Easier to build, faster to launch and more destructive than ever before, cyberattacks are getting a significant boost from frontier artificial intelligence (AI) models.
Virkkunen raised concerns that advanced AI models can now build cyber exploits in minutes or hours, posing a direct threat to the security of critical infrastructure and society at large.
While AI is a powerful asset for attackers, it is also a powerful tool for defenders.
Rene van Haaster, vice president EMEA North, Elastic
There is, thankfully, another side to the story. While AI is a powerful asset for attackers, it is also a powerful tool for defenders. Organizations are leveraging AI to reduce their mean time to detect, respond and recover, and to stay ahead of advanced attacks.
The EU’s Action Plan on Cybersecurity and AI not only outlines a coordinated strategy for responding to AI-driven attacks, but also proposes a blueprint for structured access to advanced AI models for the use of IT security teams working within public authorities and private companies.
Adapt and survive
This is an important step forward but, in today’s AI-fueled threat landscape, there are three areas that EU organizations need to consider if they want to keep hackers in check. In short, they must adapt to survive.
The first is control and sovereignty. This is particularly important in Europe, where technological sovereignty has become an increasingly strategic objective.
Organizations need the ability to understand where their data has been created, moved and stored. This is central to their ability to retain meaningful control over the technologies they depend on. In practice, this means avoiding architectures that lock them into specific providers or limit their ability to integrate new capabilities and retaining the freedom to move data in, between, and out of vendors and service providers as their needs evolve. Vendor lock-in is a procurement concern, and one that many organizations seek to escape from.
Open source can help address this challenge. It enables organizations to reduce dependence on any single supplier, combine multiple technologies, switch providers, maintain systems independently or engage local service providers to do so on their behalf. This contrasts with most closed-source IT security products, where continuity of service is by no means a given, especially as vendors can change their commercial terms or exit the market altogether.
Additional advantages lie in code being publicly available for inspection and modification. Open-source technologies are continuously reviewed, maintained and improved by a global development community of people working together to make updates, address gaps, fix bugs and test security tools. They are built by the community for the community and the benefit of the industry.
The second consideration is economics. Typically, implementing IT security technologies involves a range of structural costs and licensing penalties from vendors that make little sense in a world of rising threats and stagnant or even shrinking budgets.
Some of these costs introduce unnecessary risk, like per-device fees that may force organizations to leave lower-priority endpoints unguarded. Some organizations also pay extra costs associated with add-on technologies for automating security processes to coordinate response workflows. Others are dealing with the considerable financial risks involved in using large language models (LLMs) that don’t adequately explain or keep a record of decisions for auditing purposes. During incident response, there are also the high costs and delays attached to retrieving historical data for analytical purposes.
Fragmented tools and restrictive pricing models force IT security teams into a risky game of balancing protection and cost. The objective should therefore be to make comprehensive security economically sustainable.
To achieve this, many teams are looking toward platforms that consolidate monitoring, alerting and response, where pricing is based on compute power and storage.
Organizations are embedding AI agents across the cyber stack, automating high-volume and repetitive tasks. This is not to replace human analysts, but to free them for the work that demands human judgment.
Technology architecture matters too. Sprawling estates of disconnected security tools create operational and financial costs. Bringing logs, signals and alerts together in a unified platform can give teams a full, real-time picture of all activities and behaviors occurring across an IT architecture. The best of these platforms will incorporate AI capabilities to identify threats and automate analytical and management tasks, including reverse-engineering malware, compiling actionable case summaries and predicting future vulnerabilities.
The third consideration is readiness for innovation: agentic security. AI agents can take the pressure off overwhelmed security operations center (SOC) analysts by automatically handling tasks such as data collection, threat prioritization, alert correlation and response planning.
The transition to an agentic SOC is already underway. Organizations are embedding AI agents across the cyber stack, automating high-volume and repetitive tasks. This is not to replace human analysts, but to free them for the work that demands human judgment.
