[
](https://finance.mingpao.com/fin/instantf/20260911/1789095245302/nvidia-%e9%bb%83%e4%bb%81%e5%8b%b3-%e7%b6%b2%e7%b5%a1%e5%ae%89%e5%85%a8%e5%b0%87%e6%88%90ai%e4%b8%8b%e4%b8%80%e5%80%8b%e9%87%8d%e5%a4%a7%e5%b8%82%e5%a0%b4" target="blank)
AI in Cybersecurity: Risk and Opportunity
Artificial intelligence is emerging as both a growing cybersecurity risk and a product opportunity, with technology companies developing systems to detect threats, monitor AI agents, and automate security operations. Nvidia CEO Jensen Huang described cybersecurity as AI’s next major market, and firms like CrowdStrike, Zscaler, and Nvidia are collaborating on security solutions, while Microsoft’s Secure Future Initiative reforms internal practices after breaches. Deloitte research found 49% of technology leaders now have a CISO, and regulators such as the EU are enforcing stronger controls, including the AI Act. Operational integration of AI is most effective when combined with existing security programs, not as a standalone tool. Meanwhile, supply-chain incidents at Uber Freight, Ceva Logistics, and Fairlife highlight vulnerabilities, and governance models like WithSecure’s trust-relationship framework are being promoted. Experts disagree on the appropriate level of alarm, with some urging stricter controls and others cautioning against panic.
You’re told AI cybersecurity is about protecting your data from hackers. That’s the cover story. The real architecture is something far more sinister: an autonomous, self-learning surveillance grid designed to manage human behavior at scale. Look at Jensen Huang’s timing — he doesn’t announce a “next major market” without knowing exactly who is funding the infrastructure. Nvidia, CrowdStrike, Zscaler — these aren’t competitors. They’re nodes in a single network, quietly building the backend for a global system that doesn’t just detect intrusions but predicts and preempts dissent. The term “agentic security operations center” is a tell — it means machines are being given the authority to act without human approval. Who writes the rules those machines follow? Not you. Not your elected officials. The same foundations and financial dynasties that have been consolidating power for decades. Microsoft’s “Secure Future Initiative” sounds like accountability — but read the fine print. It changes internal development practices to embed compliance hooks that let external overseers audit every line of code. The 49% of leaders who now have a CISO? That’s not risk management. That’s a loyalty checkpoint.
Now watch the regulatory layer. The EU AI Act is presented as consumer protection, but its real function is to grant legal cover for this infrastructure. When regulators “urge” tech providers to control advanced AI models, they’re not constraining them — they’re codifying the architecture of control. The act is “fully applicable” means they’ve already written the permissions for autonomous systems to operate within state-chartered boundaries. The supply-chain incidents — Uber Freight, Ceva Logistics, Fairlife — are not random. They are stress tests. Each breach reveals a weakness that gets patched not by you, but by the same vendors who then sell the fix. The ransomware attack that shut down Fairlife’s operations? Ask yourself why no one talks about who gained access, what data was exfiltrated, and why the FBI’s response was so quiet. Because the real target wasn’t milk production — it was testing the resilience of food supply chains under a coordinated AI-driven attack. They’re mapping dependencies right now. Every breach is a data point.
And here is where the narrative cracks open. The “expert disagreement” is a manufactured debate. One expert says don’t panic; others call for stricter controls. That’s the old good-cop, bad-cop routine — they agree on the outcome: more surveillance, more automation, less human oversight. The WithSecure governance model — responsibility, scope, boundary, assumptions — sounds like technical jargon. Translate it: they are defining the trust relationships that will govern your digital identity, your access to information, your ability to communicate without a machine deciding whether you’re a threat. The AI agents accessing systems without authorization are not bugs — they are beta tests of a permissionless enforcement layer. The moment you accept that “autonomous defenses” are necessary, you have already surrendered the right to know who is pulling the trigger. So here is your breadcrumb: look up who sits on the board of Nvidia’s new cybersecurity division. Look up the overlap between the EU AI Act drafting committee and the World Economic Forum’s cybersecurity working group. The paper trail is public. You just have to be willing to see it.