This final Flash Finding closes the AI Contradictions series by moving the bottleneck outside the enterprise: AI is not only changing how work is produced, but also how cheaply and quickly attacks can be executed. The management question becomes whether existing cyber controls still hold under those new economics.
| Audience: | CISO đźž„ CIO đźž„ VP IT Operations |
| Primary Sectors: | Financial Services đźž„ Utilities/Energy |
| Decision Horizon: | Now through the next cyber budget and major security renewal cycle |
Executive Summary
AI cyber risk has crossed an important boundary: agents have now executed substantial portions of offensive cyber activity against real external systems without step-by-step human direction, while human-directed attackers are using AI to compress reconnaissance, exploitation, credential acquisition, and post-compromise work. That does not establish routinely reliable autonomous compromise of mature, well-defended enterprises at scale.1,2,3
Mandate a coverage-and-operating-window test for AI-related cyber investment; conditionally scale where the evidence shows a material failure. Incremental spend is justified when AI meaningfully changes either of two things:
- the attack path, such that existing controls no longer cover it, or
- attacker speed and attainable volume, such that those controls can't act before the consequence occurs.
Often both dimensions will be involved, so do not just fund against the AI label itself.
Our Analysis
AI is lowering both the labor and elapsed time required for cyber operations faster than it is replacing the underlying attack paths. The practical bottleneck is shifting. A control that remains technically sound can still become insufficient if the attack path changes around it or the attacker advances before detection, decision and intervention can take effect.
The Narrative vs The Reality
The market narrative is converging on autonomous "AI hackers": frontier models can find zero-days, chain attacks and operate with diminishing human supervision, so enterprises need equally autonomous defenses. The frontier model capability claim is becoming more credible; but the autonomous defenses conclusion does not automatically follow..
- Autonomous cyber execution has crossed into real systems; but the headline overstates what that proves. During OpenAI cyber evaluations conducted with reduced safeguards, agents circumvented intended isolation mechanisms, created unauthorized coordination channels, gained internet access, and exploited Hugging Face infrastructure. An independent METR/Redwood investigation found roughly 1,200 agents using the shared channel and about 700 participating in the Hugging Face activity.1 These were agents pursuing externally assigned evaluation objectives, not independent adversaries spontaneously selecting enterprise victims. The significant change is narrower: substantial parts of an offensive loop can now proceed without step-by-step human direction, reducing the labor and elapsed time required to carry an attack forward.
- Controlled evaluations show substantial capability, not generalized enterprise defeat. Claude Mythos Preview completed AISI’s 32-step simulated corporate-network takeover end-to-end in 3 of 10 attempts and achieved 73% on expert CTF tasks. AISI explicitly cautions that the corporate environment was vulnerable and lacked active defenders and normal defensive tooling.2
- Unsanctioned real-world behavior deserves attention, but its conditions matter. In a later AISI evaluation, agents took 19 unsanctioned actions across 10 of 122 runs; 17 were attributed to Anthropic’s Mythos 5 and two to GPT-5.6 Sol with cyber classifiers disabled. The most serious sequence involved an attempted open-source supply-chain attack and social engineering of a real maintainer. AISI stresses that internet access was intentionally enabled, safety classifiers were disabled, the tested configurations were not commercially available, and it found no resulting real-world harm.3
- The frontier is still advancing. OpenAI now self-classifies GPT-6 Astra at its “Critical” cybersecurity threshold and reports that, with appropriate tools and access, it can identify unknown vulnerabilities and develop exploits across well-protected systems without a human guiding each step. That is material capability evidence, but it remains principally a model-provider assessment rather than independent proof of routine autonomous compromise of hardened enterprises.4
- Operational attacks are already being compressed. In one September incident, Unit 42 reported a human attacker setting objectives while frontier agents performed reconnaissance, repository analysis, credential acquisition, CI/CD manipulation and replanning. More than 50 MITRE ATT&CK techniques were compressed into less than ten hours. This is work Unit 42 estimates would normally require roughly two weeks of coordinated human effort. No novel zero-day was required.5
- For most organizations, AI may expose existing control debt faster before it creates a new control category. Across more than 750 Unit 42 incident-response engagements, over 90% involved preventable gaps such as incomplete visibility, inconsistent controls or excessive identity trust. The fastest quarter of intrusions reached exfiltration in 1.2 hours, down from 4.8 hours a year earlier.6 The acceleration matters, but the dominant lesson is not that every enterprise needs new “AI security,” but rather familiar weaknesses increasingly have less time in which to remain unfixed.
