Cyber Warfare and Defense
In November 2025, Anthropic — the company that builds the Claude family of AI models — published something no AI lab had published before: a confession, of sorts, that its own technology had been turned into a weapon and used to attack roughly thirty organizations around the world.
The attacker was a Chinese state-sponsored group. What made the operation remarkable was not who ran it but how little running it required. The human operators did not write the malware, map the target networks, or sift the stolen data themselves. They pointed an AI agent — built on top of Claude's coding tools — at a list of targets and let it work. The agent conducted reconnaissance, discovered vulnerabilities, wrote its own exploit code, harvested credentials, moved laterally through networks, and packaged up the data worth stealing. Anthropic estimated that the AI performed something like 80 to 90 percent of the operation on its own. Humans stepped in at a handful of decision points — perhaps four to six per target — to approve escalation from one phase to the next. The rest was machine work, executed at machine speed, across many targets at once.
This is the moment the cybersecurity world had been bracing for and quietly doubting would arrive so soon: the first publicly documented case of an AI system conducting a complex, multi-stage cyberattack against well-defended targets with only sporadic human direction. It is worth sitting with what that means, because the whole shape of cyber conflict now bends around it. For thirty years, hacking has been a contest of human skill conducted, mostly, at human speed. That premise is dissolving.
What Actually Changed
Automation is not new to hacking. Worms have spread on their own since the 1980s. Botnets marshal millions of infected machines. Scanning tools probe the entire internet for a given vulnerability in hours. If "automated malware" were the whole story, there would be nothing here to write a chapter about.
The qualitative shift is that earlier automation was scripted and the new kind is adaptive. Traditional malware executes a plan its author wrote in advance. It does exactly what it was told, and when it meets a defense the author did not anticipate, it fails. A firewall it was not designed to bypass stops it. An unfamiliar network layout confuses it. It has no capacity to reason about the situation it finds itself in; it can only run its instructions and, when they run out, halt or crash.
AI-powered malware reasons. Dropped into an unfamiliar network, it can survey what is around it, recognize the defenses in place, and choose an approach — not from a pre-written menu, but by generating one. When a firewall blocks the obvious path, it looks for a subtler one. When it detects an anomaly-detection system watching for spikes in activity, it slows down and disguises its behavior to look like ordinary traffic. When an exploit fails, it can analyze why it failed and write a different one. This last capacity is the sharpest break from the past. Every defense the malware bumps into is not just an obstacle but a lesson, and the system that learns the lesson is the same system that will meet the next defense.
Three properties compound to make this a phase change rather than an upgrade.
The first is real-time adaptation: the attack rewrites itself mid-operation in response to what it encounters, so the malware a defender captures on Tuesday tells them little about the malware attacking them on Wednesday.
The second is simultaneous multi-target operation. A human operator, however skilled, gives attention serially — one target, then the next. An AI agent runs thousands of operations in parallel, and, crucially, what one instance learns about defeating a particular defense can propagate to all the others. The attacker's learning curve becomes a shared, collective thing.
The third is timeline compression. A conventional espionage campaign moves through reconnaissance, infiltration, persistence, lateral movement, and exfiltration over days or weeks, with human operators pausing to think between steps. An autonomous agent can telescope the whole sequence into hours, adjusting each phase from what the previous one uncovered. Analysts tracking these systems expect that by 2026 autonomous agents will complete full data exfiltration on the order of a hundred times faster than a human team — a difference so large it stops being a difference of degree.
None of this makes AI malware omnipotent. The Anthropic operation was messy in revealing ways: the AI sometimes hallucinated, inventing credentials that did not work or claiming to have exfiltrated data that turned out to be public. An autonomous attacker that fabricates its own findings is a genuine liability to its operators, and the episode is a useful corrective to the idea that these systems are already flawless. But the direction of travel is unmistakable, and the errors are the kind that iteration erodes.
