Dispersive Blog

Machine-Speed Attacks Are an Architecture Problem

Written by Rajiv Pimplaskar | September 14, 2026

Kunjal Trivedi and I spent the other week in Las Vegas at CrowdStrike Fal.Con, alongside more than 10,000 practitioners from 71 countries. A couple of weeks on, one impression has outlasted the rest. The keynote was about AI. The hallway conversations were about something narrower and more useful. Nobody we met was arguing about whether AI changes the shape of an attack. That question is settled for practitioners. What they were asking, quietly and repeatedly, was whether the security investments they have already made will still be worth anything once it does. We did not meet many people with a confident answer.

AI Is Now In the Hands of Ordinary Adversaries

We sat in a hands-on Guardian session and watched it surface malicious developer activity in a live production environment in real time. It works, and it reinforced our view that CrowdStrike is executing well on the problem it has chosen.

George Kurtz framed the thesis on the mainstage: frontier AI capability has moved past nation-states into the hands of ordinary adversaries, attacks now run at machine speed, and AI systems are themselves a new surface that has to be defended. We agree with all three points. Our reading of the week is that detection and response are being rebuilt for machine speed, and the aggregation layer now wants telemetry from everything, not just the endpoint.

Everything Changed Except the Way Data Moves

Every advance on that stage operates on endpoints, identities, workloads, and the telemetry they produce. Detection got faster. Response got more autonomous. But the way data actually moves across the network has not changed.

An AI-enabled adversary that gets inside still finds what it found five years ago. Static routes. Predictable paths. Traffic that can be observed, correlated and targeted. Segmentation that holds right up until credentials are valid. Perimeter controls, firewalls included, were designed for human-paced intrusion, and industry commentary on their limits against automated lateral movement is getting blunter by the month. Machine-speed lateral movement across a transport layer that assumes it can be trusted is not fundamentally a detection problem. It is an architecture problem.

Detection is getting very good, very quickly. The network underneath it is still cooperating with the attacker.


Stealth and obfuscation at the transport layer are an additive, and necessary, defense. They reduce what an adversary can see, correlate and reach, which raises the value of every detection signal you already collect. Anyone who tells you their network layer removes the need for endpoint detection and response is selling you a gap, not a control.

Where Detection and Transport Should Meet

The most interesting forward-looking conversation we had all week was about signals. A transport layer that can act on identity and posture signals as they change, rather than only at session establishment, gives you continuous authorization instead of a one-time gate. That is precisely why we built our CrowdStrike Falcon integration, with Falcon serving as the live signal source behind it.

The logical next step is event-driven, standards-based signal exchange, so independent security products can publish and consume security events without bespoke integration work between every pair of vendors.

Urgency Is Not Evenly Distributed

One pattern worth naming. US organizations, particularly on the East and West Coasts, showed noticeably sharper concern about AI-enabled risk than their European and APJ counterparts, where the conversation leaned toward productivity gains. Different countries have different cultural and governmental relationships with AI, and enthusiasm and anxiety are not distributed the same way.

I would not read that as European or Asian organizations being wrong about the risk. I would read it as a timing difference. The gap will close, and it will close on the adversary’s schedule rather than anyone’s planning cycle. The first widely publicized breach that clearly involved machine-speed lateral movement will move that conversation everywhere at once. Architecture decisions made before that moment will be cheaper than the ones made after it.

Assume They Get In

If you spent last week watching AI-era detection get faster, the right follow-up question is not whether it will catch more. It will. The question is what your network does for the adversary in the minutes before it does.

Assume they get in. Then ask what your traffic reveals, who controls the path it takes, and what happens to it once it is captured and held for a decryption capability that does not exist yet. Every stack has an answer for the endpoint. Most assume somebody else is providing this layer.

Every era raises its own adversary. In the AI era, that adversary moves at machine speed, past static defenses and straight at the network. The only durable response is to remove what the adversary depends on seeing.

Dispersive® Stealth Networking operates post-authentication, alongside the detection and response you already run. Traffic is fragmented across dynamic, non-deterministic paths, so it cannot be correlated, intercepted or targeted. Operations continue under disruption rather than failing over. The customer controls the transport plane, with no external control-plane dependencies. And none of it requires replacing the infrastructure underneath it. If AI-era detection is moving at machine speed, the network architecture underneath it has to move first. 

Start With the Transport Layer

Dispersive® Stealth Networking operates post-authentication, alongside the detection and response you already run. Traffic is fragmented across dynamic, non-deterministic paths, so it cannot be observed, correlated or targeted. Operations continue under disruption rather than failing over. You control the transport plane, whether we operate it for you or you run it entirely yourself. Version 6.0 extends this to the AI communication layer, covering agent traffic, model inference calls and east-west data movement, with post-quantum cryptography across both the data plane and the control plane. None of it requires replacing the network underneath it.

📞 Book a consultation with Dispersive Stealth Networking: www.dispersive.io


Header image courtesy of mac231 from Pixabay.