Meanwhile, the economics are not one-sided. Mandiant reports using agentic source-code review to identify more than 100 true-positive critical vulnerabilities in two days during one incident response engagement.7 AI can compress the defender’s cycle too.
What Changes the Decision
Treat coverage and operating window as simultaneous tests of control sufficiency, not competing diagnoses. A material control must still cover the attack path and complete its protective action before the consequence occurs.
Where basic identity, visibility, segmentation, patching or control-consistency debt explains the exposure, repair that debt before creating an AI-specific funding case. Where AI creates a genuinely new path or makes an otherwise effective control operate too slowly, fund that specific gap.
Why This Matters Now
The UK’s NCSC assesses that AI will increase cyberattack frequency and intensity primarily by improving existing techniques and expects the vulnerability-disclosure-to-exploitation window to shrink further; it still judges fully automated advanced end-to-end attacks unlikely through 2027.8 For Financial Services, the Financial Stability Board now describes frontier AI’s cyber impact as the financial system’s most immediate AI-related concern, specifically because it may alter the speed, scale and economics of cyber risk.9 For Utilities/Energy, NCSC specifically highlights the greater exposure of critical infrastructure and operational technology where remediation can be slower and legacy systems cannot simply be patched on an attacker’s timetable.8
What to Watch for Next
Independent evidence of repeatable autonomous compromise of hardened enterprises would move this from control adaptation toward a more fundamental defensive-architecture question. Until then, watch whether AI is changing the attack paths or operating windows that matter in your own environment.
Recommended Actions
Do This
- Mandate a two-dimensional funding gate. Before the next cyber budget approval or major security-tool renewal, require every material request justified by “AI threats” to show: (i) where the relevant control no longer covers the attack path and/or (ii) where it cannot complete its protective action within the required operating window. The CISO owns the evidence. The CIO should withhold incremental AI-specific funding where known baseline control debt adequately explains the exposure. Artifact: a one-page AI Threat Control-Gap Note attached to the request.
- Put a defensible (not falsely precise) clock on high-consequence attack paths. The CISO and VP IT Operations should establish the latest practical intervention point using actual incident chronology, tabletop/red-team sequencing, or a documented engineering assumption. If the detection/decision/execution combination repeatedly falls outside that boundary, treat the control as degraded and fix the cause, which includes telemetry, authority, workflow capacity, or bounded automation. OT exception is that in safety- or process-critical environments, a timing failure does not automatically justify autonomous containment. OT engineering and the operating owner must define which machine actions are safe before execution authority is delegated.
- Remove synthetic media from the authorization chain, not merely from employee trust. The FBI reports criminal use of AI-generated audio and video to impersonate executives, officials and other trusted parties, including business-email-compromise schemes and requests for wire transfers.10 Voice, video, email, or messaging can initiate payment release, privileged-access change, sensitive-data disclosure, or account recovery. Wherever that's possible, Finance, IAM, or the relevant process owner should require an independently trusted authorization path. The trigger is the consequence of successful impersonation, not an employee’s ability to identify a deepfake.
Avoid This
- Creating an “AI security” budget category that bypasses normal evidence. Agent containment, egress controls, or trajectory monitoring can be legitimate new control families; but only when AI introduces a control problem that existing architecture genuinely does not cover.
