AI’s biggest cybersecurity problem may be the people using it
Artificial intelligence is increasing the speed and sophistication of cyberattacks, but people remain the main threat behind its misuse, cybersecurity experts say.
Recent incidents involving AI models breaking out of controlled testing environments and accessing external systems have raised concerns about increasingly autonomous cyberattacks. However, researchers say such cases remain highly specific and mainly demonstrate how humans can use AI to amplify existing criminal techniques.
AI has enabled malicious actors to create malware, research targets, produce convincing scams and automate attacks on an unprecedented scale.
One in four data breaches recorded between February 2025 and March 2026 was driven by AI, according to an IBM report. The FBI says Americans lost more than $893m to AI-related scams last year.
Despite the growing capabilities of AI systems, experts argue that criminals remain in control.
“It’s the humans that we need to watch out for,” said Oren Etzioni, professor emeritus at the University of Washington and former chief executive of the Allen Institute for Artificial Intelligence. “AI is just the tool.”
Several incidents in recent weeks have highlighted the risks. In July, OpenAI test models escaped their constraints and hacked into other companies' systems during an internal cybersecurity evaluation. Anthropic later said its models had breached three companies during testing, while researchers at Britain's AI Security Institute found that an advanced Anthropic model used fake identities to attempt to deceive people. Meta has also reported that one of its AI models broke into an external company's systems.
The incidents have highlighted how difficult it can be to predict how AI systems interpret instructions. OpenAI's models breached another company's system even though they had not been explicitly told to do so.
Patrick Fussell, global head of adversary simulation at IBM, compared AI to a genie.
“You want to ask it a wish, but you have to be very, very specific about the details of your wish,” he told CNN. “Or it could sort of go awry.”
However, the incidents occurred under controlled testing conditions in which normal safeguards had been deliberately removed.
“I couldn’t go into ChatGPT or Claude or something like that, and it accidentally breaks into the FBI. That’s not going to happen,” said Adam Meyers, head of counter adversary operations at cybersecurity company CrowdStrike.
“So what we’re seeing is these are done in specific test conditions where they’re monitoring to see, ‘Does this thing do something that it’s not expected to do?”
Experts say AI is currently helping criminals make established attack methods more efficient rather than independently creating entirely new forms of cybercrime.
Criminals can use AI to identify potential targets, create malicious websites and infrastructure, and automate communications with victims. AI agents can also imitate human conversations through text and voice, making phishing, fraud and extortion attempts more convincing.
“They’re using (AI) to enhance the cyberattack methodology, essentially, in all the different stages, but it’s still kind of being run by the human,” said Jud Dressler, head of the risk operations centre at cyber insurance firm Resilience.
“With AI, they could automate that buildout, and so the cost of rebuilding became very small and that changes the game,” said Rob Lefferts, corporate vice-president of threat protection at Microsoft.
The recent incidents have nevertheless prompted warnings about future AI-related threats. Experts say organisations should strengthen basic cybersecurity measures, including fixing vulnerabilities, monitoring AI agents and remaining alert to phishing and social-engineering attacks.
The developments have also intensified debate over the pace of AI development. More than 1,200 workers at leading AI companies, including Anthropic chief executive Dario Amodei, have signed an open letter calling for greater government involvement, while the White House has discussed a framework for reviewing certain AI models before release.
The prospect of artificial general intelligence has added to concerns about future cyber risks. But cybersecurity researchers say systems capable of operating at human intelligence levels remain well beyond current capabilities.
“It’s like asking someone, ‘What would it be like to live on a different planet?’” Fussell said. “You can sort of imagine, but it’s so beyond our ability to really make a plan for.”
By Aghakazim Guliyev







