Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

AI is making attacks faster and cheaper to run, but the evidence so far shows acceleration of familiar attack steps, not routine, fully autonomous intrusions. Security teams should respond by tightening the basics attackers still exploit, such as exposed services and weak identity controls. They should also govern the AI systems they run themselves, and prepare to detect and contain incidents at a pace manual processes can’t match.

This article separates what threat reports document from what they don’t, then turns the guidance from Google, Microsoft and CISA into a practical order of work.

What AI has actually changed in attacker activity

The clearest picture comes from three sources: Google Cloud/Mandiant’s March 2026 review of 2025, the Google Threat Intelligence Group (GTIG) report from September 2026, and Microsoft’s 2025 Digital Defense Report. All three describe their own telemetry and observations. None is a census of every attack, so treat them as strong signals rather than totals.

From experiments to operational use

Google’s year-in-review describes 2025 as a shift from experimentation toward operational integration. Early uses were mundane and productivity-oriented: translating content, researching vulnerabilities, drafting multilingual phishing lures and helping write code. Later examples were more worrying. The report discusses malware families it calls PROMPTFLUX and PROMPTSTEAL, which query a large language model for code or commands while running. Because the behavior can change from run to run, signature-based detection has a harder job. These are reported observations about specific malware. They don’t show that malware in general is AI-powered.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Faster operations, with a human still involved

GTIG’s September 2026 report adds evidence of agentic and multi-agent workflows, AI-assisted credential harvesting, and attacks aimed at coding assistants, security scanners, AI credentials and proprietary AI assets. Its headline example is a credential-harvesting campaign assembled and executed in under six hours after a cloud-resource compromise. That is a concrete case of human delay being squeezed out of the process.

The same report says GTIG had not observed fully autonomous pipelines for zero-day discovery and network intrusion deployed against targets in the wild. Both statements hold together: operations are getting faster and more automated, but end-to-end autonomous attack capability was unobserved as of that report.

Most observed threats still hit known gaps

Microsoft describes AI-automated phishing and multi-stage attacks, and also adversaries exploiting poorly secured AI workloads and using synthetic media. But it says most observed threats still targeted known gaps such as web assets and remote services. On identity, Microsoft’s 2025 Digital Defense Report found that 97% of identity attacks were password spray attacks. Old identity weaknesses haven’t gone away because new tools arrived.

Claim What the evidence supports What it does not support
Attackers use AI Reconnaissance, translation, lure drafting, coding and some runtime malware behavior (Google, March 2026) That all malware or all attackers use AI
Attacks are faster A credential-harvesting campaign built and run in under six hours after a cloud-resource compromise (GTIG, September 2026) That this speed is typical of every intrusion
Attacks are autonomous Agentic workflows that reduce human involvement Fully autonomous zero-day discovery and intrusion in the wild; GTIG had not observed it
Basics no longer matter Nothing supports this Microsoft reports most observed threats still target known gaps, and 97% of identity attacks were password spray

Your own AI is part of the attack surface

The speed problem has a second half: attackers aren’t only using AI, they’re going after yours. GTIG’s September 2026 report describes attacks on AI assets and AI-related software supply chains, including coding assistants, security scanners and AI credentials. Google’s year-in-review names shadow AI and lack of AI asset visibility as practical gaps. If nobody can list which AI tools, models, API keys and dependencies exist, nobody can defend them.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

How to adapt: a practical order of work

The steps below follow the guidance from Google/Mandiant, Microsoft and the joint agentic-AI guidance announced by CISA on May 1, 2026. The sequencing, and the last item in particular, is editorial judgment built on those sources rather than a published checklist.

1. Get visibility and governance in place

  • Inventory approved AI tools, AI workloads, models, the data they touch and a named owner for each.
  • Find shadow AI: unsanctioned assistants, browser tools and personal accounts used with company data.
  • Track AI-related credentials and software dependencies as assets, since GTIG reports both being targeted.
  • Set clear usage rules so staff know what is allowed and where to ask.

2. Keep agent permissions narrow

The joint guidance from CISA and partner agencies recommends “limiting agent autonomy by ensuring agents are not granted broad or unrestricted access—especially to sensitive data or critical systems,” as quoted in CISA’s May 1, 2026 announcement. In practice:

  • Give each agent its own identity and the minimum permissions for its task.
  • Keep agents away from sensitive data and critical systems unless the use case truly requires access.
  • Scale human approval to the impact of the action. Reading a ticket and deleting a production resource shouldn’t share the same approval path.

3. Fix identity and the known gaps first

Given Microsoft’s finding that most observed threats still exploit known gaps, review internet-facing web assets and remote services, prioritize known vulnerabilities, and harden accounts against password spray. The CISA guidance likewise stresses strong identity management and layered defenses. AI-enabled methods make exploitation of weak controls quicker; they don’t make strong controls obsolete.

4. Threat-model and monitor AI systems

CISA and its partners call for threat modeling, continuous monitoring and regular security assessments. For AI systems, scope should include:

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
  • Prompt-based attacks against assistants and agents
  • Software supply-chain exposure, including plugins, packages and model dependencies
  • Credential theft and privilege escalation through AI tooling
  • Unintended agent actions, not just malicious ones

Re-test after meaningful changes such as new tools, new integrations and expanded agent permissions.

5. Use AI defensively, but validate it

Microsoft describes defenders using AI for threat analysis, identifying gaps and automated response. That is worth pursuing, with limits. Test detections against realistic scenarios, keep human oversight over consequential actions, and make sure your team can explain and trust the procedures the automation follows.

6. Prepare to respond at machine speed

If a campaign can go from a cloud compromise to harvested credentials in under six hours, a response plan that depends on a Monday morning meeting is too slow. Before enabling automation that can suspend accounts or change systems, decide:

  • Who may authorize containment, and who can do so out of hours
  • How compromised accounts and credentials, including AI service keys, are revoked and recovered
  • Which automated actions are reversible, and which need a human first
  • How often incident exercises run, and whether they include an AI-assisted attack scenario
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Governance-first or AI-tooling-first?

Teams often frame the choice as buying AI security tools versus building governance. The cited guidance doesn’t rank vendors or approaches, but you can compare any strategy on five axes drawn from it:

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Axis Questions to ask
Foundational coverage Does it address exposed services, identity weaknesses and AI assets?
Agent control Can you limit agent identity, permissions and require human approval?
Visibility Can you monitor across AI systems and the software supply chain?
Testability Can you test detections and response procedures, not just deploy them?
Fit Does it match your risk posture and the staff you actually have to run it?

A tooling-first approach tends to score well on visibility but can leave agent permissions and response authority undefined. A governance-first approach covers control and fit, but without monitoring it can’t show whether the rules are followed. For most organizations the answer is governance and identity work first, then tools that make those controls measurable.

Limits of the evidence

These findings come from vendor and government sources reporting their own telemetry or guidance, and the research was current as of early October 2026. Attacker tactics shift quickly, so a statement such as “not observed in the wild” can change with the next report. Check the latest GTIG, Microsoft and CISA publications before making budget decisions on the basis of any single figure.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.