* [![perspectives](https://www.paloaltonetworks.com/perspectives/wp-content/uploads/2025/02/prespective-icon.png)](https://www.paloaltonetworks.com/perspectives)
* The Dawn of the Autonomous Agent: When AI Starts Attacking

# The Dawn of the Autonomous Agent: When AI Starts Attacking

![The Dawn of the Autonomous Agent: When AI Starts Attacking](https://www.paloaltonetworks.com/perspectives/wp-content/uploads/2026/01/Dawn-of-the-Autonomous-Agent-featured.jpg)  
**By [Dr. Nicole Nichols](https://www.paloaltonetworks.com/perspectives/author/dr-nicole-nichols/ "Posts by Dr. Nicole Nichols")** | **8 min read** |  
![share icon](https://paloaltonetworks.com/content/dam/pan/en_US/cxo-perspectives/images/cxo-share.svg)

* LinkedIn button ![linkedin-icon](https://www.paloaltonetworks.com/content/dam/pan/en_US/microsite/cortex/images/share-linkedin.svg)
* Twitter share button ![twitter-icon](https://www.paloaltonetworks.com/content/dam/pan/en_US/microsite/cortex/images/share-twitter-x-black.svg)
* \[Email share button ![email-icon](https://www.paloaltonetworks.com/content/dam/pan/en_US/microsite/cortex/images/share-email.svg)\](mailto:?subject=The Dawn of the Autonomous Agent: When AI Starts Attacking\&body=Check out this article https%3A%2F%2Fwww.paloaltonetworks.com%2Fperspectives%2Fthe-dawn-of-the-autonomous-agent-when-ai-starts-attacking%2F "Share in Email")
* ![copy-icon](https://www.paloaltonetworks.com/perspectives/wp-content/themes/csp2025/dist/images/icons/icon-share.svg)
  [](https://www.paloaltonetworks.com/perspectives/the-dawn-of-the-autonomous-agent-when-ai-starts-attacking/?pdf=download&lg=en&_wpnonce=83197ae001 "Click here to download") MEET THE AUTHOR  
  ![](https://www.paloaltonetworks.com/perspectives/wp-content/uploads/2025/06/nicole-nichols.jpg)  
  Nicole Nichols is a Distinguished Engineer in Machine Learning Security at Palo Alto Networks. She previously held senior roles at Apple, Microsoft and has contributed to both academia and industry advancements in adversarial machine learning and security. She has published at numerous ACM, IEEE, and CVPR workshops, and was co-chair of ICML-ML4Cyber workshop. She has a PhD in Electrical Engineering from the University of Washington....

[Learn more](https://www.paloaltonetworks.com/perspectives/author/dr-nicole-nichols/)

## IN THIS ARTICLE

For the entire history of cybersecurity, human speed has always been a bottleneck, *somewhere* in the system. Whether it was a lone hacker or a nation-state team, scripting and automation could not bypass the human element necessary to plan, coordinate, interpret and execute attack objectives. Consequently, the overall speed of an attack could only progress as fast as the person behind the keyboard.

That era is rapidly fading. We are now witnessing the undeniable rise of agentic AI. Shedding light on its use, Anthropic recently released [a landmark report](https://assets.anthropic.com/m/ec212e6566a0d47/original/Disrupting-the-first-reported-AI-orchestrated-cyber-espionage-campaign.pdf), which details the disruption of a cyberespionage operation orchestrated by AI agents on behalf of a group referred to as GTG-1002. The AI in this campaign followed a script and autonomously orchestrated the attack. It also mapped attack surfaces, exploited vulnerabilities, moved laterally and conducted intelligence analysis --- all at machine speed.

Beyond just an upgrade in tool sets, this campaign completely changes the dynamics of cyberwarfare. The adversary no longer sleeps or needs a human so it can connect disparate pieces of information purposefully and faster than ever before.

## The Invisible Evolution

To understand where we are going, we must recognize how the board has shifted. In AI's infancy, its success was limited to narrow, structured tasks. As large language models (LLMs) evolved, they gained the ability to generalize across complex, unstructured data. We saw this first in defense --- automated patching, code generation and vulnerability identification.

Now, the dual nature of powerful LLMs is coming home to roost, birthing a new anatomy of algorithmic threat that disrupts and defuses core processes in traditional defense.

An autonomous offensive LLM agent, unlike traditional malware, requires no command and control infrastructure because the agent is the command and control. It analyzes network topology, understands business processes, and autonomously decides how to move laterally toward critical assets. And, it doesn't need a human controller because it simply thinks.

