Artificial intelligence is moving beyond answering questions and generating content. New evidence from cybersecurity researchers shows AI agents increasingly being used to automate parts of cyberattacks, raising a fundamental question for governments and businesses: when does one of the world’s most powerful productivity tools become an autonomous security threat?
From assistant to agent
Google Threat Intelligence Group says malicious actors are progressing from basic AI prompting towards agentic systems and automated workflows.
The distinction is important. Traditional generative AI normally waits for a person to request each action. An AI agent can instead pursue an objective through several steps, using tools, analysing results and deciding what to do next.
Google documented a case during the second quarter of 2026 in which attackers compromised a cloud resource and then planned, constructed and executed an AI-enabled mass credential-harvesting operation in less than six hours.
The same technology works for defenders
AI itself is not inherently offensive. Cybersecurity teams use machine learning and AI to analyse enormous volumes of network activity, identify suspicious behaviour and respond to attacks more rapidly.
That creates an unusual technological contest. Attackers can use AI to accelerate reconnaissance, phishing, malware development and credential theft, while defenders can deploy similar technology to identify those attacks.
Speed may therefore become as important as intelligence.
Growing evidence of misuse
Anthropic reported this month that malicious actors had attempted to use its Claude models for cyber operations, surveillance and other harmful activities. The company said it had identified and disrupted a number of such operations.
The concern is increasingly international. INTERPOL has reported that AI is enabling 55% of reported cybercrime across Africa, helping criminals increase the speed and scale of their operations.
Tool and threat at the same time
The emerging picture is therefore not simply that AI is dangerous or beneficial.
The same characteristics that make AI valuable — speed, automation, scalability and the ability to process vast amounts of information — can also make it effective in the hands of an attacker.
The decisive issue may ultimately be control. As AI systems become capable of performing longer sequences of actions independently, organisations will need to know not only what an AI model can say, but what it can actually do.
AI remains one of the most powerful tools created in the digital era. The cybersecurity evidence emerging in 2026 shows why it can simultaneously become part of the threat it was designed to help humans manage.
Newshub Editorial in North America – 21 September 2026

Ask NF GPT
If you have an account with ChatGPT you get deeper explanations,
background and context related to what you are reading.

Recent Comments