Somewhere between Tel Aviv, San Francisco and Palo Alto, a consensus is forming that AI agents now run cyberattacks largely on their own. The evidence for it is thinner than the headlines suggest, and every major claim so far has originated from a commercial security vendor. Both things can be documented, so here is the count.
Who Is Claiming What, From Taipei to Bangkok
The newest claim arrived on 12 August. Dream Security, an Israeli vendor that raised $260 million at a $3 billion valuation selling AI defence to governments, published a report describing a “near-autonomous” four-day intrusion into an Asian government’s systems in July: 21 systems mapped, at least 85 accounts compromised, more than 2,500 personnel files taken. Dream’s own report names no country; press reports identified the target as Taiwan, and the government in question has not commented.
It is not the first such account. Anthropic reported in November 2025 that AI performed 80 to 90% of an espionage campaign against roughly 30 targets worldwide. Palo Alto Networks’ Unit 42 described a campaign against Malaysian and other targets in a report it titled “Autonomous Cyberattacks”. And the security firm Hunt.io has documented an AI-agent espionage case at Thailand’s Ministry of Finance, where an open-source agent ran reconnaissance without human approval. The claims span Asia; the sourcing pattern is the same everywhere. Each account comes from one commercial security vendor. Separately, China’s foreign ministry accused the United States in March of AI-enabled attacks on Chinese infrastructure, although it did not publish independently verifiable evidence.
What the Evidence Actually Shows
Read closely, the reports undercut their own headlines. Dream’s research says “near-autonomous”, with humans setting the framework’s parameters; it names no AI model and publishes no indicators of compromise. In Unit 42’s “autonomous” campaign, the attacker had to fall back to manual operations to succeed. The Anthropic case drew the same criticism: “AI is a super boost but it’s not skynet, it doesn’t think,” researcher Daniel Card told BleepingComputer. CSIS’s Jiwon Lim put it more formally: AI’s contribution today is “not innovation but efficiency”, “a change in timelines, not in type”.
The capability is real and improving; we have covered how agentic attackers actually work and an agent-driven breach in July. What no published case yet shows is an AI running every stage of an attack on its own.
What Governments Say, and Do Not
The agencies with the deepest visibility are far quieter than the vendors. France’s ANSSI stated in February that it is not aware of any AI-enabled attack on French entities and has not identified any AI system capable of carrying out every stage of an attack autonomously. ENISA has published nothing on autonomous attacks; what its Threat Landscape 2025 actually measured is that four fifths of social engineering campaigns involved AI-assisted phishing. Germany’s BSI told German media in August that AI lowers the barrier to entry. Taiwan’s own National Security Bureau, reporting 2.63 million daily intrusion attempts in 2025, did not mention AI-driven operations once.
Asia’s governments are moving on governance rather than attribution: Singapore’s IMDA published a Model AI Governance Framework for Agentic AI in January, one of the first anywhere. And the UK’s AISI found a frontier model completed 56% of a simulated 32-step enterprise attack for roughly £65 a run, with its own caveats attached. Test conditions, not the wild. That distinction is the whole story so far.
Europe’s Rulebook Gap
Whatever the truth of any single incident, one fact needs no vendor: none of the EU’s three core cyber laws recognises an AI-driven attacker. The Cyber Resilience Act’s 24-hour incident reporting duty begins on 11 September and the text never mentions AI. NIS2’s transposition is running late, with roughly a third of covered German organisations registered by the March deadline. DORA does not name AI either, which is why the ECB sent banks a “dear CEO letter” on 8 July; more than 85% of supervised banks already use AI, and they are reported to have until 31 October to file action plans. Our sister publication covered the banking exposure in May.
Carnegie Europe’s researchers argue the AI Act does not treat agentic AI as its own category either.
So the honest tally stands at: several vendors claiming, no government confirming, no indicators published, and every measured trend still pointing the same way. Some of these incident reports may yet collapse under scrutiny. The gap in Europe’s rulebook will still be there when they do, and its first deadline is thirty days away.
This article is for information only. The incident accounts above come from commercial security vendors and have not been independently confirmed by the affected governments. All quotations were verified against primary documents on 12 August 2026.
Author: Ákos Szima
See Also
Check Point Research: AI Has Crossed From Assistant to Operator