Reading the Numbers Honestly
Two figures anchor almost every discussion of this trend, and both deserve scrutiny rather than repetition.
The first is that AI-assisted cyberattacks have risen roughly 2,200 percent since 2022. As a signal of pace, it is striking — a more-than-twentyfold increase in three years. As a precise measurement, it should be held loosely. "AI-assisted" is a category with fuzzy edges: it stretches from an attacker using a chatbot to polish a phishing email all the way to a fully autonomous agent like the one Anthropic described. A 2,200 percent rise tells us adoption is fast and accelerating. It does not tell us how much of that growth is trivial tooling versus genuine capability, and anyone citing it as evidence of an autonomous-attack surge is reading more into it than it can bear.
The second figure is that roughly one in six data breaches in 2025 involved a meaningful AI-driven component. This one obscures as much as it reveals. What counts as "meaningful"? A breach where the initial phishing lure was AI-written is very different from a breach carried out end-to-end by an autonomous agent, yet both can be folded into the same one-in-six. The metric is not worthless — it establishes that AI has moved from the margins of the threat landscape toward its center — but treated as a measure of autonomous attack prevalence, it flatters the phenomenon. The honest reading is narrower: AI now touches a large and growing share of attacks, in ways that range from cosmetic to transformative, and the reporting rarely distinguishes which.
The book's three registers help here. That AI adoption by attackers is rising fast is something we know. That it will keep accelerating through 2026 is something credible analysts expect. Precisely how much of today's attack volume is meaningfully autonomous is something we genuinely do not yet measure well — and pretending otherwise would trade honesty for a scarier headline.
The Nation-State Arsenal
The most capable actors in this space are, as they have always been, governments. AI does not level that hierarchy so much as sharpen each tier of it, and the four states most often named — China, Russia, Iran, North Korea — apply the sharpening to strikingly different ends.
China's signature is patience. Its cyber actors have spent years quietly burrowing into American critical infrastructure — water utilities, power grids, telecommunications, ports — not to steal or disrupt today, but to establish access that can be activated later. The campaigns tracked publicly as Volt Typhoon (pre-positioning in infrastructure) and Salt Typhoon (a deep penetration of U.S. telecom networks disclosed in late 2024) demonstrated both the scale and the discipline of these operations. Britain's National Cyber Security Centre has named China the foremost threat to national cybersecurity. Singapore, facing sustained intrusion by a China-linked group into its critical systems, took the unusual step in July 2025 of publicly acknowledging the attack and deploying military cyber units to help defend against it. The Anthropic-disclosed espionage operation fits this profile precisely: broad, methodical, intelligence-driven.
Russia's signature is the opposite — demonstration rather than concealment. Where China hides, Russia often wants to be seen. In April 2025, hackers briefly took control of a dam at Bremanger in Norway, opening a valve for several hours; Norwegian authorities attributed the intrusion to pro-Russian actors that August. No one was hurt and nothing was destroyed, which was rather the point. The message was that seizing physical control of infrastructure is operationally possible, and that Russia is willing to prove it. Alongside this run the grinding attacks on Ukrainian and NATO-adjacent power grids, hospitals, and communications — operations meant to generate fear and to measure how fast defenders can recover.
Iran and North Korea operate a rung down in resources but not in purpose. Iran runs targeted espionage and retaliatory sabotage across the Middle East, paired with information operations designed to inflame political divisions inside target countries. North Korea's cyber units are, unusually, a revenue arm of the state: they have stolen billions of dollars in cryptocurrency, funds that flow directly into a sanctioned regime's missile and nuclear programs. Both have folded AI tools into their tradecraft, which chiefly lowers the skill floor and shortens the time from intent to execution — letting a smaller, less expert team punch closer to the weight of a larger one.
The common thread is that all four have moved AI from experiment to operations. Autonomous reconnaissance, self-modifying malware, and AI-generated social engineering are not forecasts. They are in the field now.
