The people whose entire job is to protect your data from hackers have bigger budgets than ever, a ticking clock, and a clear and present threat. They have responded to this situation by being unable to make decisions. According to Axios, security leaders across major companies are so overwhelmed trying to figure out how bad AI-powered cyberattacks might get that they've essentially frozen up — right at the moment when experts say the window to act is closing fast.
The Clock Is Running. Nobody Is Moving.
Here's the setup: AI models capable of running end-to-end autonomous cyberattacks — the kind that don't need a human hacker sitting at a keyboard making decisions — are coming. Not in some distant sci-fi future. Soon. And the people paid to stop them are caught in a kind of collective deer-in-headlights situation that experts told Axios is actively dangerous.
The term being used is 'decision fatigue.' Which sounds clinical and almost sympathetic until you realize what it actually means: companies with expanded cybersecurity budgets, staffed with experienced security professionals, are sitting on their hands because they can't quite figure out how bad things are going to get. That is not a great answer when the threat is autonomous AI that does not share their hesitation.
What Autonomous Cyberattacks Actually Mean
Let's be specific about what's at stake, because 'AI-powered cyberattacks' can sound like vague tech-sector hand-wraving. It isn't. The scenario experts are describing to Axios involves AI models that can identify vulnerabilities, plan the attack, execute it, adapt when defenses push back, and exfiltrate data — all without a human pulling the strings in real time. That's a fundamentally different threat than the phishing emails and ransomware gangs companies have spent the last decade getting used to.
The old model of cyberattack has human bottlenecks. Hackers need time. They sleep. They make mistakes born from impatience or greed. Autonomous AI attacks have none of those weaknesses. They scale infinitely, they don't get tired, and they can probe thousands of systems simultaneously while your security team is still in a meeting about the Q3 threat assessment.
Four months after Anthropic released its model, according to Axios, security leaders are still in the 'sizing up' phase. The experts quoted in the piece are not being gentle about what that delay costs.
The Budget Isn't the Problem. The Paralysis Is.
What makes this particularly maddening is that the resources exist. Axios reports that many of these security leaders are operating with expanded budgets, specifically allocated to confront the AI threat. The money is there. The awareness is there. The problem is that the scale of the unknown has become so enormous that it's producing inaction rather than urgency.
Decision fatigue is a real psychological phenomenon, and it gets worse the higher the stakes feel. When every option carries existential risk, the brain's threat-response systems can start working against you, making it harder to commit to any path. That's a reasonable description of what's happening to individuals. Applied to corporate security infrastructure protecting millions of customers and billions in assets, it is a catastrophe in slow motion.
Experts told Axios that companies need to be 'taking bold action and mobilizing quickly.' The fact that this needs to be said out loud, to people whose job titles include the word 'security,' tells you something about the gap between where we are and where we need to be.
The Window Is Short and Nobody Agrees on How Short
One of the core problems driving the freeze, according to the Axios reporting, is that security leaders are genuinely struggling to size up the timeline. How long before autonomous attack-capable AI lands in the hands of malicious actors at scale? Six months? Eighteen? Is it already happening in targeted attacks on critical infrastructure? Nobody seems to have a confident answer, and that uncertainty is doing what uncertainty usually does: giving people an excuse to wait for more information.
But waiting for clarity on an exponentially developing technology is a trap. The nature of AI capability growth is that the jump from 'worrying' to 'catastrophic' can happen faster than a procurement cycle. By the time the timeline becomes obvious, the preparation window is already closed. Security experts understand this. The decision-makers above them, apparently, are still running the math.
The Industry That Cried Wolf (And Then the Wolf Showed Up)
Cybersecurity as an industry has a credibility problem that's partly of its own making. For years, vendors and consultants have sold escalating fear as a product. Every new threat was the big one. Every gap in your defenses was one click from total collapse. Companies learned, not unreasonably, to discount the alarm bells a little.
The problem is that those alarm bells eventually get calibrated to the wrong threat level. When the actual catastrophic, paradigm-shifting threat arrives, it arrives into a room full of people who've been professionally skeptical of catastrophic, paradigm-shifting threats for a decade. That's the environment AI-powered autonomous attacks are walking into. The boy-who-cried-wolf effect may be part of what's keeping security chiefs from acting with appropriate speed.
Axios notes this is happening at major companies — not scrappy startups without dedicated security infrastructure. These are organizations with the resources and institutional knowledge to respond. The failure here isn't one of capacity. It's one of will, timing, and organizational decisiveness.
The Dingo Take
You are supposed to believe that the people running cybersecurity at major corporations — people who have studied this field, who read the same research you don't, who get paid handsomely to think about exactly this kind of threat — just need a little more time to assess the situation. That the right response to a closing window of preparation is to stay in the assessment phase a bit longer. That 'decision fatigue' is an explanation rather than an indictment.
It is an indictment. The function of a security apparatus is not to perfectly understand a threat before acting. It is to act proportionally to the risk as it develops, even with incomplete information. Every military, every emergency response system, every competent institution on the planet operates on this principle. What Axios is describing is senior professionals collecting paychecks to make hard calls under uncertainty, and then not making the calls. If your budget is expanded and your mandate is clear and your window is closing, the decision fatigue is the emergency.
The attackers using these tools will not be fatigued. They will not be waiting for a better picture of the threat environment. They will not be scheduling a follow-up meeting to finalize the response framework. The asymmetry here is not subtle, and the executives frozen at their desks should understand that the breach report they're eventually going to have to write to customers will not benefit from the extra time they spent deciding whether to act.
Comments