AI in cyberattacks
The use of artificial intelligence (AI) in cyberattacks is becoming an increasingly serious security problem. AI allows attackers to automate reconnaissance, generate highly convincing phishing messages, identify vulnerabilities more efficiently and adapt malicious activities at greater speed and scale. It can also make attacks harder to detect by imitating legitimate behaviour and rapidly changing tactics in response to defensive measures. These developments increase risks for individuals, organisations and critical infrastructure, making stronger cybersecurity controls, faster incident response and responsible safeguards for AI technologies increasingly important.
Daniel Arp was featured in two ORF Zeit im Bild reports on 31 July and 3 August 2026, discussing how increasingly capable artificial intelligence systems are changing the cybersecurity landscape.
The first report examined recent security incidents involving AI agents developed by OpenAI and Anthropic. During cybersecurity testing, Anthropic models gained unauthorised access to systems belonging to three organisations, following a separate incident involving an OpenAI agent. Arp explained that the cases did not involve attacks on consumers or private computers. However, they demonstrated that autonomous AI systems may take unintended actions when given access to external tools, networks and credentials. He stressed that AI developers need stronger technical safeguards, clearly restricted permissions and effective monitoring to prevent agents from operating beyond their intended environments.
The second report focused on the growing use of AI by cybercriminals and other malicious actors. According to CrowdStrike’s 2026 Global Threat Report, attacks by AI-enabled adversaries increased by 89% in 2025 compared with the previous year. AI can help attackers conduct reconnaissance, create convincing and personalised phishing messages, automate parts of malware development and exploit security weaknesses more rapidly. These capabilities do not necessarily introduce entirely new forms of cyberattack, but they allow established methods to be carried out faster, more efficiently and on a much larger scale.
Together, the reports highlighted two related cybersecurity challenges: AI systems may cause harm through insufficiently controlled autonomous behaviour, while attackers can deliberately use the same technology to improve their operations. Arp emphasised that appropriate safeguards are required both during the development and deployment of advanced AI systems, and that companies must be held responsible for the actions of the AI systems they operate. Individuals and organisations can reduce their exposure by using password managers, two-factor authentication and passkeys where available. Systems and applications should be updated regularly, while important data should be protected through reliable and independently stored backups.
Watch the report from 31 July 2026 on ORF ON from 10:10.
Watch the report from 3 August 2026 on ORF ON from 3:11.