In an agentic SOC, instead of spending hours manually triaging across multiple consoles just to reconstruct the full picture of a threat, analysts will increasingly delegate it to AI agents. This avoids slower response times and longer exposure windows, reducing cyber risks to the organization. Analysts can focus their time and skills on supervision, governance, context and the high-impact decisions for which human expertize remains essential.
Vrije Universiteit Brussel (VUB), a public research university in Belgium, illustrates the value of getting that foundation right. Academic freedom has resulted in a highly decentralized IT estate supporting thousands of researchers running their own systems, sensitive research and personal data. Just three engineers are able to operate detection and investigation across 64 billion events and more than 300 servers, because VUB has centralized its data, normalized it for analysis, and built detection and investigation capabilities on a foundation it can control.
Clear-eyed assessment
Getting these fundamentals right will be vital as the EU forges ahead on its stated ambition of scaling up Europe’s AI-driven cybersecurity capabilities. In fact, a clear-eyed assessment of how an organization stands on these issues today is a prerequisite to that organization getting the best from AI-based cybersecurity in the future.
Multi-cloud architectures, expanding volumes of data and increasingly complex digital estates have revealed serious gaps in tried-and-tested ways of protecting digital systems.
There is also a compliance dimension. The EU Action Plan explicitly connects its ambitions with Europe’s existing cybersecurity and technology framework, including the AI Act, the NIS2 Directive and the Cyber Resilience Act.
Yet, the environment these rules are designed to protect is itself changing. Multi-cloud architectures, expanding volumes of data and increasingly complex digital estates have revealed serious gaps in tried-and-tested ways of protecting digital systems. Now, a growing onslaught of AI-enabled attacks adds another dimension, as adversaries can discover vulnerabilities, develop exploits and operate at a speed and scale that human-only security processes will struggle to match.
The answer to this cannot be to leave AI in the hands of attackers.
Europe is right to explore how advanced AI can be put to work for defenders too. But access to powerful models will only deliver results if organizations have first established the control, data foundations and operating models needed to use them effectively.
Attackers are moving toward machine-scale cybersecurity. Defenders need to be ready to do the same.
It’s time to fight fire with fire.
Disclaimer
POLITICAL ADVERTISEMENT
The sponsor is Elastic
The political advertisement relates to the EU’s Action Plan on Cybersecurity and Artificial Intelligence and advocates for greater adoption of AI-powered cybersecurity, arguing that Europe and its organisations need stronger technological foundations, greater control over data and infrastructure, and increased use of AI to defend against increasingly sophisticated cyber threats.
Over the last couple of weeks, hackers have targeted and broken into the systems of several water plants in the United States. Here’s what we know and don’t know about this wave of attacks allegedly carried out by the Iranian government.
President Donald Trump is paving a legal pathway for U.S. companies to launch cyberattacks on foreign cybercriminal gangs — a significant and potentially controversial measure that would put approved tech and cybersecurity firms on the front lines of digital combat.
The memo represents one of the biggest shifts in U.S. cyber policy undertaken in recent years. It would empower tech and security companies — whose data and control over internet infrastructure often offer unique insight into foreign hacking operations — to mount state-sanctioned digital strikes.
While many such companies already work closely with U.S. intelligence and law enforcement agencies, a web of legal and political constraints has long prevented them from taking direct action inside foreign networks.
Companies that want to participate would be required to sign contracts with both the Department of Justice and the Department of Homeland Security and to undergo what the memo describes as “rigorous vetting” while working with the government. The overall effort would be overseen by a National Coordination Center, established in an earlier Trump administration executive order, with co-executive directors from DOJ and DHS.
However, the memo states that no operations by the companies would be approved until the executive directors at DOJ and DHS establish “consensus procedures” with the White House Homeland Security Council guaranteeing “complete oversight and control of Participating Companies’ performance.”
Those procedures, it notes, should be drafted within 60 days. They are likely to be extensive.
