The next major cybersecurity threat may not be a hacker sitting behind a keyboard.
It could be AI systems searching for vulnerabilities, testing attacks and adapting their approach at a speed humans cannot match.
If that sounds far-fetched, consider what malicious software can already do. Computer worms can spread automatically from machine to machine. Malware can alter its appearance to evade detection, while botnets can coordinate thousands or even millions of compromised devices at once.
Those systems, however, generally follow strategies written by humans in advance.
Modern AI introduces something different: the ability to analyze a situation, make decisions and change tactics based on the result. Today’s advanced models can already write and review code, identify vulnerabilities, operate software tools and determine whether an approach succeeded or failed.
The concern is not that malware suddenly becomes conscious. It is that we may be combining the persistence and scale of traditional malware with increasingly capable automated reasoning.

From AI-Assisted Hacking to AI-Driven Hacking
Early concerns about generative AI and cybersecurity focused mostly on assistance. AI could write better phishing emails, translate scams, explain programming techniques or help inexperienced attackers modify malicious code.
Agentic AI changes that equation.
An AI agent can potentially be given a goal, access to tools and an environment where it can take actions. Instead of simply explaining what a hacker should do, it can perform portions of the process: analyzing a system, searching for weaknesses, testing approaches and adjusting when something doesn’t work.
The distinction is important.
A chatbot answers questions. An agent can act.
Cybersecurity may be one of the areas where that difference becomes most significant.
AI Can Already Exploit Real Vulnerabilities
Research is beginning to demonstrate these capabilities under controlled conditions.
The CVE-Bench cybersecurity benchmark was created specifically to test whether AI agents could exploit real-world software vulnerabilities. Researchers found that the strongest systems could successfully exploit a meaningful portion of the vulnerabilities tested.
Another widely cited 2024 experiment gave GPT-4-based agents descriptions of 15 previously disclosed software vulnerabilities. With those descriptions available, the AI successfully exploited 87% of them. The study was small and does not mean AI can automatically compromise 87% of systems, but it demonstrated that advanced models could connect technical vulnerability information with the actions required to exploit it.
The capabilities have continued improving. Anthropic reported that its Claude models became substantially better at identifying vulnerabilities, completing multi-step attack chains and changing tactics when an initial strategy failed.
That ability to fail, analyze the failure and try something different may ultimately matter as much as raw coding ability.
Frontier Models Are Approaching Serious Cyber Capabilities
The AI companies themselves are now treating cybersecurity as a major frontier risk.
In August 2026, OpenAI disclosed that early testing of its Astra model had advanced enough that the company said it could not rule out reaching its highest “Critical” cybersecurity capability threshold.
Under OpenAI’s Preparedness Framework, that level includes capabilities such as discovering previously unknown vulnerabilities in hardened systems or independently carrying out sophisticated attack strategies after receiving only a high-level objective.
That does not mean Astra has been proven capable of autonomously attacking real-world infrastructure. It does mean that one of the world’s leading AI laboratories considers those capabilities plausible enough to warrant specific safeguards and testing.
Cybersecurity is no longer an accidental side effect of increasingly capable AI models. It is becoming a capability developers are actively measuring.

Real-World Attacks Are Becoming More Automated
The transition from research experiments to real-world misuse may already be beginning.
In late 2025, Anthropic reported disrupting what it described as an AI-orchestrated cyber espionage campaign. According to the company’s investigation, attackers used Claude to perform vulnerability research, create exploit code, obtain credentials, analyze stolen information and assist with other parts of the operation.
Anthropic estimated that AI performed roughly 80% to 90% of the campaign’s workload, with humans stepping in mainly for important decisions.
More recent threat research from the company describes multi-agent systems being used for reconnaissance, exploitation and data theft. In one example, Anthropic said an attack workflow could automatically rebuild and redeploy parts of its toolkit after security software detected it.
That creates a potentially dangerous feedback loop:
Attack → fail → analyze → adapt → try again.
Why AI “Swarms” Matter
The term “AI swarm” can sound overly futuristic, but the basic idea does not require science-fiction intelligence.
A single operator could coordinate dozens, hundreds or eventually thousands of AI agents working on separate parts of a problem simultaneously. One agent might analyze software while another searches documentation, another examines credentials and another tests potential weaknesses.
Useful results could then be fed back into the larger attack process.
Humans already solve difficult problems through experimentation. We try different approaches until something works.
AI allows that experimentation to happen in parallel and at enormous speed.

