Artificial intelligence is helping attackers find vulnerabilities and exploit them faster, putting pressure on organizations to speed up patching and security response, according to Amazon Web Services (AWS).
At a virtual media briefing on Sept. 15, Bryce Boland, AWS head of security solution architecture for Asia Pacific and Japan, identified three challenges for enterprises: slow patching, risk management processes built around human response times, and compliance practices that may struggle to keep pace with changing AI risks.
Citing Verizon’s 2026 Data Breach Investigations Report, Boland said attackers could exploit a vulnerability within hours, while enterprise patching took an average of 32 to 43 days.
He also said organizations faced 50% more critical vulnerabilities to patch in this year’s reporting dataset than in 2025.
“When the speed and scale are fundamentally different, the risk management processes based on historical methods may no longer hold,” Boland said.
He added that organizations need to review their compliance practices as security frameworks evolve to address AI-related risks.
“The biggest challenge posed by high performance AI threats is that the attacks are becoming faster and more numerous. Enterprises need tools that respond at machine speed. And AI has to be part of the answer,” Boland said.
AWS pointed to threat intelligence systems built into its services. Boland said Mithra, a model that assesses the trustworthiness of internet domains, examines 1 trillion DNS requests and detects roughly 124,000 new malicious domains a day.
He said Madpot observes more than 750 million threats and detects 400 million malicious activities daily, while Sonaris analyzes network traffic to identify and block malicious attempts.
Boland also discussed AWS Continuum, which includes automated application security reviews and penetration testing. AWS said its penetration testing capability is generally available and has helped customers reduce testing timelines from weeks to hours.
Security design review, code review, and threat modeling capabilities remain in preview. AWS announced Continuum in June as the successor to AWS Security Agent.
Boland cautioned that automation alone would not address the problem.
“Pretty much every organization right now is pushing to modernize and automate their patching, but what we would suggest is that simply buying a tool is probably not the right strategy. You need to also think about architecture and process,” he said.
For AI agents that can access company data and act autonomously, AWS recommends secure development practices, limited access privileges, external controls, and evaluations before granting greater autonomy.