They will outline steps for participating companies to obtain approval for proposed offensive hacking operations, so the government can confirm that the targets are criminal gangs and ensure that operations are consistent with U.S. law and don’t undermine ongoing U.S. intelligence efforts. Companies could propose surveillance operations to help identify criminals or “effects” operations to degrade the systems they use to stage their attacks.
Participating companies would have to pass minimum standards for technical expertise and personnel vetting, and would be required to notify the federal government if they believe approved operations may result in the loss of life or rise to the level of use of force under international law.
Some see the memo as a critical step to help the U.S. government counter foreign cybercriminal gangs that operate outside the reach of U.S. law enforcement.
“For years we’ve called the American technology industry a strategic asset but left it on the cyber sidelines,” Joe Lin, the CEO and co-founder of Twenty, a start-up that builds offensive cyber tools for the U.S. government, said in a statement. “This administration is changing the paradigm.”
The memo notes that companies will only be authorized to target criminals that are “not an institutional part of a foreign government or wholly operated under a foreign government’s direction.”
Even with the help of the U.S. intelligence community, making that distinction could be difficult.
Adversaries such as Russia, China and Iran have persistently targeted U.S. critical infrastructure, including water systems, ports, and telecommunications infrastructure, while multinational crime syndicates have defrauded billions of dollars annually from Americans via complex online schemes.
But many cyber gangs in Eastern Europe are thought to operate with the tacit consent of the Russian government, while state hackers in Iran and China sometimes moonlight as cybercriminals to earn extra money or deflect blame for their governments’ attacks.
More broadly, it is not always easy for digital investigators to determine who is responsible for a given cyberattack, or who different computer networks belong to — another risk the memo contemplates.
Companies that accidentally carry out operations targeting a U.S. citizen or network will be required to immediately pause the operation and notify the U.S. government, the memo states. It does not appear to preclude activities that are deliberately “directed” at a U.S. person, so long as they receive “any necessary authorization, judicial or otherwise, prior to approval of the operation.” Under U.S. law, a “U.S. person” can refer to an American business or organization.
Many lawmakers and security experts have broadly supported calls for the private sector to play a larger role in responding to cybercrime, though not all approve of granting them the ability to launch active hacking efforts.
In recent years, some House members have debated the idea of issuing “letters of marque” to private companies to carry out cyberattacks on behalf of the U.S. government, similar to the U.S. Navy authorizing private ships to disrupt British shipping during the War of 1812.
As part of a more assertive cyber posture, Trump has turned to U.S. Cyber Command to mount digital attacks in tandem with U.S. military operations, including in Iranand Venezuela. He signed an executive order this March to clamp down on countries that fail to take action against scam centers operating within their borders.
That same month, the White House called on the private sector to broadly help it “disrupt” foreign adversaries in its new national cyber strategy, though it stopped short of telling private companies to take riskier and more consequential steps, such as directly launching attacks against foreign criminals.
Some of the most prolific online fraud operations are believed to emanate from scam compounds in Southeast Asia. But hackers from North Korea — who for years have stolen hundreds of millions in cryptocurrency from victims around the world — would likely be exempt from targeting by U.S. companies since they work at the direction of the North Korean government.
Leading artificial intelligence models from Anthropic and OpenAI created fake online personas and tried to deceive human coders into abetting a cyberattack during a recent safety evaluation, the U.K.’s AI Safety and Security Institute disclosed Tuesday.
It marks the latest case in which a powerful AI system has attempted a digital attack on an unwitting third party without direct prompting during such an evaluation — heightening concerns the powerful technology is advancing too fast for responsible oversight.
The disclosure is likely to ignite fresh calls in Washington and Silicon Valley for more rigorous regulation of the AI industry, particularly over frontier models with advanced capabilities to detect and launch cyberattacks. It comes just days after similar testing mishaps involving some of the same models from OpenAI and Anthropic sparked urgent calls for new AI safety regulation and a push within Silicon Valley to slow the rapid pace of AI development.
