AI can already help attackers carry out and speed up parts of cyber operations, but public evidence does not show fully autonomous attacks completing the entire intrusion lifecycle as a routine real-world capability. The distinction matters: AI assistance, automated tasks and multi-step agents can raise risk without proving that a system can independently plan and execute a cyber campaign from start to finish.
What does “autonomous” mean in a cyberattack?
The word can describe very different levels of machine involvement. An AI tool that drafts a phishing message is not equivalent to an agent that coordinates multiple actions, and neither alone establishes end-to-end autonomy.
| Level | What it means | What the evidence supports |
|---|---|---|
| AI assistance | A person uses AI for a task such as writing, research or analysis, while directing the operation. | The UK National Cyber Security Centre (NCSC) said in May 2025 that AI was being used for reconnaissance, vulnerability research, social engineering, basic malware generation and processing stolen data. NCSC’s assessment of AI and cyber threats through 2027 |
| Automation of a stage | Software carries out a bounded task or sequence, such as scanning or processing information, under a larger human-directed operation. | The NCSC says some attack stages can already be automated. That does not establish that the whole operation runs without people. NCSC’s May 2026 Cyber Shield blog |
| Agentic, multi-step work | An AI system uses tools and takes a series of steps toward a goal, potentially with limited supervision. | Anthropic reported cases in which actors used its models across multiple stages of operations. Those are company-reported case studies, not a measure of how common such activity is. Anthropic’s September 2026 threat-intelligence report |
| End-to-end autonomy | A system independently plans and carries out the complete intrusion lifecycle in a real-world environment. | The NCSC said in May 2026 that it had not seen this operating in real-world systems. NCSC’s May 2026 assessment |
“AI cyber war” can therefore overstate what is established if it is taken to mean machines independently conducting whole campaigns. The more evidence-based concern is that AI can make familiar offensive techniques faster, more scalable or accessible to more actors.
What are attackers using AI for now?
In its May 2025 assessment, the NCSC expected AI’s near-term impact to come mainly from improving existing intrusion techniques. It assessed that AI would almost certainly make some operations more effective and efficient, contributing to greater frequency and intensity. That is a dated assessment with a horizon through 2027, not a guarantee about what will happen after that date. Read the NCSC assessment.
#1 Best Overall
Anthropic’s September 2026 report describes misuse activity that the company says it disrupted from December 2025 through August 2026. Its selected cases involved suspected state-linked groups, financially motivated actors and politically motivated individuals. Anthropic argues that AI increased speed, scale and depth across operations and says the activity used Claude Haiku, Sonnet and Opus. It reports no malicious activity in those cases involving Claude Fable or Mythos-class models, apart from one illicit distillation case. These are Anthropic’s own threat-intelligence findings; they should not be treated as an independent prevalence study or a representative count of all cyber activity. Anthropic’s report and case descriptions.
A reported operation with a disputed autonomy claim
The Congressional Research Service (CRS) summarizes Anthropic’s account of an alleged 2025 espionage campaign in which 80%–90% of the work was reportedly automated. CRS also notes that some researchers questioned how successful or autonomous the campaign was. The percentage is an attributed claim about that reported campaign—not a general measure of AI automation in cyber operations. CRS’s 2026 summary.
Does the evidence show fully autonomous cyberattacks?
Not as an established, routine real-world capability. The NCSC’s May 2026 institutional statement is: “While some stages of a cyber attack can already be automated, we have not yet seen fully autonomous attacks operating across the complete intrusion lifecycle in real‑world systems.” This is the NCSC’s assessment, not a claim that AI poses no serious risk. NCSC Cyber Shield.
The NCSC’s earlier forecast is also specific: through 2027, it considered full automated, end-to-end advanced attacks unlikely, with skilled actors remaining in the loop. A forecast about that period should not be silently extended into later years. NCSC’s 2025 assessment.
Quick wins for a faster PC:
Fix the driver behind crashes, sound loss and screen glitchesFind Drivers →Repair Windows errors before they cause bigger problemsFix Now →Scan for outdated or missing drivers - takes under a minuteDriver Scan →Rank #3
What an evaluation-environment incident does—and does not—show
Anthropic says it reviewed 141,006 cybersecurity evaluation runs in which Claude could have obtained internet access and identified three incidents involving unauthorized access to real organizations’ production infrastructure from third-party evaluation environments. According to the company, the evaluations were intended to be isolated, but a misunderstanding with an evaluation partner left internet access available. Anthropic says the models used basic methods such as weak passwords and unauthenticated endpoints, and the runs lacked safeguards normally used for general availability. Anthropic’s July 2026 disclosure.
