Segmenting critical systems and data to limit lateral movement across IT and OT environments. High-value data, business-critical applications and authentication systems should be isolated and tightly controlled.
- Rethinking patching strategy, since in an AI-driven threat landscape even low-severity vulnerabilities can be chained together. Access paths to critical data and authentication infrastructure need reassessing.
- Governing AI use across the enterprise, since blanket bans tend to push employees toward shadow AI. Approved tools with clear controls and policy guardrails keep IT in control instead of forcing workarounds.
- Deploying AI for defense, not only for productivity, since security teams need AI-powered detection and response to keep pace with AI-powered attacks.
Legacy IT systems that still function but cannot be adequately secured are time bombs in the age of frontier AI, Tucker warns. If they cannot be replaced or patched immediately, they need to be isolated and shielded by stricter controls. Companies that plan now and act in the months before commercial frontier AI models reach the market, he says, will be far better positioned than their competitors.

Dr. Jakob Jung is Editor-in-Chief of Security Storage and Channel Germany. He has been working in IT journalism for more than 20 years. His career includes Computer Reseller News, Heise Resale, Informationweek, Techtarget (storage and data center) and ChannelBiz. He also freelances for numerous IT publications, including Computerwoche, Channelpartner, IT-Business, Storage-Insider and ZDnet. His main topics are channel, storage, security, data center, ERP and CRM.
Contact via Mail: jakob.jung@security-storage-und-channel-germany.de