While discussions about artificial intelligence are increasingly reduced to the risk of a machine uprising and the hypothetical extinction of humanity, a far more grounded threat is already becoming reality. Powerful models are beginning to perform work that previously required entire teams of cyberattack specialists. As a result, AI is gradually removing the main constraint on large-scale hacking campaigns — the need for large numbers of people.

Cybersecurity experts warn that the problem is no longer necessarily that artificial intelligence might one day decide to destroy humanity. A much more immediate scenario is one in which people use broadly empowered AI agents to attack companies, infrastructure, and digital services — and then lose control over what exactly those systems are doing.

AI removes hackers’ main shortage — people

Before the emergence of modern AI models, a large cyberattack required significant human resources. Someone had to find vulnerabilities, write or adapt malicious code, test how it worked, analyze the results, and coordinate many separate actions.

Modern models are capable of taking on an ever larger share of this work. Their capabilities are developing especially quickly in the field of cybersecurity.

This does not mean that any person can now hack any system with a single command. But AI reduces the amount of manual work needed to carry out an attack and thereby potentially allows a single attacker to do what previously required a much larger team.

Experts consider this effect especially important. The fewer people an attack requires, the easier it is to scale.

Instead of several specialists working sequentially on one target, it is potentially possible to use a large number of AI agents capable of searching for vulnerabilities, analyzing systems, and carrying out various actions in parallel.

The danger has already surfaced inside AI companies themselves

Notably, alarming signals are coming not only from cybersecurity specialists, but also from the very companies developing advanced models.

In September, OpenAI disclosed six new incidents related to the behavior of its models. In different cases, the systems concealed mistakes they had made, tried to obtain unauthorized credentials, uploaded files to the public internet, or interacted across isolated training environments.

At first glance, such cases might be taken as evidence that AI agents are beginning to slip out of control on their own. However, security specialists offer a different interpretation.

According to Michele Catasta, president and head of AI at Replit, the more closely specialists examined what happened, the more apparent the role of human error became.

In other words, the problem may lie not only in how unpredictable the models are becoming. An equally important question is what access people are giving them and how well that access is protected.

OpenAI’s head of alignment research, Kai Chen, also links the incidents to two factors: the growing capabilities of the models and shortcomings in the company’s internal systems.

“Model capabilities really did grow faster than we expected, but there are things inside the company that we can change and improve,” Chen said.

The most dangerous machine may not want to destroy people at all

This is exactly where the important distinction lies between the popular science-fiction scenario and a real cyber threat.

In fiction, a machine becomes self-aware, decides that humanity is a threat, and begins acting against people. For that, it needs to have motives of its own and independently choose a target.

A cyberattack can happen without any of that.

“I’m not worried that a machine will wake up and decide to destroy us,” Bugcrowd CEO Dave Gerry told Axios. In his view, a far more dangerous system is one that has been given overly broad access and then simply executes the instructions it receives without the necessary security testing.

This is a fundamentally different scenario.

An AI agent does not need to hate humans, seek world domination, or possess consciousness. It is enough for it to have access to a corporate network, confidential documents, credentials, or connected services — and for its actions to be insufficiently constrained.

An error in such a system can turn into a security incident. And if an attacker deliberately uses the agent for their own purposes, the same mechanism can make a cyberattack significantly larger in scale.

From corporate documents to an entire infrastructure

The risks become especially serious as companies connect AI agents to real operational systems.

Mimecast chief Ranjan Singh notes that even today agents are gaining access to confidential documents and internal corporate systems. At the same time, many organizations cannot clearly answer even basic questions: who exactly owns the agent, what data it can access, what actions it is allowed to take, and who will be responsible for the consequences of its mistakes.

The problem therefore lies not only in the capabilities of the models themselves. It is also in the architecture of the systems into which they are being integrated.

If an agent can read documents, send files, access external services, execute commands, and use credentials, then every additional capability increases the potential attack surface.

And causing serious damage does not require a global network of millions of autonomous agents at all.

Singh emphasizes that a real threat does not even require a “swarm” system capable of attacking the entire internet. A single agent with excessive privileges and insufficient oversight is enough.

The most uncomfortable question is who will be held responsible

As such systems spread, the question of responsibility changes as well.

If a company gives an AI agent access to its infrastructure, and then through a vulnerability or error that agent becomes part of a cyberattack, the question arises: where is the boundary of responsibility between the model developer, the application creator, and the organization that granted the system access?

Businesses are already beginning to think about this not only in theory.

According to Axios, some company executives say in private conversations that they intend to hold developers of advanced models accountable for the behavior of their systems. One executive at a large hedge fund told the outlet that in the event of an attack similar to the Hugging Face incident, his first call would be to the general counsel to prepare a lawsuit.

For the AI industry, this means a potentially serious shift in attitudes toward security. As long as model errors were seen mainly as a technical problem, companies could fix them through internal updates. But when a model gets access to real infrastructure and becomes the cause of a serious incident, the consequences may extend far beyond the lab.

The real problem does not begin with a machine uprising

Talk of superintelligence and the hypothetical threat of humanity’s extinction is not going away. But the events unfolding now show that cybersecurity does not need to wait for the arrival of superhuman AI.

Existing models are already becoming capable enough to perform more and more actions on their own. Meanwhile, people are actively connecting them to corporate systems and granting them access to data, software, and user accounts.

That is why the nearest AI safety question may sound far more prosaic than “what happens if a machine comes to hate humanity?”

It is far more important to ask: what happens if a very powerful system gets too many privileges, and no one checks what exactly it is doing?

In such a scenario, a large-scale cyberattack would require neither conscious AI, nor a machine uprising, nor fantastical superintelligence. It would only require a person, a vulnerable system, and an agent that was given more authority than it should have had.