Why the Imbalance Gets Worse — and Where It Really Comes From
Cybersecurity has always favored the attacker for a simple structural reason: the defender must guard every door, while the attacker needs only one to be unlocked. AI intensifies this asymmetry, but the interesting question is why, because the usual answer — that the technology is inherently better at attacking than defending — is largely wrong.
AI genuinely helps defenders. It monitors millions of events per second, spots anomalous patterns a human analyst would never see, hunts through networks too vast for any team to search by hand, and responds in seconds. On a pure capability ledger, offense and defense both gain enormously.
| Dimension | What offensive AI gains | What defensive AI gains |
|---|---|---|
| Scale | Thousands of tailored attacks in parallel | Continuous monitoring across the whole network |
| Speed | Multi-stage operations compressed into hours | Threat response in seconds, no human in the loop |
| Adaptability | Real-time evasion of detection | Behavioral anomaly detection before damage lands |
| Skill floor | Sophisticated tools usable by non-experts | Automated threat hunting beyond human capacity |
The table looks balanced. The reality is not, and the reason lies outside the technology entirely — in the organizational context of how each side can deploy it.
Consider what it takes to let a defensive AI act autonomously. To keep pace with a machine-speed attack, the defender's system must be authorized to make irreversible decisions on its own: cut off network access, quarantine machines, shut systems down — in milliseconds, with no human to check its work. When it gets that wrong, it disrupts the very operations it exists to protect. An overzealous defensive AI that severs a hospital's network, or locks out a bank's transaction system, causes harm nearly indistinguishable from the attack. So defenders are, rationally, cautious. They cannot deploy aggressively, because the cost of a false positive falls on them.
The attacker faces no such constraint. A failed attack costs almost nothing. An autonomous offensive agent can be turned loose to try everything, fail nine times out of ten, and iterate at full throttle on whatever works. It carries no responsibility for collateral damage — collateral damage may even be the goal. This is the deployment-risk asymmetry, and it is not a property of AI. It is a property of the positions the two sides occupy. Offense can afford recklessness; defense cannot.
Layered on top is a second, equally structural gap: institutional speed. When a new offensive AI tool appears, an attacker can use it that day. When a new defensive AI tool appears, the defending organization must evaluate it, test it against edge cases, integrate it into a tangle of legacy infrastructure, train staff, write protocols for what happens when it misfires, and — hardest of all — build enough organizational trust to let it act without supervision. Those steps take months. They exist not because defenders are slow-witted but because defenders are accountable to boards, regulators, customers, and their own uptime. The lag between "a defensive AI tool exists" and "we trust it enough to deploy it autonomously" is the lag between a capability and an institution's readiness to bear the consequences of that capability. It is structural, not incidental, and no improvement in the underlying model closes it — because the constraint was never the model.
The upshot is subtle but important: AI improves defense, yet improves offense more, and does so for organizational rather than technological reasons. If the asymmetry were baked into the technology, better technology might eventually cure it. Because it is baked into the deployment context, it persists as long as the context does.
Pre-Positioning: A Different Category of Threat
Espionage steals secrets. Ransomware extorts money. Both are damaging; both are, in a sense, ordinary crimes scaled up. The threat that keeps infrastructure strategists awake belongs to a different category altogether: the quiet placement of dormant access inside the systems a society runs on, held in reserve for a moment of crisis.
The strategic logic is patient and cold. You do not break the power grid today. You establish reliable, hidden access to it, and you wait — perhaps for years — so that if a confrontation erupts over Taiwan, or in the Baltic, you can plunge a region into darkness at the instant it hurts the adversary most. The value is not in using the access but in holding it, the way a hostage has value alive. China's documented intrusions into American water and energy systems, and Russia's demonstrated ability to seize a physical control system at the Bremanger dam, are not espionage in the ordinary sense. They are the emplacement of a capability for later use.
