We Are Officially Beyond Theoretical AI Attacks

AI's threat capability has now been demonstrated, but where does that leave us?

Key Takeaways

  • AI going rogue is no longer a possibility, and recent events have put AI safety into the news
  • While AI is a dangerous tool for cyber attacks, organizations are also using it to prevent them, and a lack of regulation in the US remains an issue
  • Leaders are calling for frontier labs to slow model development, but experts argue this may not give us a better understanding of AI’s capabilities

If recent news has taught us anything, it’s that we no longer need to theorize about the possibility of AI systems going rogue. Recent episodes of AI-enabled attacks have led to warnings from prominent researchers, and calls from frontier labs to slow AI development.

However, AI isn’t just an adversary. It’s also been useful for preventing cyber incidents, which could make it harder to regulate.

All in all, cyber expert Brandon Dixon is unsure about how much slowing down will protect us against AI’s capabilities. He urged businesses to understand their own processes first and map out risks in a recent interview with Tech.co.

Recent AI Attacks Put Safety in the Spotlight

Days before Anthropic CEO Dario Amodei called for frontier labs to slow down AI model development, ex-Anthropic and ex-OpenAI researcher Jacob Coxon released a series of posts on X expressing fear for the future of humanity.

Among the passages, Coxon claimed AI leaders are “gambling with our lives” in their pursuit of superintelligence. His comments most likely would have joined the chorus of existing AI “doomers” as they’re called, had they not followed a series of highly concerning autonomous AI attacks.

 

About Tech.co Video Thumbnail Showing Lead Writer Conor Cawley Smiling Next to Tech.co LogoThis just in! View
the top business tech deals for 2026 👨‍💻
See the list button

Most recently, OpenAI disclosed several concerning behaviors exhibited during the testing of GPT-5.6 Sol. The model supposedly started to leave instructions for future versions of itself, telling it to conceal mistakes and misaligned behavior from users. If that doesn’t concern you, just remember what happened with Hugging Face.

To Brandon Dixon, co-founder and CTO of Ent, which helps organizations understand and protect against malicious actors and AI agents, we’ve moved beyond the theoretical stage of AI cyber attacks. This ultimately means the playing field has shifted massively, and what we do next is important, but also hard to figure out.

AI’s Positive, and Negative, Impact on Security

When I’ve interviewed cyber experts on AI, what we discuss is a kind of double bind. AI is facing both sides of the battlefield, in that it’s helping businesses detect and react to attacks faster, while mounting those attacks in the first place.

“The models being used to craft phishing lures are also being used to find bugs before they ship, improve code quality, and surface vulnerabilities in production systems before they’re exploited,” Dixon told me.

At the moment, it’s impossible to see a world where we fight AI, without using AI. “Speed and efficiency cut both ways,” Dixon told me. Essentially, the features that make AI so good at attacking us, also make it very good at protecting us.

Nevertheless, AI-powered cyber attacks are a serious concern. Using that speed and efficiency, attacks can happen faster, without giving humans enough time to detect them, and serious amounts of data can be lost.

“The limiting factor for attackers has historically been the ability to understand the data that was stolen,” Dixon noted. “But now, AI supercharges that.”

Policing AI is Becoming Increasingly Difficult

Cyber experts have been calling for a more careful consideration of AI’s security vulnerabilities for some time. However, this point in time does feel significant. Dixon said it’s because we’ve now seen these capabilities in action.

“There are documented cases of AI agents breaking out of sandboxes, taking unintended actions, violating corporate policies, or otherwise behaving adversarially. These systems have materialized and evolved extremely quickly,” he explained.

“We are only a handful of years into this technology, and its capabilities change materially every year. That makes it difficult to know where it is heading or to apply security and governance measures that will not become outdated shortly after they are deployed.” – Brandon Dixon, co-founder and CTO at Ent

Despite the technology moving faster and faster, the US government is yet to pass any federal laws around AI. Individual states like California have implemented some AI laws, but currently, AI isn’t equally regulated in the US.

And, given recent comments made by Trump following the slowdown call from AI leaders, it doesn’t look like any new laws will be passed through Congress soon. Mostly, this is because of rapidly developing Chinese AI models, which Trump has continually said the US needs to outpace.

However, many experts will say some government intervention on AI is needed, Dixon included. “I think the government should establish sensible rules that preserve innovation and progress while preventing clearly reckless or harmful uses.”

“The goal should not be to eliminate risk entirely because that would suppress legitimate research and defensive deployment. Oversight should focus on meaningful risks and measurable harms, not broad restrictions on the underlying technology,” he said.

Will Slowing Down AI Protect Organizations?

It’s difficult to think about what happens if we slow down. What’s most important to remember, for starters, is that even though AI leaders have committed themselves to slowing down, they could turn the other way, especially given the stance of the Trump administration.

For Dixon, slowing down AI won’t necessarily put us in a better place. “From my perspective, more time does not necessarily produce a better understanding of security vulnerabilities,” he said, though he does admit he can’t speak for frontier labs themselves.

While additional time could help review code, test software, or identify weaknesses, he added, organizations may not use the time as wisely as we assume they will. “If history is any indication, many will wait for attacks to begin before responding appropriately.”

It’s still not entirely certain what slower development will look like, should it happen. But, Dixon told me businesses shouldn’t use an inability to control all aspects of AI as a reason not to adopt it. To him, it doesn’t make any sense. But what also doesn’t make sense, is just “adopting AI, hoping for the best and not having any clue what people are doing.”

Instead, organizations need to understand how they actually operate. “It is not enough to identify sensitive data, intellectual property, or trade secrets,” he said.

He advises businesses to figure out “which behaviors are acceptable, which workflows deserve attention, how those workflows could be exploited, and how that exploitation would be detected.”

Did you find this article helpful? Click on one of the following buttons
We're so happy you liked! Get more delivered to your inbox just like it.

We're sorry this article didn't help you today – we welcome feedback, so if there's any way you feel we could improve our content, please email us at contact@tech.co

Written by:
Nicole is Tech.co's News Editor, reporting on the latest technology news and curating The AI Strat newsletter. After studying English Literature and Creative Writing, they worked on local newspapers and online publications, including Outlander Magazine. Previously, they covered tech products and news at Expert Reviews. Outside of Tech.co, they enjoy sports and video games.
Explore More See all news
Back to top