AI is learning to hack. Now what?

Thema:
Cybersecurity
29 September 2026

The question is no longer whether AI can hack, but what this means for cyber defence. AI is making cyberattacks faster, cheaper and more autonomous. That is why TNO, NS and ten other frontrunners are working together within the Prometheus initiative on shared, market-neutral capabilities that automatically identify vulnerabilities at Dutch organisations and help remediate them.

The rise of autonomous AI agents

Recent developments show that AI models are operating with increasing autonomy. During a security test, OpenAI models explored an external AI platform without human direction, while Anthropic demonstrated how effectively AI can identify software vulnerabilities. At the same time, Dutch security services warn that AI is not only accelerating cyberattacks, but also increasing their scale and complexity. This further amplifies their potential impact on government, businesses and critical infrastructure.

For TNO, these developments mark a new phase in cybersecurity. ‘They raise the same question for many organisations,’ says Michiel van der Veen, Business Director Cybersecurity at TNO. ‘How do we respond?’

Bram Poppink

‘The time between a vulnerability becoming known and being exploited has fallen to almost zero.’

Bram Poppink

AI Security Expert at TNO

Cyber defence must accelerate too

According to Bram Poppink, AI Security Expert at TNO, the answer starts with accelerating cyber defence. ‘AI has now surpassed humans in nine out of the ten tasks typically performed by a hacker,’ he says. The biggest shift is the speed at which attackers exploit vulnerabilities. ‘The time between a vulnerability becoming known and being exploited has fallen to almost zero,’ says Bram. Organisations must therefore accelerate and automate their patching processes to keep pace.

Using AI against AI

Attackers are already making extensive use of AI, while cyber defence is still lagging behind. ‘Attackers operate at machine speed, while defensive processes still largely operate at human speed,’ says Dimitri van Zantvliet, Director of Cybersecurity at Nederlandse Spoorwegen, which is working with TNO through Prometheus. The logical next step, in his view, is to also systematically deploy AI for defense. This is precisely what Prometheus is working to achieve.

What is Prometheus?

Prometheus is a public-private initiative involving twelve Dutch organisations and coordinated by Digital Holland. The partners jointly develop and test AI capabilities for cybersecurity, working closely with commercial providers and incorporating existing market solutions. One example is using AI to automatically identify and validate software vulnerabilities. This allows organisations to benefit from new AI technologies faster, without each organisation having to develop the same capabilities independently.

Which organisations are involved?

AISLE, Digital Holland, the Dutch Institute for Vulnerability Disclosure (DIVD), ESET, Hadrian, the National Cyber Security Centre (NCSC), the National Coordinator for Security and Counterterrorism (NCTV), Northwave Cybersecurity, Nederlandse Spoorwegen (NS), Schuberg Philis, Software Improvement Group (SIG), TNO and VUSec at Vrije Universiteit Amsterdam.

Dimitri van Zantvliet

‘Energy, water, healthcare, and logistics are highly interconnected, and a disruption in one sector quickly affects others.’

Dimitri van Zantvliet

Director of Cybersecurity at Nederlandse Spoorwegen

Critical sectors are interconnected

For organisations operating in critical sectors, cyber resilience is not just an internal concern. ‘Energy, water, healthcare, and logistics are highly interconnected, and a disruption in one sector quickly affects others.’ says Dimitri. The European NIS2 Directive therefore requires organisations in critical sectors to demonstrate that their cyber resilience is in order.

Sovereignty requires freedom of choice

Organisations that use AI for cyber defence must also consider their dependence on suppliers. Most of today’s most powerful AI models originate outside Europe. This is not necessarily a problem, but it does require a conscious decision. ‘Are you able to switch to another AI system at an acceptable cost and within an acceptable timeframe? That is the question that matters,’ says Michiel.

This prevents organisations from becoming locked into a single model or provider when circumstances change. Flexibility and portability are not secondary considerations. They are essential elements of a robust AI strategy.

Tools for secure AI

TNO is developing practical tools that help organisations deploy AI securely. Through AI Security Assessment and Risk Management, we assess how secure an AI model really is, particularly when it has been developed outside the EU. We also determine how organisations can implement it securely within their own infrastructure. ‘If you use AI to scan software deployed within Dutch critical infrastructure, you need to be certain that you are doing so securely,’ says Bram.

We then use AI red teaming to test whether the implementation is genuinely secure. For example, we analyse how easily attackers could manipulate a model for malicious purposes. Perhaps most importantly, we apply our knowledge and experience of secure-by-design AI, including the expertise gained through the development of GPT-NL, to train and fine-tune international AI models. This makes them safer to use for our specific purposes.

Michiel van der Veen

‘We bring companies with specific cybersecurity issues together with those building solutions, ensuring no one has to reinvent the wheel.’

Michiel van der Veen

Business Director Cybersecurity at TNO

Collaboration as an accelerator

TNO also contributes these tools to Prometheus, where organisations with different areas of expertise work together on this challenge. As a market-neutral organisation, TNO plays a connecting role. ‘We bring companies with specific cybersecurity issues together with those building solutions, ensuring no one has to reinvent the wheel.’ says Michiel.

A proof of concept for the Netherlands

Within Prometheus, TNO is leading a proof of concept that addresses three central questions:

  • Which existing AI models are sufficiently secure?
  • Which Dutch providers can host these models reliably and sustainably?
  • How can organisations use AI to identify their own vulnerabilities before attackers exploit them?

An opportunity to lead

Organisations that put an AI risk assessment on the boardroom agenda now and allocate the necessary budget can build a competitive advantage. ‘Organisations that can demonstrate that their products and services are more secure will gain an advantage over their competitors,’ says Michiel. Dimitri adds: ‘AI security is therefore not just a matter of risk management. It is also a strategic choice.’

Would you like to discover how your organisation can respond to AI-driven threats? Or are you looking for ways to put your own security to the test? Contact TNO.

Get inspired

32 resultaten, getoond 1 t/m 5

Seeing more without sharing more

Informatietype:
Insight
23 July 2026
The question is not whether information has value, but how to use that value without increasing your own vulnerability.

Cybersecurity

Informatietype:
Trending
18 June 2026

TNO Unboxed #6: the race against the quantum threat has already begun

Informatietype:
Insight
30 March 2026

Province Noord-Brabant, TNO and partners join forces on cybersecurity

Informatietype:
News
28 January 2026

Cybersecure AI

Informatietype:
Article