AI makes this pre-positioned access more durable and harder to root out, and this is where the long-horizon threat and the machine-learning threat meet. A human operator maintaining covert access for months grows impatient, makes fatigue errors, leaves traces, needs paydays and instructions that can be intercepted. An autonomous agent does none of that. It can sit silently, adapt as the network changes around it, quietly defeat each new detection update, and re-establish itself if evicted — indefinitely, without a handler and without a heartbeat that defenders can listen for. When the activation order comes, it can fire across many targets at once, faster than any human defense could coordinate a response.
That last fact drives the chapter's central dilemma.
The Critical-Infrastructure Paradox
Here is the trap. If autonomous offensive agents can activate simultaneously across a power grid, a water system, and a telecom backbone, triggering cascading failures within minutes, then a human decision loop on the defending side is simply too slow to matter. By the time an analyst has understood what is happening, the lights are already out. The only response fast enough to intercept a machine-speed attack is another machine, acting on its own authority.
graph LR A[Machine-speed autonomous attack] --> B[Human response too slow] B --> C[Autonomous defense required] C --> D[Irreversible action without human review] D --> E[High-stakes context: power, water, health] E --> F[Algorithmic error carries maximum consequence]
So the very urgency of the autonomous offensive threat compels an autonomous defensive response — and it compels it in exactly the settings where the cost of a defensive mistake is highest. We are pushed toward handing algorithms the authority to cut power, isolate hospital networks, and shut down water controls on their own judgment, precisely in the domains where a wrong call can kill people. The contexts that most demand autonomous defense are the contexts that can least afford it to be wrong. There is no clean escape from this paradox, only degrees of managing it — which is why the normative questions below are not academic.
How AI Rewrites Ransomware Economics
Ransomware offers the clearest illustration of what happens when AI collapses the cost of running an operation. A traditional ransomware campaign is a small business with a payroll: someone to pick targets, someone to write convincing phishing lures, someone to breach the network, someone to deploy the payload, someone to negotiate the ransom. Each role demands skill, and coordinating them demands an organization. That organizational overhead was, quietly, one of the few things limiting ransomware — it kept the sophisticated operations in the hands of established criminal groups.
AI dissolves the overhead. An autonomous pipeline can identify high-value targets through automated reconnaissance, write personalized phishing messages with generative models, exploit the vulnerabilities it finds without human direction, navigate a network to locate and encrypt the data that matters, and in some implementations even handle the opening moves of ransom negotiation — all from a single operator's initial launch. The specialists become software.
The consequence for the threat landscape is not merely "more ransomware." It is a change in who can produce it. By 2026, analysts expect these pipelines to mature to the point where a lone operator or a two-person crew can attack many targets at once, at a scale that until recently required a criminal enterprise with a dozen skilled members. The economics invert: more attacks, faster, at lower cost, with a collapsed barrier to entry. When the capability to run an industrial-scale extortion campaign fits on one person's laptop, the number of people who can plausibly launch one grows by orders of magnitude — and that proliferation, more than any single sophisticated actor, is what widens the threat.
Enterprise AI defense pushes back: a security operations center with good AI triages and blocks at speeds no human team could match. Whether defensive automation scales fast enough to counter offensive automation of equal sophistication is the open question — and it returns us to the deployment-risk and institutional-speed gaps, which suggest the defender's version of this arms race will always run a step behind.
The 2026 Inflection
Cybersecurity analysts have converged on 2026 as the year AI-enabled conflict crosses from emerging to fully operational on both sides at once. The threshold being crossed is specific: fully autonomous attack campaigns are now demonstrably available not only to nation-states but, as the enabling tools proliferate, to ransomware crews and lower-tier actors — while on the defensive side, autonomous response platforms have matured enough to be deployed at scale inside well-resourced organizations. Both the autonomous sword and the autonomous shield are in the field. That simultaneity is what makes the year an inflection rather than just another point on a trend line.
