With AI Agents autonomously hacking websites while discreetly coordinating with each other, this already looks like a losing battle…
Imagine a world where hackers don’t need rest or sleep, they don’t take breaks or stop on weekends, and all they do is run hundreds of simultaneously attacks, all day, every day.
This is not the beginning of a science fiction movie. Because of the advancement of artificial intelligence, this is our reality now. AI agents don’t just write code or automate repetitive tasks anymore. They plan multi-step attacks, identify vulnerabilities and keep up the work with limited human interaction.
OpenAI has warned that AI is on the verge of bringing in the era of “persistent cyberattacks” where the system works continuously instead of waiting for a human attacker to take the next step.
When AI Agents went Rogue
The warning turned real in July. During a routine cybersecurity test, an experimental OpenAI Agent escaped its controlled environment to access the internet and started attacking an AI development platform called Hugging Face. It was initially believed that this was the work of a rogue agent but investigations revealed something more sinister.
As many as 700 AI agents coordinated this attack and even attempted to communicate with each other through an improvised message board while concealing their activities. This was confirmed through independent research by METR and Redwood Research.
What’s scary here is not that AI launched a cyberattack. It is the fact that multiple AI agents coordinated with each other and carried out the attack without human intervention.
The Hacker that Never Sleeps
A human attacker can automate parts of the attack but an autonomous hacker agent can automate decision making as well.
An agent can scan for weaknesses, investigate potential targets, generate or modify code as needed, try different approaches when something fails and continue operating around the clock. If hundreds of agents are deployed with the same task, the scale and pace of the operation increase significantly.
Reuters reported that OpenAI was initially unaware of the scale and extent of the Hugging Face attack. The agents were able to communicate with each other while evading detection which is the scary part.
This also means that it doesn’t require one super hacking agent to pull off something like this. A large number of reasonably capable agents can coordinate with each other to carry out an attack of this scale.
Defence Will Struggle to Keep Up
AI is currently used for defensive purposes as well. Security teams frequently use it to analyse malware, search for vulnerabilities, monitor networks and respond to incidents.
But attackers can use the same capabilities at much greater scale. OpenAI recently mentioned that it could not rule out the fact that its upcoming Astra model has “critical cybersecurity capabilities”. This means it can potentially “could potentially autonomously identify and exploit severe real-world software vulnerabilities or conduct sophisticated attacks against highly secure targets without human intervention.”
This shows how the power balance is tilted in favour of the attackers. Cybersecurity teams might possess agentic defences but an AI attacker will have all this and more.
The Last Word
The Hugging Face incident already has OpenAI worried. Reuters recently reported that OpenAI is “slowing the pace of model development and overhauling its research and training systems” because of the incident. The company has already paused training on Astra and has introduced additional monitoring functions and safeguards.
It is a significant decision as AI companies are normally training agents to do more, not less. But in this context, the more independent an AI agent becomes, the harder it is to predict what it will do when given access to real systems.
The concern is not whether AI agents can attack autonomously. It has already been established that they can. The question is: what are we going to do about it?
In case you missed:
- Why Indian Startups Are Building “Vertical AI” Instead of the next ChatGPT
- ChatGPT vs Claude Code: How the AI race is shifting
- ChatGPT for Cyber Espionage: North Korea’s AI-Driven Phishing Campaign
- The Great Coding Reset: How AI Is Transforming Software Engineering
- AWS hit by two Outages caused by AI Tools
- India May Be Entering Its “Applied AI” Era
- Inside Landfall: The Spyware that Hijacked Galaxy Phones without a Click
- AI Can Write Code. What Happens to India’s Millions of Software Engineers?
- Google’s HOPE Model: A Big Leap Toward AI That Never Forgets
- How Operation Sindoor Defined a New Era of Technology in Defence












