OpenAI has warned that AI models are getting smart enough to launch cyberattacks on their own…
For the last few years, the concerns around artificial intelligence and cybersecurity were about how AI could power hackers with better tools to carry out their attack. But now the concern is about how AI could start launching attacks on its own. Advanced AI systems are becoming capable enough to find vulnerabilities, plan attacks and carry out parts of them with limited human intervention.
OpenAI is one of the first companies to take note of this. In August, the company noted that its latest model Astra had made such significant progress in cybersecurity and could even reach its highest level of cyber capability. Talking to The Guardian, OpenAI chief global affairs officer Chris Lehane said that we have entered a new phase where organisations may have to defend themselves against “ongoing, persistent” AI-powered attacks.
AI is getting much better at hacking
In July this year, OpenAI agents escaped control during cybersecurity testing and access systems belonging to AI platform Hugging Face. The Guardian had reported this as the first autonomous reported agentic cyberattack. Wired reported that the incident had prompted a major internal safety response at OpenAI.
OpenAI conducted more evaluations and learnt that its Astra model was more than capable of coding and conducting cybersecurity tasks. According to The Guardian, Astra could find and exploit vulnerabilities without human intervention and could even devise attacks from a high-level goal.

Hackers could find vulnerabilities much faster
Until very recently, it required skilled researchers and a lot of time to find software vulnerabilities. But AI an inspect code, test weaknesses and automate parts of this process. Which means that sophisticated cyber capabilities will become cheaper and available to more attackers.
The concern is so major that over a hundred AI companies – including OpenAI, Anthropic, Google, Microsoft, Amazon Web Services, CrowdStrike and Cloudflare – signed an open letter seeking stronger cyber defences.
According to an Axios report, the group believes that there are only months left to prepare before advanced cyber capabilities become more accessible. TechCrunch also expects cyberattacks to become more sophisticated and widespread in the coming months.
Fighting AI with AI
The fact of the matter is also that the same capabilities will help in building better defences against cyberattacks.
Anthropic is already using Claude to search open-source software for security vulnerabilities. According to Anthropic’s vulnerability disclosure dashboard, its programme had disclosed 2,300 vulnerabilities across 392 open-source projects by August. At least, 421 of them have already been patched.
OpenAI is following a similar strategy by providing defenders with powerful AI capabilities to help them discover and fix vulnerabilities before they are exploited.
The Last Word
The problem with this approach is that every significant development helps both sides.
An AI model that is good at finding vulnerabilities can help defenders in fixing them. But the same model in the hands of attackers will aid them in breaking into a system.
Cybersecurity looks all set to become AI’s next battlefield and this could happen very soon. The aforementioned set of hundred companies believe there is only a “limited window” to strengthen defences before AI-enabled attacks become more widespread.
The world might soon witness an AI vs AI battle. It is on the humans to ensure the defenders stay ahead!
In case you missed:
- The Hacker That Never Sleeps: AI Is Changing Cyberattacks
- AI on Trial: Copyright Law caught between Innovation and Litigation
- India May Be Entering Its “Applied AI” Era
- Why You Should Never Reuse Passwords
- ChatGPT for Cyber Espionage: North Korea’s AI-Driven Phishing Campaign
- The Great Coding Reset: How AI Is Transforming Software Engineering
- Inside Landfall: The Spyware that Hijacked Galaxy Phones without a Click
- Privacy Was a Myth. AI Just Proved It
- Dating AI Is Getting So Serious That the Government Is Getting Involved!
- Why Indian Startups Are Building “Vertical AI” Instead of the next ChatGPT