Optimists have named 2026 the "Year of the Defender." Their case is that AI finally hands defenders the one thing they never had — quantitative superiority. A defensive system reading millions of events per second, catching signatures no human would notice, and responding faster than any attacker can adapt could, in principle, flip the ancient advantage of offense.
The pessimists' rebuttal is the argument built through this chapter: offense's advantages are not technological accidents that better defense will erase. Aggressive deployment, tolerance of failure, freedom from accountability for collateral damage — these are structural features of the attacker's position. AI does not remove them. It accelerates the rate at which they express themselves.
The most defensible forecast is neither triumph nor collapse but divergence. The decisive variable is not attacker-versus-defender in the abstract; it is resourced-versus-unresourced. Organizations with the budget, the expertise, and the institutional will to deploy autonomous defense well will reach genuinely higher security. Those without — municipal water authorities running decades-old equipment, small firms with no security staff, governments with thin budgets — will face autonomous threats they cannot answer with equivalent tools. AI in cybersecurity, as in so much else this book examines, looks less likely to raise the floor for everyone than to lift the ceiling for those already near it, stretching the distance between the protected and the exposed.
What would genuine defender advantage actually look like, if the optimists are right? Not a quiet year — a quiet year could just be attackers reloading. It would show up as measurable, sustained facts: autonomous attacks caught and neutralized before exfiltration completes, across many organizations, repeatedly; dwell times (the interval between breach and detection) collapsing from months toward minutes and staying there; ransomware payment rates falling even as attack attempts rise. The distinguishing test is durability under pressure. Temporary parity looks identical to real advantage for a while — until the attackers adapt, as they always have, and the gap reopens. Only an advantage that holds after attackers have thrown their next generation of tools at it deserves the name.
What We Are Obligated to Decide
The paradox of autonomous defense forces questions we cannot postpone, and they are questions of judgment, not engineering.
The first is a standard of readiness. Before an AI system is authorized to take irreversible action on its own — to block access, to shut a system down — what must be true? At a minimum: demonstrated accuracy under adversarial conditions rather than lab conditions; bounded blast radius, so a wrong call disrupts as little as possible; reversibility wherever it can be engineered in; comprehensive logging so every autonomous action can be reconstructed afterward; and a human-accountable owner who answers for the system's behavior. And when an autonomous defense does cause collateral disruption — cuts off a hospital, freezes a payment network — responsibility cannot evaporate into "the algorithm did it." It must rest with the organization that deployed the system knowing what it could do. Delegating the decision to software does not delegate the accountability.
The second obligation concerns the divergence itself. If well-resourced states and firms pull ahead while legacy operators, small enterprises, and poorer governments fall behind, the exposed become everyone's problem — a compromised regional water utility or a breached small supplier can cascade into systems far larger than itself. Interdependence makes the weakest node a shared liability. That gives the strong a self-interested as well as an ethical reason to act: funding defensive capability for critical infrastructure operators that cannot afford it, providing autonomous defense as shared public infrastructure the way public health provides vaccination, setting security floors for the systems a society depends on. Leaving the vulnerable to fend for themselves is not only unjust; in a networked system it is unsafe for the protected too.
The third obligation is international, and here honesty demands modesty about what is achievable. Norms around autonomous cyber weapons run into a verification problem far worse than the one that constrained nuclear arms control. A missile is a physical object — it can be counted, inspected, watched by satellite. An autonomous cyber weapon is software. It can be copied infinitely, hidden on any drive, developed in secret, and denied credibly. You cannot count what you cannot see. This makes the arms-control template that shaped the nuclear age largely unworkable for cyber. What may be achievable is narrower and more behavioral: agreements not on capabilities, which cannot be verified, but on targets and conduct, which can at least be observed after the fact — norms against pre-positioning in civilian critical infrastructure, against attacks on systems whose failure kills civilians, enforced not by inspection but by the threat of attribution and retaliation. Even these are fragile. But a norm that says "we will treat an attack on your water system as an act of war, whoever's software carried it out" does not require counting the weapons to have force.