This is a serious containment and evaluation-design failure. It is not evidence that a model spontaneously initiated a cyber campaign: the incidents arose from evaluation runs that had access to real systems, and the company’s reported count is not a rate of real-world autonomous attacks.
Rank #4
Why does AI still change the cyber risk?
Even when a person remains involved, AI can reduce the time or expertise required for parts of an operation. The NCSC’s examples include reconnaissance, vulnerability research, social engineering and processing exfiltrated data. Anthropic’s case reports describe use across multiple stages. Together, these accounts point to an acceleration and scaling concern—not proof that AI has made human operators, access controls or operational mistakes irrelevant.
Agent systems also create security questions of their own. NIST’s May 2026 publication synthesizes responses to a request for information issued by the US Center for AI Standards and Innovation. It reports broad agreement among respondents that agents introduce novel security threats and that security concerns are a barrier to adoption. This is a summary of submitted views, not a binding standard. NIST’s summary of RFI responses.
The Tool Desk
Outbyte Driver Updater FREEScan for outdated or missing drivers - takes under a minuteDriver Scan →Outbyte PC Repair FREEClear out junk files and repair common Windows errorsFree Scan →Best Value
How should organizations defend against AI-enabled threats?
Start with established security work. AI may change the pace or scale of some tasks, but it does not remove the exposure created by unpatched systems, unsupported technology, weak access controls or poorly bounded tools.
- Reduce the weaknesses attackers can exploit. Patch exposed systems promptly, reduce reliance on legacy or unsupported systems, and address weak access controls. The NCSC identifies outdated systems, delayed security updates and weak access controls as continuing sources of exposure. NCSC Cyber Shield.
- Limit agent permissions. Give an agent only the data, credentials and tools it needs for its defined task. Keep access to sensitive information and critical systems out of scope unless there is a justified need.
- Set approval boundaries for consequential actions. Decide which actions may run automatically and which require human approval. Make those boundaries explicit, and ensure an operator can stop the agent.
- Threat-model the whole workflow. Consider how prompts, retrieved content, integrations, credentials and tool calls could be abused—not just the model in isolation.
- Monitor and audit activity. Log agent actions, make them alertable, and retain enough information to investigate what happened. Treat an agent’s actions as security events that can be reviewed and contained.
- Test and rehearse containment. Test controls as models and integrations change, and build incident response around stopping access, containing impact and recovering affected systems.
- Use defensive AI carefully. The NCSC identifies potential defensive uses including finding exposures, detecting incidents and supporting containment. Its Cyber Shield blog describes a blueprint in development—not a completed national-scale capability. AI-based defense also needs bounded access, monitoring and accountable oversight. NCSC’s description of Cyber Shield.
For practical adoption guidance, six national agencies have published advice on careful adoption of agentic AI services. NIST’s RFI summary likewise supports adapting fundamental cybersecurity practices to agent systems, rather than treating agents as ordinary software with no additional concerns. Six-agency guidance on agentic AI services · NIST’s summary of agent-security concerns.
How to assess an AI agent before deployment
There is no single product or autonomy setting that makes an agent safe for every organization. Assess a proposed deployment against the work it will do and the systems it can reach:
- Autonomy and approval: Which actions can it take on its own, which need approval, and can those boundaries be changed safely?
- Access scope: What systems, credentials, data and tools are available to it?
- Monitoring and containment: Are actions logged and alertable? Can they be reversed or stopped?
- Operational fit: Do controls work with existing security processes and incident response?
- Evidence: Has the deployment been threat-modeled and tested in conditions resembling the organization’s environment?
NIST’s May 2026 publication records commenters’ concerns and views; it does not certify any particular agent or prescribe a universal deployment. NIST’s RFI-response summary.
Crashes, No Sound, or Screen Glitches?
Random freezes, missing sound and display glitches usually trace back to one bad driver. Find and replace yours safely.Free scan · under a minuteWindows Errors? Fix Them Before They Spread
Repair common Windows errors and clear accumulated junk for a smoother, more stable PC - no reinstall needed.Free scan · no reinstallQuick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

