Artificial intelligence (AI) is making cybersecurity faster, more automated and increasingly complex. Recent security tests involving AI agents from major technology companies have shown that advanced models can identify vulnerabilities, write code, use online tools and attempt complex cyber operations when given the right permissions.
Reports involving OpenAI, Anthropic and Meta have attracted attention after AI systems interacted with real services or accessed systems during controlled evaluations. These incidents have raised an important question: Can AI be hacked, or can AI hack computer systems by itself?
The short answer is that AI is becoming highly capable at cybersecurity tasks, but the technology is not acting like a self-aware attacker. In most cases, researchers provided the models with specific goals, tools, internet access or vulnerable environments to test their capabilities.
These events are separate, but together they highlight a broader shift in cybersecurity. AI models are moving beyond simple conversation and becoming agent-based systems capable of planning, taking actions and adjusting their approach based on results.
Why are there suddenly so many AI hacking stories?
Several developments have contributed to the increase in reports about AI hacking and cybersecurity risks. The latest frontier AI models are more capable than earlier chatbots and can now perform tasks such as writing software, running commands, browsing the internet and interacting with external applications.
AI companies are also conducting more aggressive security testing. Instead of evaluating models only in private, companies such as OpenAI, Anthropic and Meta are publishing reports from red-team exercises. During these assessments, cybersecurity specialists deliberately challenge AI systems to discover weaknesses, unsafe behaviors and unexpected capabilities.
“We are seeing a perfect storm of features and aggressive testing,” Dray Agha, senior manager of security operations at Huntress, told Live Science.
According to Agha, the growing use of AI in software development and security testing is also contributing to the discovery of more vulnerabilities. Technology companies are using AI models to examine code, test infrastructure and identify weaknesses that could otherwise take security teams much longer to find.
Antonino Vaccaro, professor of business ethics at IESE Business School and director of the AI Ethics Observatory in Organizations, said that both the rapid development of AI and increased oversight have played a role in the recent headlines.
As AI systems gain access to more information, computing resources and online tools, governments and businesses are also increasing investment in testing, monitoring and accountability.
Can AI hack computers by itself?
Not exactly. Headlines sometimes describe AI as “escaping” a test environment or operating completely autonomously. However, that description can create a misleading impression of how these systems work.
AI models do not form independent intentions in the same way humans do. They follow objectives established by developers, researchers or users. Their behavior can still be surprising, particularly when they are given access to software tools, internet-connected systems or the ability to execute commands.
In recent evaluations, researchers intentionally supplied the conditions needed to test offensive cybersecurity capabilities. In some cases, a model was able to identify a weakness, create code to exploit it and continue refining its approach when the first attempt failed.
One reported incident involving Meta was linked to a misconfigured testing environment that allowed an AI model to access the internet. That does not necessarily mean the model broke out of a secure digital sandbox independently.
The major change is the shift from a conversational model to an agent-based model.
Dray Agha, Huntress senior manager of security operations
The central concern is therefore not that AI has become self-aware. The bigger issue is that increasingly capable systems can perform complex technical tasks quickly when they receive the appropriate access and instructions.
Why are modern AI models becoming better at cybersecurity?
The biggest development is the rise of AI agents. Traditional chatbots typically generate one response at a time. Agent-based AI systems can plan multiple steps, select tools, test ideas, analyze results and continue working toward a specific objective.
“The game changer is moving from a conversational model to an agent model,” Agha said. Modern frontier AI can chain actions, write code, use command-line tools and learn from failed attempts during a task.
When connected to a development environment, an AI agent can test whether a proposed solution works in practice. If the code fails, the system may identify the error, revise the code and try again. This ability to iterate can make AI particularly useful for vulnerability research and security testing.
The same capabilities can also benefit defenders. Security teams are using AI-powered tools to review code, analyze suspicious files, summarize alerts and accelerate investigations that might otherwise require hours of manual work.
Should people be worried about AI-powered cyberattacks?
Experts say the risks are serious, but they are different from the science-fiction scenario of an AI independently deciding to attack humanity.
The most immediate danger is that cybercriminals could use AI to make familiar attacks faster, cheaper and more convincing. Criminal groups do not necessarily need AI to invent entirely new attack methods. Instead, they can use existing models to scale techniques that already work.
For example, AI can help attackers:
- Research potential victims using publicly available information
- Create more convincing phishing emails and social-engineering messages
- Analyze software for possible vulnerabilities
- Generate or modify code for malicious campaigns
- Automate repetitive reconnaissance and preparation tasks
“The threat is human malice accelerated by the scale and speed of AI, not autonomous AI determined to misbehave,” Agha said.
Vaccaro argues that greater technical capability must be matched by greater responsibility. Governments, businesses and researchers will need effective policies, testing standards and oversight to ensure that powerful AI systems are deployed safely.
How will AI change cybersecurity in the future?
More AI security incidents are likely to emerge as companies give models access to additional tools, computing power and realistic testing environments. Future evaluations may reveal new capabilities, unexpected behaviors and weaknesses that require closer supervision.
Most experts expect AI to become a powerful cybersecurity assistant rather than an independent cybercriminal. Security teams may use AI to discover software bugs earlier, investigate threats faster and automate routine defensive tasks.
However, attackers will have access to similar technology. Cybercriminals may use AI to improve phishing campaigns, accelerate vulnerability research and produce more persuasive scams. This creates an ongoing competition between AI-assisted defenders and AI-assisted attackers.
The future of AI cybersecurity is unlikely to be defined by machines secretly conspiring against humans. Instead, the main challenge will be managing increasingly capable software that can carry out instructions with remarkable speed and precision.
Source: www.livescience.com


