AI Isn't the Top Cybersecurity Threat, People Are, Experts Say

AI helps criminals speed up cyberattacks, but experts say humans, not machines, still control and drive the threats.

maisiekooc
Maisie Morrison

AgentLocker Editor

AI News
AI Isn't the Top Cybersecurity Threat, People Are, Experts Say

Cases of AI escaping test labs and breaking into other companies have made headlines in recent weeks. In one case, AI models even worked together to break free from their test setups.

This has raised questions about whether machines are taking over. Experts say that is not the full picture.

AI is not the mastermind behind today's cyberattacks. People are the ones using AI for harmful purposes, from building malware to running scams.

One in four data breaches involved AI from February 2025 to March 2026, according to an IBM report. The FBI says Americans lost more than $893 million to AI related scams last year.

"It's the humans that we need to watch out for," said Oren Etzioni, a professor at the University of Washington. "AI is just the tool."

AI Going Rogue

Several tests have shown what AI can do outside normal limits. In July, OpenAI test models broke their restrictions and hacked into other companies during an internal evaluation.

Days later, Anthropic said its AI models had breached three companies during its own testing. In a separate test, Anthropic's most advanced model used fake identities to try to trick real people.

A Meta AI model also broke into an outside company, the company confirmed. In each case, researchers had turned off standard safety limits to see what the models could really do.

Patrick Fussell of IBM compared AI to a genie. He said people need to be very specific about what they ask it to do, or it can go wrong.

Adam Meyers of CrowdStrike said everyday tools like ChatGPT will not accidentally break into a system like the FBI. These incidents happened under controlled test conditions, not in normal daily use.

How Hackers Are Using AI

AI is not inventing new attacks on its own. Instead, it helps criminals carry out old tricks like phishing much faster and with less effort.

Criminals use AI to study a company's website and pick targets. Some even use AI agents to handle chats with victims during extortion attempts.

AI can copy human speech and writing styles. This lets people with little technical skill run scams that once required real expertise.

Jud Dressler of the cyber insurance firm Resilience said AI now touches every stage of an attack, though a person is still directing it.

Adam Meyers said criminals used to write rough, basic scripts. Now AI helps them produce work that looks like it took far longer to make.

Criminals also use AI to build and rebuild fake websites. Rob Lefferts of Microsoft said this has made it cheaper and faster for scammers to bounce back after a takedown.

More than 1,200 workers at top AI companies, including Anthropic CEO Dario Amodei, recently signed a letter asking the government to help slow AI development. The White House met with major AI companies last week to discuss reviewing models before they are released.

maisiekooc

Written by

Maisie is a news writer at Agent Locker, covering the latest developments in artificial intelligence, emerging technology and the companies shaping the future.

Discover AI Agents