AI Agents
Can AI Agents Discover and Exploit Vulnerabilities?
Don't just read what happened. See what could happen next.
Prediction
AI-assisted discovery scales for known classes of bugs; fully autonomous exploit chains against hardened targets remain limited but rising.
- Confidence
- 61%
- Horizon
- 6–24 months
- Impact
- High
- Direction
- Increasing
Prediction changed +13 points in 21 days
Short answer
Past-year research and vendor demos show models helping find flaws and write PoCs faster. Defenders also use the same tools. The risk is asymmetric speed — attackers need one win; enterprises need continuous coverage.
Why this question matters
If agentic offense outruns patch cycles, software supply chains and critical infrastructure face a new tempo of risk.
What's happening now?
LLM-aided vuln research spreads
Security teams and researchers use models for triage, fuzzing hints, and exploit drafting.
Signal · strong
Defensive AI adoption
SOC tooling embeds copilots for alert triage and code review.
Signal · strong
Policy attention on dual-use agents
Labs and governments debate release norms for cyber-capable systems.
Signal · moderate
Agent tool-use on real systems
Browsing and shell access raise the ceiling for automated reconnaissance.
Signal · moderate
What could happen next?
Scenario A
Arms race accelerates
Offense and defense both scale; patch windows shrink industry-wide.
Scenario B
Defenders hold tempo
Automated remediation and memory-safe rewrites blunt most AI-boosted attacks.
Scenario C
Targeted breakthroughs
A few dramatic agent-led exploits force emergency standards without generalizing.
Key companies / entities
- Microsoft
- CrowdStrike
- OpenAI
- Anthropic
Evidence
- research
Offensive AI research papers and CTF results
- news
Vendor threat reports on AI-assisted attacks
- policy
Lab responsible-scaling cyber policies
Prediction history
- Sep 22, 202661%
- Sep 15, 202657%
- Sep 8, 202652%
- Sep 1, 202648%