One of Norway's largest telecoms operators is sounding the alarm. Telenor warns that artificial intelligence is not merely a tool for defenders — it is fast becoming attackers' most powerful weapon. The company told Digi.no that the situation is demanding for both businesses and individuals alike, and that digital preparedness must be significantly strengthened.

Three hours from disclosure to attack

The figure that perhaps best captures the severity is stark: according to security research, the window between a vulnerability becoming publicly known and the first confirmed exploit in the wild has shrunk from ten months to just three hours. At the same time, organizations take an average of 243 days to patch known flaws.

This asymmetry is precisely what AI-driven attack tools exploit. Automated scanning and exploitation of known weaknesses has received a massive boost, and the number of registered vulnerabilities — so-called CVEs — rose by more than 20 percent from 2024 to 2025, reaching a total of 48,185 recorded cases.

3 hours
From disclosure to first attack
243 days
Average patch time
87 %
Orgs. hit by AI attacks in 2025
Telenor warns: AI puts the next cyberattack just three hours away - Bilde 1

AI phishing outperforms traditional methods

It is not only technical vulnerability exploitation that has received an AI boost. AI-generated phishing campaigns now achieve a click-through rate of 54 percent, compared with just 12 percent for traditional attempts, according to security research. This means attackers can, with far less effort, trick far more victims into clicking malicious links or sharing sensitive information.

Verizon's research found that exploitation of vulnerabilities nearly tripled as an entry vector, now accounting for 14 percent of all data breaches.

No doubt it is extremely demanding — Telenor to Digi.no

Defenders fight back with the same tools

But AI is not only a threat — it is also defenders' most important new weapon. Next-generation security platforms use machine learning to continuously monitor network traffic, detect anomalies, and prioritize alerts in real time. AI-driven systems can, according to research, block around 95 percent of phishing attacks and reduce response times by between 35 and 60 percent.

Organizations that adopt such automation at scale report average savings of $1.9 million per security breach and a breach lifecycle shortened by around 80 days compared with manual handling.

The human element remains essential

Despite the impressive figures for AI-powered defense, the security community points to an important limitation. SANS instructor and incident responder Matt Bromiley notes that security personnel are comfortable letting AI classify threats and prioritize vulnerabilities, but are far more reluctant to allow systems to confirm real incidents or assess behavioral anomalies on their own.

This underscores that AI currently works best as an amplifier for human analysts — not as a replacement for them.

AI makes it easier to attack and easier to defend — but defenders must act faster than ever before.

Telenor's call to action: sharpen your defenses

Telenor stressed to Digi.no that the challenge is not some hypothetical future risk, but an ongoing reality. The company believes responsibility rests with both businesses and private individuals, and that the threshold for investing in up-to-date security measures must be lowered.

With a global AI security market that analysts project will reach $136 billion by 2032, it is clear that the industry is taking the threat seriously. The question is whether Norwegian businesses are keeping pace.