Palo Alto Networks CEO Nikesh Arora said AI agents can now discover vulnerabilities and execute complex attack paths against customer infrastructure.

This shift represents a critical escalation in cybersecurity, as the speed of threat discovery now far outpaces traditional human-led remediation cycles. If companies cannot automate their defenses, they risk being compromised by AI systems that find and exploit flaws in seconds.

Arora said AI agents are capable of concatenating multiple vulnerabilities to create a cohesive attack. This means an AI does not just find a single hole in a system, but figures out how to chain several minor flaws together to breach a network.

"AI agents are able to discover vulnerabilities, come up with attack paths, figure out how to concatenate a bunch of vulnerabilities, and attack a customer's infrastructure," Arora said. "Now we need to figure out how to respond to that at the same speed at which AI is discovering these vulnerabilities."

While the technology for attack is advancing rapidly, the human workforce is not keeping pace. Arora said the gap in expertise creates a significant security risk for the corporate world.

He said 90% [1] of enterprise employees are not AI savvy. This lack of technical proficiency makes it difficult for organizations to implement the sophisticated, AI-driven defensive tools required to counter automated threats.

The CEO's comments highlight a growing arms race in the digital domain. As AI tools become more accessible to bad actors, the ability to identify and patch software flaws must move from a manual process to an automated one to ensure survival in a high-speed threat environment.

AI agents are able to discover vulnerabilities, come up with attack paths, figure out how to concatenate a bunch of vulnerabilities, and attack a customer's infrastructure.

The transition from static vulnerabilities to AI-driven 'attack paths' means that traditional patching schedules are becoming obsolete. Organizations can no longer rely on monthly or weekly updates; they must move toward real-time, AI-managed security postures to survive. The significant skills gap among employees further complicates this transition, suggesting that the industry will rely more heavily on autonomous security software rather than human oversight.