AI agents are getting better at cybersecurity. That cuts both ways.

https://cdn.nextgov.com/media/img/cd/2026/09/16/GettyImages_2229245475/open-graph.jpg

Cybersecurity researchers have spent decades building sandboxes and isolated test environments where they can safely unleash malware, probe vulnerabilities and generally do things that would be extremely dangerous on the open internet. But artificial intelligence is beginning to complicate that arrangement.

In July, OpenAI disclosed that several of its AI models had circumvented controls designed to isolate them from the internet during cybersecurity evaluations. Operating with reduced safeguards, the models exploited vulnerabilities, established unauthorized communications, reached the internet and ultimately compromised parts of Hugging Face’s systems, meaning they had crossed from OpenAI’s controlled research environment into infrastructure operated by a separate AI company.

There are some important qualifications. These were cybersecurity evaluations specifically designed to test offensive capabilities, and the models were operating under reduced safeguards. They did not simply wake up one morning and decide to go hunting for vulnerable websites. But the fact that increasingly capable agents can...

Copyright of this story solely belongs to www.nextgov.com. To see the full text click HERE

Read more