Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

AI is already helping some attackers, but Google’s latest reporting does not show fully autonomous malware attacking targets in the wild. In November 2025, Google described one AI-linked sample as experimental and unable to compromise a victim network or device, while separately reporting malware that queried a language model during live operations. By September 2026, Google had documented more automated, agent-enabled attacks—but still drew a line between those workflows and a fully autonomous attack pipeline.

What Google’s warning does—and does not—mean

The original headline’s reassurance and warning refer to different things. Google’s Threat Intelligence Group (GTIG) described PROMPTFLUX as being in development or testing in November 2025; its then-current state did not demonstrate an ability to compromise a victim network or device. That finding was about that sample at that time, not a guarantee that AI-assisted threats generally were harmless.

In the same report, GTIG said PROMPTSTEAL was its first observed case of malware querying a large language model (LLM) in live operations. The two examples had different observed status: PROMPTFLUX was experimental, whereas PROMPTSTEAL’s model queries occurred in operational activity. Neither fact establishes that malware was independently planning and carrying out an entire attack.

The “won’t last long” part of the 2025 headline was a forecast that attackers might refine their techniques—not proof that PROMPTFLUX would become effective. Subsequent reporting documents continuing developments, but it does not establish a guaranteed, linear progression from experimental code to autonomous attacks.

What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
#1 Best Overall

How the evidence changed from 2025 to September 2026

Date and source Observed status What AI did What the evidence supports
5 November 2025, Google GTIG PROMPTFLUX was in development or testing; PROMPTSTEAL was observed querying an LLM in live operations. PROMPTFLUX used Gemini API requests in attempted code obfuscation and regeneration. PROMPTSTEAL used an LLM to generate commands. AI use in malicious activity was real, but GTIG said PROMPTFLUX in its then-current state could not compromise a victim network or device.
6 November 2025, IT Pro Report on Google’s findings. Summarized the experimental samples and the prospect that attackers might refine techniques. The prediction about future improvement should not be confused with demonstrated effectiveness of the samples.
12 February 2026, Google GTIG Late-2025 AI-enabled examples were characterized as proof of concept and early indicators. GTIG also described conventional AI-generated capabilities being integrated across the attack lifecycle. Google said it had not seen experimental techniques produce a revolutionary shift in the threat landscape.
11 May 2026, Google GTIG Further AI-assisted development and operational capabilities were documented. Examples included vulnerability discovery and exploit development, obfuscation and polymorphic malware development, and PROMPTSPY’s dynamic command generation based on interpreted system state. AI was being applied to more stages of malicious activity; the report also described defensive uses for vulnerability discovery and code fixing.
8 September 2026, Google GTIG Agentic workflows and AI-enabled automation had advanced, but GTIG had not observed fully autonomous pipelines deployed against targets in the wild. In a Q2 2026 case, actors who compromised a cloud resource planned, built and executed an agent-enabled mass credential-harvesting campaign in under six hours. Automation can make an attacker’s workflow faster and more coordinated; the case is not evidence of an entirely autonomous attack pipeline.

What “AI malware” can mean

The label covers materially different behaviors. Sometimes an attacker uses ordinary AI tools to research targets, draft code or help with operations; the malicious program itself may not call a model. In other cases, malware sends prompts to an LLM or uses model-generated output to alter code or produce commands. More agentic workflows can coordinate tasks, but a human operator may still select the target, provide access, set goals or oversee execution.

  • AI-assisted attacker work: A person uses AI during development or operations. This is AI use in an attack, but does not by itself make the malware AI-powered.
  • Model-assisted malware behavior: A program queries a model or uses generated commands or code. PROMPTSTEAL and PROMPTFLUX illustrate distinct versions of this category in GTIG’s November 2025 account.
  • Agent-enabled workflow: AI helps coordinate or automate multiple actions. GTIG’s September 2026 example involved a campaign built and executed by actors after cloud-resource compromise; GTIG said it had not seen fully autonomous pipelines deployed against targets in the wild.

These categories are not a single severity scale. A tool that generates a command, a sample attempting code obfuscation, and a workflow that coordinates campaign tasks present different capabilities and evidence. GTIG’s reports describe its observations and assessments, not a census of all malware activity.

Can AI write malware that changes itself?

AI can be used in attempts to generate or alter code, and Google’s reports describe obfuscation and polymorphic malware development among the techniques actors explored. PROMPTFLUX, in the November 2025 report, used Gemini API requests in attempted code obfuscation and regeneration. But GTIG said that sample’s then-current state did not demonstrate an ability to compromise a victim network or device.

That distinction matters: an attempt to change or obscure code is not proof of reliable self-modification, successful infection, or evasion of security tools. The May 2026 report’s discussion of AI-enabled obfuscation and polymorphic malware points to further development, not a blanket finding that every such sample works or can autonomously adapt during an attack.

Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Should you worry about AI malware?

Concern is reasonable, but the evidence does not support treating “AI malware” as a new class of unstoppable software. Google’s February 2026 update called late-2025 proof-of-concept examples early indicators, not a revolutionary paradigm shift. Its September 2026 report described more agentic activity while explicitly stating that it had not observed fully autonomous pipelines attacking targets in the wild.

For an individual reader, the practical distinction is that AI can help attackers work faster or produce more capable components, while the familiar risks—malicious files, stolen credentials and compromised accounts or services—remain relevant. The cited threat reports do not evaluate consumer antivirus products or establish which products detect these samples, so they cannot support a specific product recommendation or a promise of protection.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

AI is also being used for defense

The same technology can assist defenders. Google’s May 2026 report discussed AI agents for vulnerability discovery and automated code fixing alongside attacker uses such as vulnerability research and exploit development. AI does not inherently make an activity malicious: the context, operator, target and resulting behavior determine whether it is defensive or harmful.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.