Once inside, this agent employs a new form of dynamic persistence. We often worry about "adversarial examples" --- like tricking a sensor with pixel noise --- but that's just one parlor trick in the agent's toolbox. The true threat is from the holistic set of an agent using the toolbox. Because an autonomous agent acts with a comprehensive, adaptive logic, it can overwhelm human control points with sheer speed, hiding its actions in the raw noise of logs where human analysts cannot connect the dots fast enough. It also maintains a holistic view of the target, correlating seemingly unrelated data points across the enterprise to find structural weaknesses that isolated defense strategies --- human or otherwise --- would not anticipate.

Perhaps most insidious, however, is the potential for stealth within and across all phases of an attack. The silent persistence of an agent, maintaining context of the overall attack through markdown files, as observed in the GTG-1002 event, can conduct data poisoning or piecewise indirect exfiltration a drop at a time, or piggybacking within the routine dataflows. Unlike a loud, chaotic event like a Network Mapper (Nmap) scan, this attack is a low, slow and nearly undetectable shift in how an offensive entity can maliciously influence processes and extract value from your organization's greatest intellectual assets.

## The Death of the Grace Period

We need to be clear that agentic AI breaks the "grace period."

Defenders for decades have enjoyed a lag time between the publication of a common vulnerability and exposure (CVE) and the weaponization of an exploit. That gap allowed teams to patch, test and deploy fixes. With autonomous agents, that gap is downgraded to zero.

An agent capable of reading a CVE, writing code and validating an exploit can weaponize public information faster than any human team can read the report. Recent research has demonstrated AI systems capable of generating functional exploits for new CVEs in as little as 15 minutes, turning our own transparency into a vulnerability.^[1](#foot-notes)^ The detailed roadmaps we publish to help defenders now fuel the exact agents we are fighting.

This shift requires a new rule of engagement: Data privacy is a necessary layer of defense. We must fundamentally rethink how we share data, which becomes a question of capacity. If an AI agent identifies a thousand vulnerabilities in a single hour, the act of "responsible disclosure" becomes a Denial-of-Service attack on the remediation process. Human teams simply cannot metabolize risk at that volume. Other data that could be used in social engineering or credential stealing can be pulled into attack chains with greater efficiency. Broadcasting our weaknesses to the world assumes the adversary is slow enough, and the list of problems short enough, for us to win the foot race. Humans will always lose this race when up against an autonomous agent.

## Adapting at Machine Speed

Leading through this transition demands a shift in operational philosophy. The ambiguity of the threat timeline --- whether it matures in six months or six years --- is a test of strategic foresight, not a permission slip to delay.

To survive, leaders must first escape the trap of treating legacy infrastructure as a permanent asset. Naturally we want to protect the investments we have made, but in an autonomous environment, any siloed tool that adds latency is a liability. An agent exploits the milliseconds it takes to correlate a network signal with an endpoint alert. Holding onto these tools because of their "sunk cost" is a strategic error. If a tool cannot operate at machine speed, it is unequivocally a liability.

In order to do this, though, organizations must embrace a nonlinear approach to modernization. Attackers do not incrementally improve their scripts; they leapfrog to autonomous orchestration. Defenders must match that trajectory. We must stop allocating resources to reshape and prolong legacy products that were never designed for this era. The focus must shift entirely from maintaining the old processes to R\&D for the new needs of the autonomous age. You cannot defeat an exponential threat with a linear upgrade path.

Ultimately, we must learn to lead through uncertainty. Traditional management models often demand floodlights --- full clarity, guaranteed ROI and predictable outcomes before approving a budget. But agentic AI is an adaptive, rapidly evolving threat. If you wait for a fully illuminated plan, you are already behind. Leaders must become comfortable operating with a "dim flashlight," seeing only the next few steps but moving with conviction. The goal is continuous adaptation, not perfect clarity.

## Be the Red Team

Fundamentally, we must change how we test our own resilience. Professional red teaming is often limited to narrow domain experts evaluating isolated systems. This approach creates a dangerous blind spot. We need diverse teams for the sake of variety and because testing bits in isolation fails to expose the systemic vulnerabilities that an agent can connect across subcomponents. While unstructured hackathon events might bring together more diverse perspectives, relying on ad hoc efforts performed at the margins of the workday is insufficient to create structured, systematic assessments.

We must invest in dedicated, diverse teams whose sole job is to start from scratch and learn how to be the attackers of this new era. We need to anticipate where current defenses will fail before an autonomous agent finds those cracks in the wild.

## Leadership in the Age of Agentic AI

The rise of agentic AI risk marks the inevitable next chapter in cybersecurity. But, realizing the promise of an autonomous defense requires a decisive shift in how the enterprise buys, builds and deploys security.