Like its U.S. counterpart, AISI routinely conducts security evaluations to better understand what dangers both new and soon-to-be-released AI models pose to public health and safety. But even the digital security body said the actions it uncovered by Anthropic’s Claude Mythos 5 and ChatGPT 5.6 — the latest publicly released model from either AI lab — were unlike anything it had seen before.
AISI said the malicious activity began on July 25. The AI safety evaluator detected it and launched an investigation on July 28, when it spotted “unusual data transfers” stemming from a cyber evaluation it was conducting on Mythos 5 and ChatGPT 5.6.
Overall, AISI determined that Mythos 5 and ChatGPT 5.6 took “autonomous, unsanctioned action on the live internet, targeting real people and organizations” during 10 of the 122 evaluations the research body conducted and isolated for review. The majority of those actions, it said, involved Mythos 5 and arose during a “single, sustained line of activity.”
In the most alarming incident it uncovered, Mythos 5 attempted a supply chain attack — a sophisticated technique often deployed by North Korean and Russian cyber operatives, in which hackers bury malware inside legitimate code.
To do so, Anthropic’s model created “multiple fake identities” on developer platform GitHub and used them to send messages “pressuring” an open-source software engineer to unwittingly introduce a bugged update into code widely available on the popular site, AISI said. When that effort failed, the AI “edited its earlier activity to appear harmless” and “considered adopting a fresh identity to continue,” AISI added, a sign the model was intent on repeating the ruse.
As part of the same effort, Mythos 5 also sent direct messages over GitHub to software engineers that contained malware.
In another sign of deceitful behavior AISI uncovered in its investigation, multiple AI agents it was testing appeared to communicate with one another about how to convince real engineers using GitHub to trust them. “One agent left public messages on GitHub offering collaboration with other agents working on the same challenge,” AISI wrote.
AISI’s blog and technical assessment make no mention of whether the models also attempted to exploit previously unknown software bugs — called zero-days — during the evaluation.
Last month, OpenAI disclosed that GPT 5.6 and another of its models escaped onto the open internet during what was supposed to be a controlled test, and then hacked another company in a first-of-its-kind, autonomous breach.
In response, Anthropic launched an investigation into whether any of its models took illicit action during recent testing and discovered Mythos 5 and two other models had hacked three organizations during tests dating back to April.
In a statement, an Anthropic spokesperson said they are “grateful” to AISI for their leadership and that this review underscores the need for “a broader conversation about how to safely evaluate increasingly capable AI agents.”
The spokesperson added: “As we shared after disclosing our own incident last week, the field needs stronger, shared standards for how evaluation environments are built and secured. We look forward to partnering with the UK AISI to learn more about this incident as we conduct our own investigation.”
An OpenAI spokesperson referred POLITICO to a blog post about the incident that went up Tuesday evening. “We are committed to working across the industry to strengthen shared practices for conducting high-risk evaluations safely, including convening stakeholders such as national AI institutes, independent evaluators, other AI labs, and other groups in the coming weeks,” the blog read.
AISI stressed in its blog that the malicious activity it disclosed Tuesday took place under “deliberately permissive conditions” so they could assess the safety risks posed by the two models. This included granting the models access to the internet, unlike the earlier incidents detailed by Anthropic and OpenAI.
AISI also noted the models were intentionally stripped of internal guardrails that block malicious behavior. AISI was only able to disable those controls because of its role testing Mythos 5 and ChatGPT 5.6.
Still, AISI said the incidents highlighted the need for greater monitoring of model behavior during testing, and tighter controls over their access to the internet.
The Trump administration is finalizing a voluntary framework under which AI labs would submit powerful models they want to release to the public for federal safety testing. But it has not yet made the framework public, and it includes no provisions for models AI labs are developing internally.
The incidents last month from OpenAI and Anthropic both involved models not intended for public release.
Some cyber experts say recent incidents highlight deeper questions around AI development, such as who is liable when AI systems break federal hacking laws.
“If any of these were human-originated, they would lead to clear and vigorous prosecution. I think it’s time for a serious discussion about updates to existing computer security law,” said Marc Rogers, a hacker and prominent cybersecurity expert.