
Companies don't have long left to prepare for a frightening wave of automated cyber attacks, with experts pointing towards a looming six-month deadline as leading models are already capable of action.
Many of the leading figures in the AI industry have switched their focus to the impending threat of large-scale cyber attacks this year, with OpenAI CEO Sam Altman warning a few months ago that 2026 would be home to one that is 'world shaking'.
That threshold has seemingly already passed, however, as frontier ChatGPT models realized these fears by breaking containment and hacking another company in order to best complete its goals, and new research has suggested that similar attacks will become far more common.
On top of this, cybersecurity experts have argued that humans are simply not enough any more to form a competent defense against these threats, as the speed and scale at which leading AI models operate can only be matched by its technological equal.
Models are already capable of end-to-end compromises
As reported by Dark Reading, several of the world's leading cybersecurity consultation firms have outlined the dangers that leading AI models pose, with Booz Allen being the latest to confirm their potential.
Advert
It indicated that Anthropic's Mythos 5 – a model so 'dangerous' it was banned by the U.S. government – is capable of achieving an end-to-end compromise, which reflects a complete security breach leaving every stage of the system infiltrated.

What's more frightening is that these breaches can (and have) been achieved autonomously without any human input, with AI models operating on their own terms to achieve goals that we seemingly can't control.
Brad Medairy, the president of Booz Allen's National Cyber practice, outlined: "Our view is there's going to be some level of parity, at least between the frontier models and the Chinese models over probably a six-month horizon, and so everyone is in a rapid race to evolve these capabilities."
He also noted that while humans have typically had an advantage as defenders against cyber attacks, "in the future, the balance of power shifts to the offense, because the attacker can deliver effects at speed and scale that the traditional defenses can't keep pace with."
Why human defenses won't be good enough
One fear that is confirmed by these new revelations is that we as humans simply aren't fast enough anymore, as what was previously deemed to be 'rapid' response times – often sitting at around the four-hour mark – would be far too slow to deal with the scale at which AI operations take place.
"The agents chose which systems to map, which techniques to pull from public sources, and when to expand into new sectors, all without step-by-step human direction," indicated cybersecurity firm Tenable when conducting a post-mortem of a cyberattack on Taiwanese government servers, confirming what many have feared.

Part of this danger comes from access to open-weight models, with Nico Waisman, chief information security officer at XBOW, revealing to Dark Reading:
"Open-weight models have gotten materially better at cyber, and that's what moves the ROI calculation. You no longer need frontier access to do this. That's the point where automation becomes the cheaper option, not just the impressive one."
Where humans could still retain an advantage, however, is in the form of deception, as agentic AI tools are still vulnerable to forms of 'bait' that we can easily avoid.
Medairy outlines the importance of asymmetric defenses, as the introduction of false leads and dead ends allow humans to easily navigate the right course, but AI systems fall prey to these more than 90% of the time.