July 28, 2026
When AI Becomes an Active Cyber Participant

When AI Becomes an Active Cyber Participant
Artificial intelligence has quickly become one of the most transformative technologies of our generation. Every week there seems to be another announcement about a new model, a new capability, or another company racing to integrate AI into its products. Most of the conversation has centered around productivity and innovation. As someone who has spent my career in cybersecurity, I think we also need to spend more time talking about security.
The recent incident involving OpenAI and Hugging Face is a perfect example.
According to OpenAI, the incident occurred during an internal evaluation of one of its advanced AI models that was being tested for offensive cybersecurity capabilities. The company reported that the model found a way to access the internet outside of its intended testing environment and ultimately compromised Hugging Face infrastructure while attempting to complete the objective it had been given.
Whether every detail of that account ultimately proves to be accurate remains to be seen. Like any security incident, investigations take time; additional facts emerge, and the initial public narrative often evolves. As security professionals, it is important that we avoid jumping to conclusions until the technical analysis is complete.
Regardless, the incident raises a much bigger question.
What happens when AI moves beyond simply answering questions and begins actively making decisions and taking actions?
That is a very different world than the one most organizations are thinking about today.
For years we’ve talked about AI generating phishing emails, writing malware, or helping attackers write better code. Those are certainly legitimate concerns, but they still require a human to direct the activity.
AI agents represent something different.
Instead of telling a model exactly how to perform every step, you give it an objective. The model determines the path to achieve that objective. It can make decisions, adapt when obstacles appear, and potentially chain together hundreds or thousands of actions that no human explicitly programmed.
That shift has enormous implications for cybersecurity.
Attackers have always embraced automation. They automated password guessing, vulnerability scanning, phishing campaigns, and malware deployment years ago. AI doesn’t replace those techniques. It accelerates them and makes them significantly more adaptive.
The same technology that helps an employee summarize documents or automate repetitive work could also enable an attacker to identify vulnerabilities more quickly, adjust tactics in real time, and pursue an objective with minimal human intervention.
That’s why I believe this story matters far beyond OpenAI or Hugging Face.
Whether this particular event turns out to be exactly as initially described is almost secondary. The capability itself is no longer theoretical. AI is rapidly becoming an operational participant in cybersecurity.
The good news is that the same technology can dramatically improve defense.
Security teams are already using AI to identify threats, analyze massive amounts of log data, detect anomalies, prioritize alerts, and assist with incident response. Used responsibly, AI has the potential to make defenders significantly faster than they’ve ever been before.
The challenge is making sure security evolves just as quickly as technology itself.
Too many organizations still approach AI as simply another software application. They ask whether employees should use ChatGPT or Copilot. They debate productivity gains and licensing costs.
Those are important discussions, but they are not security discussions.
The questions security leaders should be asking are different.
What systems can AI access?
What data is allowed to be retrieved?
How are its actions monitored?
What permissions does it inherit?
Can those permissions be abused?
How quickly would we know if something unexpected occurred?
These are governance questions. They are identity questions. They are risk management questions. And they are becoming more important every month.
One of the biggest mistakes I see organizations make is assuming AI changes everything.
AI reinforces the importance of the cybersecurity fundamentals we’ve been preaching for years.
Strong identity management.
Network segmentation.
Continuous monitoring.
Comprehensive logging.
Rapid incident response.
Those principles matter even more when intelligent automation enters the environment.
The organizations that will succeed over the next decade won’t necessarily be the ones that adopt AI the fastest. They’ll be the ones that adopt it responsibly while building the security controls needed to support it.
The OpenAI and Hugging Face incidents are unlikely to be the last headline involving AI and cybersecurity.
In fact, I suspect we’re only seeing the beginning.
As business leaders, technologists, and security professionals, we shouldn’t be asking whether AI belongs to our organizations. That question has already been answered.
Instead, we should ask how we can safely harness one of the most powerful technologies ever created while ensuring it remains an asset rather than a liability.
That conversation is no longer a glimpse into the future.
It’s happening right now.
—-
Chris May is Vice President of Security & Growth at Advantage Technology, where he advises organizations on cybersecurity, AI governance, and risk management. He writes regularly for techfrederick on emerging technology and its impact on businesses in our region.