AI Could Dramatically Lower the Cost of Cybercrime
The most important consequence may not be an entirely new form of hacking. It may simply be that existing attacks become much cheaper and easier to scale.
Sophisticated cyberattacks traditionally require skilled people, and skilled hackers have limited time. AI allows portions of that expertise to become software.
MIT Sloan recently asked 272 AI experts to evaluate major AI risks expected between 2025 and 2030. AI-enabled cyberattacks and weapons were among the risks receiving some of the highest severity ratings.
Researchers also highlighted a particularly concerning combination: AI can help inexperienced attackers perform tasks that once required greater expertise while simultaneously making professional hackers more productive.
In other words, AI could increase both the number of capable attackers and the capabilities of the best attackers.
Attackers Only Need One Weakness
Cybersecurity is already asymmetric.
A company might have thousands of devices, cloud services, applications and employee accounts that need to remain secure. An attacker may need to find only one forgotten server, compromised password, outdated application or undiscovered vulnerability.
AI could continuously search for those weak points without getting tired or losing focus.
A system could analyze software packages, examine newly released vulnerabilities, revisit systems after updates and compare massive amounts of technical information around the clock.
The threat does not necessarily need to be a brilliant superintelligence.
It may simply need to be relentless.
Defenders Get AI Too
There is an important counterbalance: the same technology can dramatically improve cybersecurity defense.
AI can inspect code for vulnerabilities, monitor networks for suspicious behavior, analyze security logs, prioritize alerts, recommend patches and help security teams investigate malware much faster.
This may lead cybersecurity toward an increasingly automated contest:
Offensive AI versus defensive AI.
The question is whether defense can keep pace.
Attackers have one important advantage: they choose where and when to attack. Defenders must protect everything.
Businesses May Not Be Ready
IBM has warned that malicious actors can already use AI for phishing, impersonation and increasingly sophisticated cyberattacks. At the same time, many organizations are deploying generative AI faster than they are securing it.
The risk becomes especially significant as companies connect AI agents directly to internal systems.
An enterprise AI system might eventually have access to email, cloud infrastructure, financial software, source code, customer databases and internal documents.
That means security can no longer focus only on protecting the AI model. Companies must also control what the AI is allowed to do.
An assistant that answers questions poses one level of risk. An agent that can log into systems, execute commands, modify files and access databases poses another entirely.
AI Cyberattacks and Warfare
The consequences become even more serious when cybersecurity intersects with warfare.
Modern governments and militaries depend heavily on digital infrastructure for communications, logistics, intelligence, satellites, transportation and weapons systems. Civilian infrastructure—including banking, healthcare, telecommunications and energy—is equally dependent on software.
AI could compress the timeline of cyber conflict. Operations that once required days or weeks of reconnaissance could potentially happen much faster as AI systems analyze targets, search for vulnerabilities and test potential attack methods simultaneously.
Cyberattacks can also cross into the physical world. Disrupting an electrical grid, communications network, transportation system or hospital can produce consequences far beyond damaged computer files.
MIT’s AI risk research specifically identified national security as one of the areas most exposed to advanced AI, including cyberattacks, surveillance and weapons development.

The Threat Shouldn’t Be Exaggerated
Today’s AI agents are far from perfect. They hallucinate, misunderstand environments, get stuck and frequently fail at complicated tasks.
Even Anthropic’s report on AI-assisted espionage noted that the model sometimes invented credentials or incorrectly claimed it had found secret information.
Current AI systems are therefore not unstoppable autonomous hackers.
But they don’t need to be.
Spam doesn’t work every time. Phishing doesn’t work every time. Malware doesn’t work every time.
Attackers compensate with volume.
AI makes volume cheap.
Cybersecurity Will Have to Move at Machine Speed
If attacks increasingly happen at machine speed, organizations cannot rely entirely on humans to respond.
Cybersecurity will need to become more automated as well.
That means stronger continuous vulnerability testing, faster patching, better network segmentation, strict access controls, detailed monitoring of AI agents and automated systems capable of identifying and responding to suspicious behavior quickly.
AI developers will also face difficult decisions over how powerful cybersecurity capabilities should be exposed, who should have access and what safeguards should surround models capable of operating tools autonomously.
Cybersecurity testing may eventually become as fundamental to frontier AI development as traditional model performance benchmarks.
The Bigger Question
For decades, sophisticated cyberattacks have been limited partly by economics. Highly skilled hackers are difficult to find, expensive and limited by time.
AI begins removing that limitation.
The most concerning future may not involve a rogue superintelligence deciding to attack the internet. It could be much simpler.
A criminal organization or government gives an advanced AI system a target. Hundreds of automated processes begin investigating it simultaneously. They test approaches, analyze failures and keep trying until something works.
Parts of that technology already exist.
Cybersecurity has spent decades preparing for malicious software.
The next challenge may be considerably harder:
malicious software capable of reasoning about what to do next.