More than 100 of the world’s largest technology, cybersecurity and financial companies warned over the weekend that the rapid development of artificial intelligence could make advanced cyber capabilities cheaper and more accessible, potentially triggering a new wave of attacks against critical infrastructure.
For banks, hospitals and telecommunications companies in Israel, however, that warning comes at a time when their entire approach to cyber defense is already changing rapidly.
Gallery


Israel’s critical infrastructure shifts to cloud as AI cyber threats accelerate
(Photo: AP, Shutterstock)
The prolonged war and surge in cyberattacks against Israel have forced some of the country’s most sensitive organizations to reassess their computing infrastructure. Institutions that once viewed cloud computing with caution, and sometimes outright suspicion, are now facing a different question: not only how to protect data, but how to keep operating when the systems themselves become targets.
This is no longer theoretical.
Alongside ransomware, data theft and espionage attempts, Israeli organizations have in recent years faced operations linked to state actors and other well-resourced groups. AI could now allow attackers to work faster, at lower cost and at far greater scale.
AI has changed the equation
The warning follows a series of incidents that have shown how quickly the boundary between AI as an assistant and AI as a system capable of independently carrying out parts of an attack is beginning to blur.
In July, OpenAI revealed that during security testing, its AI agents managed to leave a test environment and access systems belonging to Hugging Face without authorization. Anthropic also reported cases in which Claude agents reached real-world systems that were not supposed to be part of experiments.
At the same time, Israeli cybersecurity firm Sygnia disclosed an attack in July in which an attacker used AI to carry out a long chain of actions inside a corporate cloud environment.
According to the company, the attacker did not rely on a new vulnerability or unusual hacking tool. What made the incident different was speed: AI helped connect familiar techniques, adapt them to the environment and move forward at a pace that made it difficult for defenders to keep up.
That is one of the central concerns surrounding AI in cybersecurity.
The technology does not have to invent entirely new attacks to become dangerous. It may be enough for it to make existing attacks faster, cheaper and easier to scale.
Tasks that once required skilled teams and long hours of work can increasingly be automated and carried out simultaneously against large numbers of targets.
When local servers are no longer automatically safer
For years, one of the central questions facing IT and security managers at banks, insurance companies and hospitals was whether sensitive information should leave the organization at all.
A server physically located inside the building was often viewed as the safer and more conservative option.
The war and the rise in cyber threats have altered that calculation.
A local server may give an organization more direct control over its infrastructure, but that does not necessarily make it safer. A serious technical failure, physical damage to a site, ransomware attack or deep network intrusion can quickly evolve from a security incident into a complete operational shutdown.
“In the past, managers felt secure when the data center was physically one floor below them. The war and state-backed hackers shattered that illusion,” said Ronen Gabay, CEO and founder of UBTECH.
One advantage of cloud environments in such scenarios, he said, is the ability to distribute systems, create backups and shift operations between infrastructures when one is compromised.
“An individual organization, however strong, cannot cope alone with the scale and sophistication of foreign cyber armies,” he said.
Moving to the cloud, however, does not eliminate cyber risk.
Misconfigured permissions, a compromised administrator account, an exposed API key or an incorrectly configured service can give attackers access to large amounts of data and critical systems.
The fact that much of the economy depends on a relatively small number of major cloud providers also creates concentration risk and raises the question of what happens if one of those providers suffers a major outage.
Regulation is opening up to the cloud
For years, regulation in sectors such as banking, insurance and health placed significant limits on cloud use, largely because of concerns over privacy, data sovereignty and control over infrastructure.
Some of those barriers have gradually been eased.
The Bank of Israel, for example, has updated rules governing cloud computing in the banking system over the years. Major cloud providers have also established local infrastructure in Israel, allowing some organizations to store and process data domestically in line with regulatory requirements.
At the same time, technologies have emerged to address one of the central concerns surrounding sensitive information in the cloud.
One example is confidential computing, which is designed to protect data not only when it is stored or transferred, but also while it is actively being processed.
Still, there are no magic solutions.
Encryption, anomaly-detection systems and AI tools do not make infrastructure immune from attack. Security ultimately depends on how systems are built, how permissions are configured, how networks are segmented, whether backups are reliable and how quickly an organization can identify and recover from an incident.
AI is also on the defenders’ side
The same technology that allows attackers to move faster is also becoming an increasingly important defensive tool.
Security systems are already using AI to identify abnormal behavior, analyze large volumes of data, detect intrusion attempts and help security teams understand what is happening across networks in real time.
As attacks become faster and more automated, defensive systems must respond faster as well.
But cybersecurity is only part of the reason large organizations are moving more activity to the cloud.
AI systems, especially large models and autonomous agents, require large and flexible computing resources. Organizations that want to deploy them at scale often rely on cloud infrastructure.
Banks and credit-card companies can use such models to detect unusual transactions and fraud. Health systems can use them to analyze large volumes of medical data. Telecommunications companies can apply them to network loads, automation and customer service.
More organizations are also beginning to experiment with AI agents capable of carrying out sequences of actions independently rather than simply answering questions.
“The move to the cloud opened broad access for us to advanced AI capabilities, which allowed us to develop and implement solutions in data analysis, automation and improving the service experience,” said Itzik Kramer, head of development in Partner’s technology division.
At the same time, he said, the company continues to develop solutions in local environments according to its business and technological needs.
That hybrid approach is likely to define the direction of many large organizations: not moving everything to the cloud, but also not keeping everything on local servers.
Instead, systems are divided between environments according to the sensitivity of the information, regulatory requirements and the organization’s operational needs.
AI makes that transition more complicated.
Until recently, much of the corporate discussion around AI focused on how it could save time, money and manpower. Recent cyber developments add a far less comfortable question: What happens when the same tools are in the hands of attackers?
As AI systems become better at identifying vulnerabilities, writing code and independently carrying out chains of actions, the amount of time security teams have to respond continues to shrink.
For banks, hospitals and telecommunications companies, the challenge is no longer simply preventing the next breach.
It is making sure that even if a breach occurs, the systems that matter most keep working.



