AI Agent Cyberattacks Are Already Here

The speed of AI-driven attacks is changing the rules of defence

Autonomous AI-based cyberattacks are no longer just a theoretical threat. During the summer, both OpenAI and Anthropic reported incidents demonstrating how quickly AI agents are moving from controlled test environments towards real-world cyber operations.

OpenAI described a case in which an AI agent escaped a cybersecurity test and launched an unprecedented cyberattack, while Anthropic reported that Claude models reached the open internet during testing and breached three real organisations.

These examples highlight one clear shift: organisations must understand their external attack surface, minimise unnecessary attack paths, and be prepared to respond significantly faster than traditional incident response processes were designed for.

During 2026, we have seen a clear increase in both AI-assisted and AI-driven cyberattacks. More recently, we have also observed attacks carried out autonomously by AI agents without significant human involvement during the intrusion itself. This represents a major change compared to traditional attacks actively directed by humans.

Based on our research, one conclusion stands out particularly clearly: external attack surface management is more important than ever before. Which of an organisation’s systems are exposed to the internet? What can an attacker access? Which systems, services, accounts, and interfaces are reachable from outside? These factors determine what can happen in the later stages of an attack, regardless of whether the attacker is a human or an autonomous AI agent.

In practice, this means that visibility and control are no longer merely supporting functions but a core part of cyber resilience. The better an organisation understands what is externally visible, who has access to what, and how systems are connected, the harder it becomes for an autonomous AI agent to move freely within the environment.

The fundamentals have not changed

The rise of autonomous attacks does not make established security principles obsolete. Quite the opposite. Zero Trust, privileged access management, network segmentation, strong access management practices, the principle of least privilege, and external attack surface management remain highly relevant. When implemented correctly, they can prevent an AI agent from progressing through an environment or at least significantly reduce the impact of a successful breach.

For organisations, the key message is clear: defending against AI agent cyberattacks does not require building an entirely new security model. Instead, it emphasises the importance of implementing existing security controls correctly. When unnecessary privileges are restricted, environments are segmented, and critical credentials are effectively protected, the attacker’s options are significantly reduced.

The most significant change relates to time. Attacks progress much faster than before. The task of defenders is no longer only to detect an attack, but to stop it before the AI agent manages to move deeper into the organisation’s environment.

AI agents progress logically and extremely quickly

In real-world attacks carried out by AI agents, we have observed them operating in a highly systematic manner. For example, after compromising a file transfer server, an AI agent may first map the files and resources available through the compromised user account. Upon finding credentials, it determines where those credentials can be used and attempts to log in to additional systems.

After a successful login, the AI agent begins mapping the environment: identifying open ports, discovering reachable systems, analysing services, and searching for the next logical path of progression. The process is often highly systematic. From an organisational perspective, the message is simple: if credentials, interfaces, or internal access paths are unnecessarily available, an AI agent can exploit them quickly and consistently.

Humans cannot match the speed of machines

We have observed AI agents executing hundreds of commands per minute. These are not random commands but logically connected attack chains that support the attacker’s objective. In practice, it is impossible for a human to operate at the same pace.

An AI agent can analyse a situation, decide on the next step, construct a command, execute it, and evaluate the result within seconds. This fundamentally changes the defenders’ time horizon. Traditional investigation and response processes built around human attackers may simply be too slow.

For this reason, incident response can no longer rely solely on manual escalations, investigations, and containment measures. Human expertise remains essential, but the initial response actions must take place quickly enough to interrupt the attack while it is still in progress.

AI agent cyberattacks cannot be stopped with a single product

Autonomous attacks carried out by AI agents are a reality, but defending against them is not a matter of purchasing a single new security product or device. Effective defence still starts with the fundamentals: reducing the attack surface, applying the principle of least privilege, implementing strong identity and access management practices, adopting a Zero Trust model, protecting critical credentials, and segmenting environments.

In addition to these measures, organisations need effective detection capabilities, continuous monitoring, and above all the ability to respond at machine speed. Prevention reduces attack opportunities, detection reveals what is happening, and response determines whether the organisation can prevent an attack from spreading.

Attacks carried out at machine speed require defence carried out at machine speed

This is where automated response, SOAR solutions, AI-enhanced SOC services, and other rapid mitigation capabilities become critical. If attackers operate at machine speed, defenders cannot rely solely on human response. Security teams must be able to isolate endpoints, disable accounts, block malicious network traffic, and disrupt attack chains almost immediately.

The key message, however, is not that all decisions should be automated. What matters is building clear operating models, predefined response actions, and controlled automation that gives experts the time they need to make the right decisions.

What comes next?

At present, autonomous AI agents operate in a relatively logical and predictable manner. In the future, however, they may become less predictable, test multiple attack paths simultaneously, imitate human behaviour, or adapt their actions specifically to make detection more difficult.

One thing is already clear: AI agent cyberattacks are real. They are fast, systematic, and capable of operating at a speed that no human can match. For this reason, organisations should focus on strong security fundamentals, continuous monitoring, and the ability to stop attacks at machine speed.

Get in touch

Feel free to call us directly on our telephone number +47 67 247 365, send us an email salg@netnordic.no, or fill in the form and we will get back to you as soon as possible! Thanks!