Open-source AI models pose greatest security threat: Meerah Rajavel

Cheap open-source AI models could widen the cyberattack threat as adversaries gain access to powerful tools without the cost of frontier models

Meerah Rajavel, chief information officer (CIO) at Palo Alto Networks
Meerah Rajavel, chief information officer (CIO) at Palo Alto Networks
Avik Das
4 min read Last Updated : Aug 30 2026 | 9:51 PM IST
The greatest threat to cybersecurity comes from inexpensive open-source artificial intelligence (AI) models and not the frontier versions, says Meerah Rajavel, chief information officer (CIO) at Palo Alto Networks. Cheap access to large language models (LLMs) has “changed the game” in cybersecurity, she tells Avik Das in a video interview from her company’s headquarters in Palo Alto, California. Edited excerpts:
 
How are companies’ boards discussing cybersecurity?
 
When ChatGPT came along in 2022, everybody thought that if you throw an LLM, the magic will happen — only to realise that one needs to think about AI-first process reimagination, which is no different from a digital transformation. AI-first thinking is letting AI take the lead and humans supporting it. A few years later, we started seeing enterprises’ sensitive documents getting into LLMs without the right controls. Security started becoming more important than anything.
 
Since last year, we have seen AI models starting to reason and plan. That started the conversation about agentic AI and autonomous systems. Hence, we also started seeing runtime security and how AI agents can exploit vulnerabilities and take advantage of loopholes in the system. Hence, if there are no guardrails and constraints, security in the old systems becomes an issue. In my opinion, every step you want to take with AI, you would also want to equally see how we are integrating security. Not just in the steps you are taking, but in the possible places that AI can escape.
 
Has the conversation shifted from AI processes and strategies to returns on investment (RoI)?
 
We look at AI in three different vectors. First, what products and services we are going to offer to protect our customers in the use of AI. We spend a lot of time on our product strategy for protecting AI. The second conversation normally comes around how we are using AI to fight AI. In other words, today you cannot have humans doing that. So how are we using AI in our products to make sure that we are combating AI. The third vector is how AI is producing RoI in running the business.
 
For us, automation of information technology (IT) operations has increased to 83 per cent this financial year from 12 per cent a few years ago. IT operation costs have declined almost 72 per cent over the last two years while travel and expenses have reached 90 per cent automation through a combination of AI and process redesign. 
 
Have cyberattacks become more complex because of AI?
 
LLMs have significantly changed the game of AI. With more than 70,000 customers, we stop about 30 billion attacks that pass through our network. The thing that was most insightful last calendar year was that almost 250 million attacks — four times as many as the year before — were something we have never seen before. That’s what AI is really good at, pointing out a particular attack vector.
 
Do you anticipate more attacks in the next few years?
 
It is going to happen a lot more. The frontier models are not free and it is going to cost you to launch an attack. There are adversaries who will not have the economic constraint because the RoI is much higher. The biggest threat is the open-source models, which are available within four to six months, and not the frontier models, which are not available to all. But when you have an open-source model that can actually be not as expensive in four to six months, all you need is the compute and the skills [to conduct a cyberattack].
 
You say cybersecurity should not be just a layer on top. How are enterprises adopting this?
 
Security is like oil when you are cooking. You may have oil in the beginning, you may add a little bit more in the middle, and you may have to garnish it in the end depending on the dish. You don’t take the oil in the end and pour it on top. Security is the same. Imagine you have built a system and now you want security. You can’t just surround it.
 
With new software development, more people are aware of that and they are really leaning in on the principle. That is why you have application security people more as part of the infosec team. It is not anymore just infrastructure. Because when you have to start thinking about integrated security, you need to think at all levels from your infrastructure to your data to your application layer. Hence we see more application security engineers as part of the company, as well as part of your organisation.
 
   

One subscription. Two world-class reads.

Already subscribed? Log in

Subscribe to read the full story →
*Subscribe to Business Standard digital and get complimentary access to The New York Times

Smart Quarterly

₹900

3 Months

₹300/Month

SAVE 25%

Smart Essential

₹2,700

1 Year

₹225/Month

SAVE 46%
*Complimentary New York Times access for the 2nd year will be given after 12 months

Super Saver

₹3,900

2 Years

₹162/Month

Subscribe

Renews automatically, cancel anytime

Here’s what’s included in our digital subscription plans

Exclusive premium stories online

  • Premium stories handpicked daily by our editors

Complimentary Access to The New York Times

  • News, Games, Cooking, Audio, Wirecutter & The Athletic

Business Standard Epaper

  • Digital replica of our daily newspaper — with options to read, save, and share

Curated Newsletters

  • Insights on markets, finance, politics, tech, and more delivered to your inbox

Market Analysis & Investment Insights

  • In-depth market analysis & insights with access to The Smart Investor

Archives

  • Repository of articles and publications dating back to 1997

Ad-free Reading

  • Uninterrupted reading experience with no advertisements

Seamless Access Across All Devices

  • Access Business Standard across devices — mobile, tablet, or PC, via web or app

Topics :Artificial intelligencecybersecurityCyber threat

First Published: Aug 30 2026 | 9:50 PM IST

Next Story