What Is an Autonomous AI Attack, and Has One Actually Happened?

Autonomous AI attack illustration: AI agents probing government networks across Asia
Takeaways

    • Security vendors have reported at least four “autonomous” AI attack cases across Asia since November 2025, and not one government has confirmed one.

    • France’s ANSSI says it has identified zero AI systems capable of running every stage of an attack on their own.

    • The EU Cyber Resilience Act’s 24-hour reporting duty starts on 11 September, and none of Europe’s three cyber laws mentions AI-driven attacks.

Somewhere between Tel Aviv, San Francisco and Palo Alto, a consensus is forming that AI agents now run cyberattacks largely on their own. The evidence for it is thinner than the headlines suggest, and every major claim so far has originated from a commercial security vendor. Both things can be documented, so here is the count.

Who Is Claiming What, From Taipei to Bangkok

The newest claim arrived on 12 August. Dream Security, an Israeli vendor that raised $260 million at a $3 billion valuation selling AI defence to governments, published a report describing a “near-autonomous” four-day intrusion into an Asian government’s systems in July: 21 systems mapped, at least 85 accounts compromised, more than 2,500 personnel files taken. Dream’s own report names no country; press reports identified the target as Taiwan, and the government in question has not commented.

It is not the first such account. Anthropic reported in November 2025 that AI performed 80 to 90% of an espionage campaign against roughly 30 targets worldwide. Palo Alto Networks’ Unit 42 described a campaign against Malaysian and other targets in a report it titled “Autonomous Cyberattacks”. And the security firm Hunt.io has documented an AI-agent espionage case at Thailand’s Ministry of Finance, where an open-source agent ran reconnaissance without human approval. The claims span Asia; the sourcing pattern is the same everywhere. Each account comes from one commercial security vendor. Separately, China’s foreign ministry accused the United States in March of AI-enabled attacks on Chinese infrastructure, although it did not publish independently verifiable evidence.

What the Evidence Actually Shows

Read closely, the reports undercut their own headlines. Dream’s research says “near-autonomous”, with humans setting the framework’s parameters; it names no AI model and publishes no indicators of compromise. In Unit 42’s “autonomous” campaign, the attacker had to fall back to manual operations to succeed. The Anthropic case drew the same criticism: “AI is a super boost but it’s not skynet, it doesn’t think,” researcher Daniel Card told BleepingComputer. CSIS’s Jiwon Lim put it more formally: AI’s contribution today is “not innovation but efficiency”, “a change in timelines, not in type”.

The capability is real and improving; we have covered how agentic attackers actually work and an agent-driven breach in July. What no published case yet shows is an AI running every stage of an attack on its own.

What Governments Say, and Do Not

The agencies with the deepest visibility are far quieter than the vendors. France’s ANSSI stated in February that it is not aware of any AI-enabled attack on French entities and has not identified any AI system capable of carrying out every stage of an attack autonomously. ENISA has published nothing on autonomous attacks; what its Threat Landscape 2025 actually measured is that four fifths of social engineering campaigns involved AI-assisted phishing. Germany’s BSI told German media in August that AI lowers the barrier to entry. Taiwan’s own National Security Bureau, reporting 2.63 million daily intrusion attempts in 2025, did not mention AI-driven operations once.

Asia’s governments are moving on governance rather than attribution: Singapore’s IMDA published a Model AI Governance Framework for Agentic AI in January, one of the first anywhere. And the UK’s AISI found a frontier model completed 56% of a simulated 32-step enterprise attack for roughly £65 a run, with its own caveats attached. Test conditions, not the wild. That distinction is the whole story so far.

Europe’s Rulebook Gap

Whatever the truth of any single incident, one fact needs no vendor: none of the EU’s three core cyber laws recognises an AI-driven attacker. The Cyber Resilience Act’s 24-hour incident reporting duty begins on 11 September and the text never mentions AI. NIS2’s transposition is running late, with roughly a third of covered German organisations registered by the March deadline. DORA does not name AI either, which is why the ECB sent banks a “dear CEO letter” on 8 July; more than 85% of supervised banks already use AI, and they are reported to have until 31 October to file action plans. Our sister publication covered the banking exposure in May.

Carnegie Europe’s researchers argue the AI Act does not treat agentic AI as its own category either.

So the honest tally stands at: several vendors claiming, no government confirming, no indicators published, and every measured trend still pointing the same way. Some of these incident reports may yet collapse under scrutiny. The gap in Europe’s rulebook will still be there when they do, and its first deadline is thirty days away.


This article is for information only. The incident accounts above come from commercial security vendors and have not been independently confirmed by the affected governments. All quotations were verified against primary documents on 12 August 2026.

Author: Ákos Szima

See Also

Check Point Research: AI Has Crossed From Assistant to Operator

Was Hugging Face Breached by AI Agents?

AISI Caught Anthropic’s Mythos 5 Going Rogue

Share this article

Latest news

Subscribe to our newsletter

More News