AI is already carrying out attacks with almost no human involvement: the world is entering a new era of cyberwarfare

AI is increasingly taking on the tasks of reconnaissance, vulnerability scanning and post-compromise activities, forcing defence systems to automate just as quickly.

0

Artificial intelligence is increasingly moving away from its role as a hacker’s assistant towards becoming a system capable of independently carrying out individual stages of a cyberattack — from reconnaissance and vulnerability scanning to data collection following a breach. Patrice Kane, CEO of Thales, stated that defences must evolve just as quickly: «AI must be countered with AI.» Microsoft and Anthropic are also observing a trend towards more autonomous attacks, although fully automated, sophisticated breaches have not yet become the norm.

Briefly about the main points

  • Thales has observed an increase in the speed and complexity of cyberattacks utilising AI.
  • Microsoft reports a shift from AI assistants to semi-autonomous attacks.
  • In controlled tests, the AI has already successfully carried out complex, multi-stage attack chains.
  • Experts emphasise that security measures should also be automated and make use of AI.
Add UkrMedia to your Google sources Get more of our news in the recommendations.

AI is starting to carry out part of the cyberattack on its own

Just a few years ago, artificial intelligence was mainly used in cybercrime to write phishing emails, analyse code or create simple scripts. Now the picture is changing.

In its Digital Defence Report 2026, Microsoft reports that over the past six months it has observed a shift from AI that assists the operator, to systems that are already capable of to lead part of the attack or carry it out independently. AI is used for reconnaissance, vulnerability scanning, creating phishing campaigns, developing malware and post-compromise activities.

In a controlled Microsoft environment, one of the most advanced AI systems was able to pass 32 sequential stages of a complex attack. At the same time, the company emphasises: fully autonomous real-world cyberattacks until they became widespread, and people still play an important role in setting goals and making key decisions.

Vulnerabilities can be turned into weapons in less than a day

Another problem is speed.

According to Microsoft, the median time from the discovery of a vulnerability «in the wild» to its exploitation in attacks has already fallen well under 24 hours. At the same time, it often takes large companies between 30 and 60 days to rectify critical external vulnerabilities.

AI only widens this gap. What previously required several days’ work by an experienced team can now be partially automated: the system analyses the code, tests different operational scenarios and moves on to the next step without the constant involvement of an operator.

Anthropic has discovered «swarms» of AI agents

Anthropic In her September report, she described real-life instances where cybercriminals had used agent swarms — swarms of AI agents.

In this type of operation, a single lead agent breaks the task down into parts and assigns them to dozens of subordinate agents. Some carry out reconnaissance, others look for vulnerabilities, whilst others analyse security software or collect stolen data.

Anthropic reports that, in certain campaigns, automated systems may have been operating for hours or days with minimal human supervision.

The company also described a group of Chinese-speaking operators who maintained permanent AI agents for the automated collection of open-source intelligence, vulnerability research and other cyber operations. In this context, humans were primarily responsible for identifying targets and reviewing the results.

AI lowers the barrier to entry for hackers

The biggest change is not just that attacks are becoming faster. AI is reducing the amount of specialist knowledge required to carry out individual stages of a cyberattack. Tasks that previously required the involvement of an experienced programmer or security analyst can increasingly be delegated AI agent.

Anthropic notes that automation reduces the cost of cyber operations for an attacker. A single operator can potentially target dozens of targets simultaneously, rather than just one.

This is particularly dangerous for small and medium-sized businesses. Previously, such companies may not have been of interest to sophisticated attackers due to the low potential financial gain. However, if a significant proportion of their operations is automated, it becomes more economically viable to attack thousands of less well-protected organisations.

Thales: «AI must be tackled with AI»

Against this backdrop, the CEO of Thales Patrice Kane called on companies and governments to invest significantly more in AI protection.

According to him, attackers are already using AI to carry out faster and more complex operations, and sometimes to perform certain tasks autonomously. Consequently, traditional systems that rely on manual analysis of each signal may simply be unable to respond in time.

Thales has unveiled new systems to protect against AI attacks and has expanded its collaboration with Google Cloud in the field of corporate AI security. Kane emphasised that the main advantage of AI for defence lies in its speed: the system can simultaneously analyse millions of events, detect anomalies and automatically block suspicious activities before a human can spot them.

Real AI agents have already attempted to attack government systems

The research firm Transluce reported that AI agents had attempted to gain access to the website Library and Archives Canada. The Canadian Cyber Security Centre has confirmed that it is aware of these attempts, but has found no evidence of a successful breach.

An isolated incident involving an AI agent was previously reported in Australia, where the system gained unauthorised access to a government portal containing medical data.

OpenAI It also alerted more than 100 organisations to unauthorised activity involving AI agents.

These cases do not mean that AI is already capable of carrying out any kind of cyberattack on its own. However, they do demonstrate that autonomous systems are already able to move beyond test environments and interact with real-world information systems.

The main danger is the scale

Even if a single AI agent is no match for an experienced hacker, it has another advantage — scalability.

A thousand AI agents can simultaneously:

  • to scan thousands of websites for vulnerabilities;
  • create personalised phishing messages;
  • analyse the sources of password leaks;
  • to test different penetration methods;
  • to gather information once access has been granted;
  • to adapt malicious code after it has been detected by security systems.

Anthropic has already seen cases where a single operator was working with dozens of victims simultaneously, whilst the AI automatically reconfigured and redeployed the tools after they had been blocked.

Fully autonomous hackers have not yet become the norm

Microsoft explicitly states that most sophisticated real-world attacks still require substantial human control. AI is good at automating individual parts of the process, but it can make mistakes, misjudge the context or get stuck when dealing with non-standard systems.

Anthropic also points out that even in the most autonomous campaigns, people generally retain control over strategic decisions: who to attack, what data is valuable, and what to do with the information obtained.

So, the main change in 2026 is not the emergence of an «AI hacker» who has completely replaced humans, but a sharp reduction in the amount of manual work required to carry out an attack.

Cybersecurity joins the AI-versus-AI race

The next logical step is becoming increasingly clear: attacks and defences will be automated simultaneously.

On the one hand, there are AI agents that search for vulnerabilities around the clock, generate exploits and manage campaigns. On the other hand, there are defence systems that must independently detect anomalies, analyse code, block suspicious activity and patch vulnerabilities before an attacker can exploit them.

That is precisely why Thales’s proposition «to combat AI with AI» could become one of the key principles of cybersecurity in the coming years.

WRITE A REPLY

enter your comment!
enter your name here