Frontier AI models can now find exploitable vulnerabilities faster than any human research team, and attackers have that capability today. In Episode 335 of the Managing Uncertainty Podcast, Bryan Strawser of Bryghtpath introduces the AI Storm, a scenario of concurrent zero-days with exploitation beginning within hours of disclosure. He explains why the threat environment your continuity, incident response, and crisis management plans were built for no longer exists.
Bryan walks through five unwritten assumptions every plan rests on and shows how each one breaks under AI Storm conditions. He shares anonymized findings from tabletop exercises Bryghtpath ran with clients this year, including unknown emergency patch velocity, undefined authority for production-impacting actions, and teams that could not sustain the surge. Strong teams improvised well, but improvisation is not a plan.
He closes with five decisions executive teams should make in the next ninety days, from measuring real patch velocity to signing a pre-authorized decision matrix and funding a continuous defensive stack.
Learn how Bryghtpath designs and facilitates the AI Storm exercise at bryghtpath.com/contact.
Subscribe to the Managing Uncertainty Podcast wherever you listen.

