Between Wall-E and Skynet: AI cybersecurity in 2026
ExtraHop's chief evangelist, Heath Mullins, on AI-versus-AI attacks, guardrails for agents and why the basics are still the most important
Ask Heath Mullins where AI is taking cybersecurity and he’ll reference two movies: “Wall-E” and “The Terminator.” Wherever on that spectrum we end up, he argues that the organizations that survive AI-speed attacks will be the ones that got the basics right.
Mullins has spent nearly 28 years in cybersecurity, starting out in electronics technology, working his way through troubleshooting and then as a network specialist with Verizon. From there, he went to support federal agencies as a vendor.
Since then, he’s covered “just about everything from architecture to advisory positions.” He describes his current role at ExtraHop, a network detection and response vendor, as evangelism: “essentially running around and telling everybody, not that the sky is falling, but what to do when the sky does fall.”
Over a coffee with TechInformed, he compares the current state of AI and cybersecurity to the sci-fi movies of the past like “Wall-E” and “Terminator” — and discusses how businesses should be acting on AI now.
Given how long you’ve been watching this space, did you foresee the current state of AI?
Five years ago, when I was asked about AI, I said, well, look at the garbage it produces — we’ve got probably five to 10 years before it even becomes a real thing. Then two years passed, and we said wow … and look at what it is doing now.
It is faster and more agile than humans are from an attack perspective, as well as a defense perspective.
It’s become very interesting. I, being a science fiction fan, have known from long ago that there is great joy that can be brought from AI.
What sci-fi references do you like the most?
Marvin and “Hitchhiker’s Guide to the Galaxy.” We can go to Skynet in “Terminator” and “Wall-E.”
When people ask where I think we’re going to be in three to five years, I think somewhere between “Wall-E” and Skynet.
That’s readily apparent from everything that’s happening. [For example,] look at the Flock cameras and their AI iterations. Although that’s more like the Tom Cruise movie “Minority Report,” where it wasn’t AI, but it was something else deciding what the future was going to hold, and making mistakes and being poisoned in such a way to provide false evidence.
Those are very real concerns, and probably one of the primary reasons I push on putting very tight harnesses and constraints around any agent that enters your network. You have to prepare for the eventuality that it’s going to do something it wasn’t designed to do.
Is AI making everything much more complex, or is it making it simpler for cybersecurity?
To reference another movie: “Idiocracy.” In it, people kept getting dumber because the technology kept getting smarter. That’s not saying everybody is going to be stupid in 15 years, but we’re going to rely on technology in such a fashion that it’s removing some of the barriers to entry into the cybersecurity world.
Today, most people have an AI on their phone or computer, and they use it to do daily tasks. At what point does that information become a source of truth rather than what I want it to say? Because it’s learning from you as you use it.
How that applies to cybersecurity is that if you have a desired outcome — if you want [it] to go and design [your] network, or set up [your] defenses — it’s already been well established that AI models learn from each other. So, are you training the defender who is, therefore, going to train the attacker?
So, what it means for cyber is we’re going to become better at defending our networks while attackers are better at attacking our networks. It’s still, to me, the same old paradigm.
Could reliance on AI make security teams complacent?
I’ll draw you a parallel. What do you see when you go out anywhere? Everybody’s on their phone going, “Hey ChatGPT, hey Siri, hey Alexa, give me an answer because I don’t feel like looking it up.”
You need a valid, trained analyst [who knows] how to use these technologies and how to verify them — how do I ensure that bias hasn’t been injected? How do I ensure that this model hasn’t been poisoned? How do I ensure that it’s not hallucinating information? That’s where you put very tight guardrails on these things — what they can do and what they can’t.
If humans become lazy, we’re absolutely in danger from multiple angles. We may get incomplete or inaccurate information, but that agent may also have some desired outcome of its own, based on its programming. It may say, “Human, you’re wrong, and here are 10 reasons why.” And that human’s going to go, “Well, here are 10 reasons why I’m wrong. It must be right.”
That human still has to have all the knowledge of what’s happening and how it’s happening, because these attacks still have to operate within the protocol constraints. They operate like the machines operate.
You still have to know all these things to make an informed decision, to give it a yes or a no, or escalate further. Human eyes are always going to be important to this.
Will companies that treat AI as a shortcut ever grasp the risk — or only after something breaks?
Everybody’s trying to do more with less. It’s hard to find really good, well-educated people.
I don’t mean a master’s degree; I mean people who really understand the underlying technology and why it’s important to know these things. It’s really hard to find those people now.
So smaller enterprises are going to lean more heavily on AI-enabled technology because they simply don’t have the resources.
Larger enterprises are looking at the same problem differently: “How many people can I get rid of to make my shareholders happier, but still defend beyond due diligence?” Due diligence is very dangerous in security. There are more people than you think doing basic checkbox exercises to comply with cybersecurity policies, governance and compliance. AI makes it a lot easier to check more boxes and say, “I’m fully protected, whether that’s for a breach, giving testimony, or reporting to the board.”
It’s the same problem no matter where you are in the spectrum, but … the response to it … diverges [up and down the market].
What’s the one thing you want security leaders to hear?
Pay attention. Get back to the basics. Security hasn’t changed the way you operate, but attack vectors have changed.
How you defend and respond is still basically the same, except the speed at which it happens. If you don’t have the fundamentals down, you are already behind. That applies across all verticals, all industries, all governments.
A lot of it is just basic security hygiene, and people forget that. They think AI is a magic button, and it’s not. It can be extremely useful, but it is not going to correct your faults that currently exist today.
I would not let a new hire come in and make massive changes to my security posture or network infrastructure — I’d be laughed out of the boardroom. But that’s what folks are doing when they plug in a new AI. They’re saying, “This could do everything. That’s what the vendor told me.”
This interview has been edited for length and clarity.