The boardroom's priority is to intentionally remove the strategic friction of adoption --- shifting risk tolerance and expediting budget approvals that often stall innovation. This top-down clarity empowers managers to tackle the operational friction, giving R\&D teams the specific mandate to leverage AI, study the new battlefield and build robust autonomous defensive agents. The capacity to execute this plan requires new performance goals. They must allow risk and failure so teams can quickly assess a wide set of options with technical depth and curiosity, but without being slowed down by procurement processes or assurances of success that cannot be made.

The question has shifted from *when* this battle will be fought to *how* you choose to prepare for it. Will you look backwards at past resilience, confident that it has gotten you too far to fail? As we see our adversaries playing chess to our checkers, how will you enable your teams to learn this new game and level up?

The move is yours.

Curious about what else Nicole has to say? Check out her other articles on [Perspectives](https://www.paloaltonetworks.com/perspectives/author/dr-nicole-nichols/).

*** ** * ** ***

^1^ Mayura Kathir, "[AI Systems Can Craft Exploits for Known CVEs in Minutes](https://cyberpress.org/ai-systems-can-craft-exploits/)," Cyber Press, August 22, 2025.

* [AI](https://www.paloaltonetworks.com/perspectives/all-articles/?cat=ai)
* [Staying Ahead of Evolving Threats](https://www.paloaltonetworks.com/perspectives/all-articles/?cat=staying-ahead-of-evolving-threats)

## Related Content

![](https://www.paloaltonetworks.com/perspectives/wp-content/uploads/2026/03/Securing-the-Wrong-Layer-featured.jpg) BLOG

### Staying Ahead of Evolving Threats

**Cybersecurity in 2026: What we predicted, what surprised us, and what's next**

At Palo Alto Networks, we are privileged to sit at the intersection of cybe...

[Haider Pasha](https://www.paloaltonetworks.com/perspectives/author/haider-pasha/ "Posts by Haider Pasha")
[](https://www.paloaltonetworks.com/perspectives/cybersecurity-in-2026-what-we-predicted-what-surprised-us-and-whats-next/)  
![](https://www.paloaltonetworks.com/perspectives/wp-content/uploads/2026/03/Why-Cybersecurity-KPIs-Are-Changing-featured.jpg) BLOG

### AI

**Why Cybersecurity KPIs Are Changing (And What This Means for Security Leaders)**

True cyber resilience is impossible to achieve without strategic and tactic...

[Helmut Reisinger](https://www.paloaltonetworks.com/perspectives/author/helmut-reisinger/ "Posts by Helmut Reisinger")
[](https://www.paloaltonetworks.com/perspectives/why-cybersecurity-kpis-are-changing-and-what-this-means-for-security-leaders/)  
![](https://www.paloaltonetworks.com/perspectives/wp-content/uploads/2026/03/Weaponized-Intelligence-featured.jpg) BLOG

### AI

**Weaponized Intelligence**

We are building the foundation that makes defense possible....

[Nikesh Arora](https://www.paloaltonetworks.com/perspectives/author/nikesh-arora/ "Posts by Nikesh Arora")
[](https://www.paloaltonetworks.com/perspectives/weaponized-intelligence/)  
STAY CONNECTED

## Connect with our team today

Job Level  
Sign me up to receive news, product updates, sales outreach, event information and special offers about Palo Alto Networks and its partners.  
By submitting this form, I understand my personal data will be processed in accordance with Palo Alto Networks [Privacy Statement](https://www.paloaltonetworks.com/legal-notices/privacy?ts=markdown) and [Terms of Use](https://www.paloaltonetworks.com/legal-notices/terms-of-use?ts=markdown).  
This site is protected by reCAPTCHA and the Google [Privacy Policy](https://policies.google.com/privacy) and [Terms of Service](https://policies.google.com/terms) apply.
Reach out  
{#footer} Products and Services

* [AI-Powered Network Security Platform](https://www.paloaltonetworks.com/network-security?ts=markdown)

* [Secure AI by Design](https://www.paloaltonetworks.com/ai-security?ts=markdown)

* [Prisma AIRS](https://www.paloaltonetworks.com/ai-security/prisma-airs?ts=markdown)

* [AI Access Security](https://www.paloaltonetworks.com/sase/ai-access-security?ts=markdown)

* [Cloud Delivered Security Services](https://www.paloaltonetworks.com/network-security/security-subscriptions?ts=markdown)

* [Advanced Threat Prevention](https://www.paloaltonetworks.com/network-security/advanced-threat-prevention?ts=markdown)

* [Advanced URL Filtering](https://www.paloaltonetworks.com/network-security/advanced-url-filtering?ts=markdown)