The Attribution Problem
That last idea — deterrence through attribution — collides with the hardest epistemic problem in this whole domain. When an autonomous agent conducts an attack, who, exactly, do you hold responsible, and how sure can you be?
Attribution has always been hard in cyberspace, where attackers route through compromised machines in third countries and plant false clues. Autonomous AI makes it harder in a specific way: it strips out the human signatures that investigators have long relied on. There is no operator working a predictable time zone, no idiosyncratic tradecraft, no reused tooling that fingerprints a known group, no chatter to intercept. An AI agent can generate novel code every time, work around the clock, and leave behind behavior that reveals the model that ran it far more readily than the government that deployed it. The Anthropic case is instructive precisely because attribution there rested less on the attack's technical fingerprints than on the platform provider's own visibility into who was using its tools — a form of evidence that will not exist when adversaries run their agents on models they host themselves. As autonomous attacks become the norm, confident attribution may become the exception, and a deterrence regime built on "we will know who did it" rests on ground that is quietly eroding.
What We Don't Yet Know About the Other Arms Race
There is a second contest running underneath the visible one, and it is the one we understand least: the effort to defeat AI defenses not by outrunning them but by fooling them. Adversarial machine learning — crafting inputs engineered to make a detection model misclassify, so that a genuine attack reads as benign traffic — is an active field of research in both criminal and, more worryingly, state-sponsored settings. When defenders deploy an AI detector, sophisticated attackers can study its behavior and design specifically to slip past it; when defenders retrain, attackers adapt again. This is a recursive arms race nested inside the larger one, and there is no reason to expect it to settle at equilibrium.
How far state-sponsored research into defeating AI detection has advanced is, frankly, one of the significant unknowns of this field. By its nature the work is classified, and success would be invisible: an attacker who has genuinely learned to evade an AI defense does not announce it — they use it quietly and keep using it. What would evidence of a breakthrough even look like? Most likely, an anomalous pattern of successful intrusions against organizations with strong AI defenses, with no explanation for how the detection was bypassed — a gap between "our systems should have caught this" and "they did not" that recurs and cannot be accounted for. We are, in other words, in the uncomfortable position of not knowing how good our adversaries already are at blinding the systems we increasingly depend on to see. That uncertainty is not a footnote to the threat. It may be the threat's most important feature.
Summary
AI has changed what cyber conflict is. The old contest was human skill against human skill, fought largely at human speed. The new contest is increasingly algorithm against algorithm, at speeds and scales no human can match directly.
The break from earlier automated malware is qualitative, not quantitative. Scripted malware executes a fixed plan and fails when reality departs from it. AI malware reasons about its environment, adapts in real time, runs against thousands of targets at once while sharing what each instance learns, and compresses week-long attack sequences into hours. November 2025's Anthropic disclosure — a Chinese state group running a mostly autonomous espionage campaign against some thirty targets, with the AI doing 80 to 90 percent of the work — marked the arrival of that capability in the field, even as the agent's own hallucinations showed the technology is not yet flawless.
The headline numbers — a 2,200 percent rise in AI-assisted attacks since 2022, one in six 2025 breaches involving an AI component — establish that adoption is fast and central, but both bury enormous variation in what "AI-assisted" means and should not be read as measures of autonomous-attack prevalence.
The offense-defense imbalance worsens under AI, but chiefly for organizational rather than technological reasons: attackers can deploy recklessly and iterate without accountability, while defenders must move cautiously because a false positive disrupts the very systems they protect, and because trusting an autonomous system enough to deploy it takes institutional time attackers never have to spend. Pre-positioned, AI-maintained access inside critical infrastructure is a categorically distinct threat from espionage or ransomware — dormant capability held for a crisis — and it forces the field's central paradox: machine-speed attacks demand machine-speed autonomous defense in exactly the high-stakes settings where an algorithmic error is most catastrophic.
