Google's Threat Intelligence Group (GTIG) warns that AI is enabling cybercriminals and nation-state actors to automate and massively scale their attacks, with some threat actors building and executing full credential-harvesting campaigns in under six hours. Both financially motivated criminals and state-sponsored groups from countries like China, Iran, and North Korea are leveraging AI across the entire attack lifecycle — from reconnaissance and malware development to social engineering and influence operations. While Google actively disrupts these adversarial operations and hardens its own models against misuse, the fundamental dynamic mirrors longstanding cybersecurity challenges, with AI simply adding greater speed, scale, and complexity to an enduring arms race.