If artificial intelligence (AI) is making cyber attackers faster at finding vulnerabilities, companies cannot continue relying on humans and traditional security systems to defend themselves, according to payment gateway Razorpay's CEO and cofounder Harshil Mathur.“If the threat actor is a model, your defence actor cannot be a human anymore. Your defence actor has to be a model,” Mathur said in a conversation with Peak XV Partners managing director Mohit Bhatnagar at the Global Fintech Fest 2026.Mathur said Razorpay has a dedicated security team that is using AI models to build its defensive posture. The fintech uses a combination of proprietary and open-source models to identify vulnerabilities across its code and infrastructure.Also Read: GFF 2026: The next breakthrough in responsible financial AI can be built in Mumbai, says Maharashtra CM FadnavisThis is becoming necessary as attackers increasingly use AI to continuously probe systems for weaknesses, he said.“Attackers are consistently using models now to run in a loop and find weaknesses in a system across the board,” Mathur said.Historically, companies had to rely on human penetration testers or external researchers to identify vulnerabilities. AI models are now allowing companies to run similar exercises internally and continuously look for weaknesses before they are exploited.“There was never a way for you to run something like a model across your infrastructure, across your codebase, to identify and protect against vulnerabilities before they are hit in the wild,” Mathur said.He said the balance is now shifting, with companies able to use AI to find and fix vulnerabilities before attackers discover them.But Mathur sees a growing risk for companies that have not kept pace with attackers.“What we see today is the transitionary nature of it, where some companies haven't invested that much in cybersecurity, but the attackers have that model available,” he said.Also Read: GFF 2026: BharatPe launches agentic AI assistant for merchants, connects to over 60 live systemsIn such a scenario, attackers could be using AI while companies continue to depend on “old-school systems” for defence.“I think that's a recipe for disaster right now,” Mathur said. “If the attackers are using models, you have to use models to defend. If you are missing that out, you are going to lose.”Mathur said the answer is not to slow down AI adoption because of the risks it creates. Instead, companies need to accelerate the development of AI-powered defences alongside the technology itself.“Any new technology that creates a risk is better solved through technology,” he said.