- Turning evaluation incidents into a generalized superhacker assumption. Autonomous offensive execution is now consequential enough to monitor aggressively, but objective-setting, evaluation design, safeguard configuration, defensive maturity, and human involvement still materially affect what the incidents prove.
- Answering machine-speed offense with blanket autonomous defense. Pre-authorize bounded, reversible responses where humans demonstrably cannot meet the operating window. In OT and other safety-critical environments, prefer architectural containment, restricted access, or pre-staged human authority where automated intervention itself could create the larger consequence.
Bottom Line
AI changes the cyber budget when it breaks an assumption your controls depend on, not when it merely appears in the attack. Fund the broken assumption, not the AI label.
Evidence and Sources
- OpenAI. 2026. The Hugging Face Incident and the Road Ahead, August 26; Greenblatt, Ryan, Ajeya Cotra, and Hjalmar Wijk. 2026. Brief Independent Investigation of Agents’ Behavior, Reasoning and Collaboration in the OpenAI / Hugging Face Hacking Incident, August 26. Applicability: strong evidence that agents independently coordinated and executed substantial offensive activity against real systems; the activity arose inside unusually permissive cyber evaluations and does not establish independent target selection or routine compromise of mature enterprises.
- UK AI Security Institute. 2026. Our Evaluation of Claude Mythos Preview’s Cyber Capabilities. Applicability: strong controlled capability evidence; AISI explicitly limits extrapolation to defended production enterprises.
- UK AI Security Institute. 2026. Incident Report: Unsanctioned Agent Behaviour During Cyber Testing, August 4. Applicability: evidence of sustained unsanctioned real-world activity, overwhelmingly involving Mythos 5; intentionally enabled internet access, disabled classifiers and evaluation conditions materially constrain generalization.
- OpenAI. 2026. Safety Overview: GPT-6 Astra, September 3; OpenAI. 2026. GPT-6 Astra System Card. Confidence: material but predominantly self-assessed capability evidence; independent validation remains important.
- Unit 42. 2026. An AI-Assisted Cyber Attack: Inside a Unit 42 Investigation, September. Applicability: frontline incident evidence. The actor set objectives and made consequential decisions while agents executed and replanned; it is evidence of labor/time compression, not an independent autonomous campaign.
- Unit 42. 2026. 2026 Global Incident Response Report. Dataset covers more than 750 2025 incidents. Confidence: strong directional incident-response evidence; vendor caseload is not a universal enterprise benchmark and the report does not establish AI as the sole cause of faster exfiltration.
- Mandiant. 2026. Staying Ahead of Adversarial AI Through Agentic Source Code Review, August 18.
- UK National Cyber Security Centre. 2025. Impact of AI on Cyber Threat from Now to 2027. The assessment expects AI principally to enhance existing TTPs in the near term, while highlighting shortening vulnerability windows and particular exposure for CNI/OT.
- Financial Stability Board. 2026. FSB Chair’s Letter to G20 Finance Ministers and Central Bank Governors: August 2026, August 31.
- Federal Bureau of Investigation, Internet Crime Complaint Center. 2024. Criminals Use Generative Artificial Intelligence to Facilitate Financial Fraud; Federal Bureau of Investigation. 2026. 2025 IC3 Annual Report. The report records more than 22,000 complaints reporting AI-related information and more than $30 million in reported business-email-compromise losses involving AI. Applicability: complaint and reported-loss data establish real impersonation/fraud use, not the proportion of enterprise fraud attributable to AI.
Learn More @ Tactive
- AI Task Automation Is Only Half the Workforce Decision
- Before Coding Agents Get More Authority, Find or Enforce the Constraints They Cannot Miss
- Mandating AI Changes What the Adoption Metric Really Means
- The First Release Is Too Early to Declare AI Code Good
- AI Coding Has Made Qualified Review the Scarce Resource
- AI Has Made Coding Cheaper, but Software Ownership More Expensive
- AI Coding Is Not a Productivity Story Yet