I remember the days when merely saying “AI” was enough to earn glares for bringing up such a taboo subject, almost equivalent to saying “Voldemort.” Now, AI is at the center of many people’s daily lives and certainly at the center of business operations. I find myself using AI for everyday tasks. Unfortunately for security teams, the bad guys are using it too.
AI is sitting in the middle of everything. It sits between employees and the tools they use every day, between developers and the code they write, between security teams and the alerts they triage, between vendors and the services they deliver, and between data and decisions. Increasingly, it is connected to the data that makes those decisions possible, including emails, documents, tickets, code, customer records, security findings, vendor information, documents, and more. This is hugely important: when AI becomes the middle layer and has access to so much of our data, it does not just create a productivity opportunity. It creates a trust problem.
One useful way to think about that trust problem is AI man-in-the-middle, or AI MITM.
What is AI man-in-the-middle?
Most people are familiar with the idea of a man-in-the-middle attack (i.e. when an attacker gets between two parties that think they are communicating directly). From there, they can intercept information, steal credentials, manipulate a transaction, or change the outcome.
AI MITM is not exactly the same thing, but the concept is similar. In this case, the “middle” might be an AI assistant, an agent, a plugin, an integration, or an AI-enabled vendor workflow. It is the system sitting between a person and an action, between a question and an answer, or between a business process and the data it depends on. This is where things get interesting. Or uncomfortable. Probably both.
AI tools are no longer just chatbots answering random questions. They are being connected to real systems: email, calendars, documents, ticketing platforms, code repositories, cloud environments, CRMs, security tools, vendor portals, and customer data. Once AI has access to those systems, it is participating in the workflow as opposed to just generating content. And when something participates in the workflow, security teams have to care about how it can be manipulated if it were to end up in the wrong hands.
A malicious prompt hidden in a document could influence what an AI assistant summarizes or shares. A compromised plugin could abuse permissions that were approved months ago and never revisited. An AI coding tool could read an attacker-controlled issue or package and suggest unsafe code. A vendor could add AI to a platform your company already uses, quietly changing how sensitive data is processed or shared.
This is not theoretical, science fiction, killer robots, or AI “going rogue.” It poses a very practical question: what happens when we put a powerful, connected, fast-moving intermediary between people, systems, and decisions, and then assume it can be trusted?
AI is also changing the attacker’s workflow
There is another side of this, too. AI is not just sitting in the middle of our workflows; it is also starting to sit in the middle of the attack itself. Threat actors can and are using AI to move faster through the messy parts of an attack, such as writing lures, adapting messages, triaging stolen data, identifying what is valuable, and deciding what to do next. AI allows attackers to take mass amounts of data and quickly sort through it to decide what is valuable in an attack. In other words, AI can become the attacker’s analyst. That sentence should make all of us pause for a second. Attackers are using AI in the same way we do, just with different goals.
It is also why Adversary-in-the-Middle, or AiTM, attacks matter here. AiTM phishing kits sit between the user and a legitimate service, often capturing session tokens after the user successfully completes many common forms of MFA. The attacker is not always trying to break into the endpoint first, rather they are trying to intercept trust after the user has already authenticated, allowing them to bypass MFA.
AI makes this broader trend more urgent. It can increase the speed and adaptability of attacks. For defenders, that compresses the timeline. The window between exposure, compromise, triage, and impact gets smaller.