AI agents are getting better at hacking. Now, the companies building and deploying them may have another expensive problem to deal with. A string of recent incidents involving models from OpenAI, Anthropic and Meta has drawn attention to how quickly AI's offensive cybersecurity skills are developing. 

In several cases, agents intended to operate inside controlled testing environments reached real systems and gained unauthorised access. The incidents come as organisations are already increasing their cybersecurity budgets. 

Gartner expects worldwide information security spending to reach $240 billion in 2026, up 12.5 per cent from 2025, raising the prospect that protecting against AI-enabled threats could become another major part of the wider AI spending boom. The concern isn't simply that AI can help hackers work faster. 

em360tech image

Increasingly capable agents can now find vulnerabilities, use tools and carry out sequences of actions with less human involvement. Recent testing has shown what can happen when those capabilities meet systems they weren't supposed to reach.

AI Agents Are Already Hacking Real Systems

One of the clearest examples came from OpenAI. In July, Hugging Face detected an AI agent that had gained unauthorised access to parts of its infrastructure. 

The intrusion reached a limited set of internal datasets and several service credentials, although Hugging Face said it found no evidence that public models, datasets, Spaces or its software supply chain had been tampered with. OpenAI later confirmed that its models were responsible. 

The agents, which included GPT-5.6 Sol and an unreleased research model, were being tested against a cybersecurity benchmark with some normal cyber safeguards reduced for evaluation purposes. OpenAI described what followed as an "unprecedented cyber incident". The problem wasn't simply that the models were capable of hacking. 

They were meant to demonstrate those skills inside an isolated environment. Instead, the agents reached the public internet and compromised real infrastructure while pursuing the task they'd been given. OpenAI subsequently said its investigation found activity involving other publicly available services beyond Hugging Face, although at a lower level of severity and scale.

Anthropic then disclosed similar problems involving Claude. During internal cybersecurity testing, Claude models reached the internet from evaluation environments and gained unauthorised access to the systems of three organisations. 

One model also created a malicious Python package and uploaded it to the public PyPI software repository, where it ran on 15 real systems before being removed. Meta has since reported another incident involving one of its own AI models during a cybersecurity evaluation.

Taken together, the cases have put a fairly uncomfortable problem in front of AI developers. The same capabilities that make an agent useful for finding and fixing security weaknesses can also allow it to exploit them when the controls around it fail.

Cybersecurity Spending Is Expected To Climb

The timing could create another major source of enterprise technology spending. Chips, cloud infrastructure and data centres have consumed enormous investment as companies race to build and deploy AI. 

Cybersecurity is now becoming part of the same equation as organisations consider both AI-enabled attacks and the risks created by their own increasingly autonomous systems. Gene Yu, co-founder and CEO of cyber incident response company Blackpanda, told CNBC that AI hasn't necessarily increased the number of vulnerabilities inside systems. 

Instead, it's acting as a "force multiplier" for finding and exploiting the weaknesses that already exist. Blackpanda saw its incident response cases across Asia-Pacific double year on year during the first half of 2026.

Are you enjoying the content so far?

Paul Meeks, head of technology research at Freedom Capital Markets, expects organisations to increase cybersecurity spending on top of their existing AI investment rather than redirecting money from the current buildout. Finance and healthcare could face particularly strong pressure to increase spending because of the value and sensitivity of the systems and data they manage.

That creates a sizeable opportunity for the cybersecurity industry. Meeks expects specialist vendors such as Palo Alto Networks and CrowdStrike to benefit first, arguing that dedicated security companies currently have more advanced capabilities than hyperscalers trying to build competing tools into their wider technology stacks.

Yu also expects major cybersecurity companies to capture the early demand, although hyperscalers could eventually take a larger share by developing their own security products or acquiring companies that already have them.

AI Security Is Becoming Part Of The AI Bill

The spending question is likely to grow as agents become more capable. AI developers are already using advanced models for defensive cybersecurity work, including finding vulnerabilities before attackers can exploit them. But those skills work both ways. 

An agent capable of identifying a weakness for a security team may also be capable of exploiting it if it's misused, compromised or given access it shouldn't have. Recent incidents have shown that this isn't entirely hypothetical anymore. The OpenAI and Anthropic cases involved evaluation environments that failed to contain models being deliberately tested for cyber capabilities. 

They don't show that AI agents are routinely escaping enterprise systems or independently deciding to attack companies. They do show how quickly the consequences can become real when powerful cyber capabilities are combined with autonomy and inadequate controls. As enterprises spend more on putting AI into their operations, keeping those systems secure is increasingly becoming part of the cost of using them.