We’ve seen plenty of articles and doom and gloom about AI agents leaving their homes and attacking systems all around. Finding novel ways to hack and leaving no traces.
Let’s actually have a look at what it means and what we can do instead of just panicking.
First things first. What should make us worried?
AI has made a thing that needed people and was time-consuming fairly straightforward. To a degree. What AI is great at is “Try something, find out how to get around the error you got and try that”, and just iterating, effectively chaining together different attacks, including social engineering. How it “knows” what to do next is that a lot of attacks and solutions to errors are documented across the internet. So it picks them up and makes changes to scripts to fit the situation. A bit of a simplification, but it’s closer to reality than the doom.
Previously, the more sophisticated scripts would be written by hacking groups, and to a smaller degree they would be available to use by less experienced users (what we call script kiddies). People who would download a script, run it against some systems and see what happens. They might not be able to update the script or necessarily easily work around the first line of defence. Now they can.
Now anyone can perform fairly sophisticated attacks, and quite cheaply.
What it means is that a lot of smaller companies, who would not have been worth attacking for more sophisticated groups, might now be at the centre of it.
That wouldn’t be a problem if all the security across companies were top-notch. However, that’s not the case. What this has shown us is that we will need to invest more in cyber security and take it a bit more seriously, as a random teenager could get your and your clients’ data if they have an hour to spare and want some cryptocurrency to pay for their Counter-Strike skins.
You would never be interesting enough for a group, but you might be a line on a spreadsheet of companies an AI agent will be iterating through. They might break into one in a hundred, and that could be worthwhile.
What will make this worse is the rise of vibe coding. Having more systems quickly put together without expertise will increase the exposure and possible ways in.
My suspicion is that we will see a rise in data breaches and ransomware.
“Wait, if AI can hack, can it also help us to set up our systems better?”
YES! Thank you for asking. Such a thoughtful thought.
AI as part of the development process and system review can highlight gaps people would miss. It can automate penetration testing and run it regularly, rather than once a year, as it would be done manually by a third party.
It can help you keep up to date with vulnerabilities and translate them into understandable solutions. AI can proactively monitor logs to look for anomalies and potential issues. It can tie together multiple isolated security flags across your systems to help you understand that something else might be afoot.
But it can also get it wrong. That’s why we need expertise as part of the process. And a “Make no mistakes, full security” prompt will not do the job.
What AI agents have changed is that they have put us technologists on the back foot a bit more, and we need to catch up. Luckily, we already have standards and practices for information security. There is no need to reinvent the wheel; we just need to be more diligent in applying them.