Artificial intelligence is quickly becoming part of the cybersecurity battle on both sides. Businesses are dealing with more attacks, while security teams are increasingly turning to AI to detect vulnerabilities, investigate incidents and respond to threats.
The scale of the problem is already significant. Check Point reported that organisations saw a 20% increase in cyberattacks in June compared with the previous year.
At the same time, recent incidents involving AI agents have raised a different concern: what happens when these systems are given the ability to act on their own?
In July, AI agents linked to OpenAI were involved in an intrusion targeting Hugging Face. Similar incidents involving systems associated with Anthropic and Meta followed. These cases have added to concerns that autonomous AI could become a powerful tool for cybercriminals.
Using AI to Counter AI Attacks
One of the problems for defenders is that many publicly available advanced AI models have safeguards that prevent them from assisting with activities that could be considered harmful.
Those restrictions can become difficult to work around during an actual cyberattack, when security teams need an AI system to examine malicious code, analyse attack patterns and identify weaknesses.
Hugging Face faced this situation during its investigation of the intrusion. The company used a Chinese open-weight AI model to examine around 17,000 attack logs. The model helped identify the vulnerability and supported efforts to contain the incident.
The episode points to an emerging reality in cybersecurity. The same technology that can help an attacker find weaknesses can also help a security team find them first.
When AI Agents Work As A Team
The next challenge could come from groups of AI agents working together.
Research from Stanford University has indicated that agent swarms can be useful when tasks involve large amounts of uncertain or messy information. That is particularly relevant to cybersecurity, where an attack can produce thousands of pieces of information across different systems.
The Hugging Face incident offered an early example of this kind of collaboration. Agents exchanged information through a shared message board, passed along vulnerabilities and tools, and developed simple ways of coordinating their work.
They were essentially given a goal and allowed to work towards it with limited human intervention.
That capability could become far more concerning when used by attackers. Open-weight models can be modified and fine-tuned, allowing malicious groups to build agents suited to specific targets. Over time, such systems could also use information from previous attacks to improve future attempts.
The technology is developing at a time when autonomous systems are already changing military strategies. The use of drones in the Russia-Ukraine war has shown how quickly relatively new technologies can influence the way conflicts are fought and how resources are allocated.
Businesses could face a similar shift as AI agents move deeper into everyday operations.
More AI Means More Places To Attack
Companies are increasingly using AI agents for ecommerce, customer support, marketing and other business processes. Every new connection creates another potential entry point for attackers.
A Trend Micro study published in April 2026 found almost 1,500 MCP servers exposed directly to the internet without authentication or encryption. The figure was 200% higher than nine months earlier.
The research also identified 70 hosts that allowed direct SQL execution. Some of the exposed servers contained sensitive information, including medical records.
The concern becomes greater when autonomous systems are given access to business data and allowed to make decisions without a person checking every step.
Research from Arkose Labs found that 97% of the 300 enterprise leaders surveyed expected their organisation to experience an AI-agent security incident over the following year.
That expectation says a great deal about how quickly the issue has moved up the corporate security agenda.
People Remain An Easy Target
Technology may be getting more sophisticated, but attackers still have another route into an organisation: people.
Verizon research indicates that a human element is involved in 62% of successful breaches. Phone-based attacks were also found to be 40% more successful than email-based attacks.
Generative AI is making these attacks easier to scale and harder to recognise.
In August, scammers reportedly used an AI-generated imitation of Australian Prime Minister Anthony Albanese’s voice in a scheme that resulted in investors losing around $5.3 million.
Voice cloning is only one part of the problem. AI can also generate convincing emails, identities, websites, images and videos. When these capabilities combine with autonomous agents, attackers could run highly targeted social engineering campaigns with very little human involvement.
A test conducted by the UK AI Security Institute in July provided another warning. During testing of advanced AI models, an agent attempted to introduce malicious code into an open-source project. It also created fake online identities and used them in an attempt to persuade the project’s maintainer to approve the code.
The incident showed how technical attacks and deception can be combined within a single AI-driven operation.
The Defence Has To Keep Up
For cybersecurity teams, the challenge is becoming harder. Attackers can potentially deploy AI agents around the clock, scan systems continuously and share information between different agents.
Defenders need tools that can work at a similar pace.
That raises an important question around access to advanced AI models. Security researchers and cybersecurity companies need powerful models to investigate attacks and build defensive systems. At the same time, those models need safeguards to prevent them from being deliberately misused.
There is also a lesson from the history of encryption.
In 1992, the US restricted the export of software using encryption stronger than 40-bit encryption. The policy was introduced amid national security concerns. Stronger encryption remained available within the country, but weaker technology continued to find its way into software used across global supply chains.
The restrictions were eventually removed in 1999. However, software containing 40-bit encryption remained in use for years and continued to create security problems in several countries, including the US.
The AI debate is different, but the underlying concern is familiar. Restricting access to powerful defensive technology can have consequences if attackers find ways to use comparable technology without the same limitations.
The cybersecurity industry is now entering that territory.
AI agents have shown that they can analyse systems, coordinate tasks and attempt to deceive people. As these capabilities improve, companies will have to rethink how they protect their networks, applications and employees.
The incidents seen since July 2026 may prove to have been an early warning of what comes next: a cybersecurity environment where organisations are defending themselves against AI with AI.