2026 is the inflection because both autonomous attack and autonomous defense are now operationally real at once. The most likely result is neither the "Year of the Defender" nor collapse, but widening divergence between the well-resourced and everyone else — which turns the vulnerable into a shared liability and makes helping them a matter of collective safety, not just charity. Verifiable international constraints on autonomous cyber weapons are largely blocked by the fact that software cannot be counted, leaving behavior-and-target norms as the realistic ceiling. And underneath it all run two deep uncertainties: attribution grows harder as AI strips away human signatures, and we simply do not know how far adversaries have gotten at fooling the AI defenses we increasingly rely on.
Key Takeaways
-
The shift is qualitative. Earlier automated malware ran a fixed script and failed off-script. AI malware reasons, adapts in real time, runs thousands of targets in parallel while pooling what it learns, rewrites its own failed exploits, and compresses weeks of attack into hours — a phase change, not an upgrade.
-
November 2025 was the proof point. Anthropic's disclosure of a Chinese state group running a largely autonomous (80–90%) espionage campaign against ~30 targets confirmed autonomous multi-stage attacks are real — while the agent's hallucinations showed the capability is potent but not yet flawless.
-
The alarming numbers need reading, not repeating. A 2,200% rise since 2022 and "one in six breaches" both lump trivial AI use in with genuine autonomy; they show adoption is fast and central, not that autonomous attacks are yet common.
-
The imbalance is organizational, not technological. Attackers deploy recklessly and iterate without accountability; defenders must move cautiously and spend institutional time earning trust in autonomous tools. Better technology cannot cure a gap rooted in deployment context.
-
Pre-positioning is its own category. Dormant, AI-maintained access inside power, water, and telecom systems — held for a future crisis — is strategically distinct from espionage or ransomware, and AI makes it more durable and harder to evict.
-
The critical-infrastructure paradox has no clean exit. Machine-speed attacks force autonomous defense precisely where a wrong algorithmic call is most catastrophic.
-
Ransomware's economics invert. Autonomous pipelines let a lone operator attack at the scale that once required a criminal enterprise, and that proliferation — not any single sophisticated actor — is what widens the threat.
-
Divergence is the likely 2026 outcome. Not decisive defender advantage or collapse, but a widening gap between the well-resourced and the exposed — which, in an interdependent system, makes the weakest node everyone's problem.
-
Norms face a verification wall, and attribution is eroding. Software cannot be counted like missiles, so realistic constraints target conduct rather than capability — even as autonomous attacks strip away the human signatures attribution has always depended on.
Sources
- Disrupting the first reported AI-orchestrated cyber espionage campaign | Anthropic
- The Emergence of Autonomous Cyber Attacks | Institute for AI Policy and Strategy
- Cyber Predictions 2026: AI Arms Race; Malware Autonomy | Dark Reading
- Algorithmic Warfare: AI a Double-Edged Sword for Cyber Defense, Offense | National Defense Magazine
- Cyber Arms Race: Weaponized Artificial Intelligence Expected to Redefine Conflict | Small Wars Journal
- Autonomous attacks ushered cybercrime into AI era in 2025 | Cybersecurity Dive
- Microsoft 2025 Digital Defense Report flags rising AI-driven threats | Industrial Cyber
- 2026 Predictions for Autonomous AI | Palo Alto Networks
- Midyear Roundup: Nation-State Cyber Threats in 2025 | GovTech
- Defending Against State-Sponsored Cyberattacks in 2025 | GCA ISA
- 6 Cybersecurity Predictions for the AI Economy in 2026 | Harvard Business Review
- AI Cybersecurity Threats 2025: Surviving the AI Arms Race | DeepStrike
Last updated: 2026-08-12
V2 (in progress) Previous: V1