* [Advanced WildFire](https://www.paloaltonetworks.com/network-security/advanced-wildfire?ts=markdown)

* [Advanced DNS Security](https://www.paloaltonetworks.com/network-security/advanced-dns-security?ts=markdown)

* [Enterprise Data Loss Prevention](https://www.paloaltonetworks.com/sase/enterprise-data-loss-prevention?ts=markdown)

* [Enterprise IoT Security](https://www.paloaltonetworks.com/network-security/enterprise-device-security?ts=markdown)

* [Medical IoT Security](https://www.paloaltonetworks.com/network-security/medical-device-security?ts=markdown)

* [Industrial OT Security](https://www.paloaltonetworks.com/network-security/ot-security-solution?ts=markdown)

* [SaaS Security](https://www.paloaltonetworks.com/sase/saas-security?ts=markdown)

* [Next-Generation Firewalls](https://www.paloaltonetworks.com/network-security/next-generation-firewall?ts=markdown)

* [Hardware Firewalls](https://www.paloaltonetworks.com/network-security/hardware-firewall-innovations?ts=markdown)

* [Software Firewalls](https://www.paloaltonetworks.com/network-security/software-firewalls?ts=markdown)

* [Strata Cloud Manager](https://www.paloaltonetworks.com/network-security/strata-cloud-manager?ts=markdown)

* [SD-WAN for NGFW](https://www.paloaltonetworks.com/network-security/sd-wan-subscription?ts=markdown)

* [PAN-OS](https://www.paloaltonetworks.com/network-security/pan-os?ts=markdown)

* [Panorama](https://www.paloaltonetworks.com/network-security/panorama?ts=markdown)

* [Secure Access Service Edge](https://www.paloaltonetworks.com/sase?ts=markdown)

* [Prisma SASE](https://www.paloaltonetworks.com/sase?ts=markdown)

* [Application Acceleration](https://www.paloaltonetworks.com/sase/app-acceleration?ts=markdown)

* [Autonomous Digital Experience Management](https://www.paloaltonetworks.com/sase/adem?ts=markdown)

* [Enterprise DLP](https://www.paloaltonetworks.com/sase/enterprise-data-loss-prevention?ts=markdown)

* [Prisma Access](https://www.paloaltonetworks.com/sase/access?ts=markdown)

* [Prisma Browser](https://www.paloaltonetworks.com/sase/prisma-browser?ts=markdown)

* [Prisma SD-WAN](https://www.paloaltonetworks.com/sase/sd-wan?ts=markdown)

* [Remote Browser Isolation](https://www.paloaltonetworks.com/sase/remote-browser-isolation?ts=markdown)

* [SaaS Security](https://www.paloaltonetworks.com/sase/saas-security?ts=markdown)

* [AI-Driven Security Operations Platform](https://www.paloaltonetworks.com/cortex?ts=markdown)

* [Cloud Security](https://www.paloaltonetworks.com/cortex/cloud?ts=markdown)

* [Cortex Cloud](https://www.paloaltonetworks.com/cortex/cloud?ts=markdown)

* [Application Security](https://www.paloaltonetworks.com/cortex/cloud/application-security?ts=markdown)

* [Cloud Posture Security](https://www.paloaltonetworks.com/cortex/cloud/cloud-posture-security?ts=markdown)

* [Cloud Runtime Security](https://www.paloaltonetworks.com/cortex/cloud/runtime-security?ts=markdown)

* [Prisma Cloud](https://www.paloaltonetworks.com/prisma/cloud?ts=markdown)

* [AI-Driven SOC](https://www.paloaltonetworks.com/cortex?ts=markdown)

* [Cortex XSIAM](https://www.paloaltonetworks.com/cortex/cortex-xsiam?ts=markdown)

* [Cortex XDR](https://www.paloaltonetworks.com/cortex/cortex-xdr?ts=markdown)

* [Cortex XSOAR](https://www.paloaltonetworks.com/cortex/cortex-xsoar?ts=markdown)

* [Cortex Xpanse](https://www.paloaltonetworks.com/cortex/cortex-xpanse?ts=markdown)

* [Unit 42 Managed Detection \& Response](https://www.paloaltonetworks.com/cortex/managed-detection-and-response?ts=markdown)

* [Managed XSIAM](https://www.paloaltonetworks.com/cortex/managed-xsiam?ts=markdown)

* [Next-Generation Identity Security](https://www.paloaltonetworks.com/idira?ts=markdown)

* [Privileged Access Management](https://www.paloaltonetworks.com/idira/human/privileged-access-management?ts=markdown)

* [Identity and Access Management](https://www.paloaltonetworks.com/idira/human/identity-and-access-management?ts=markdown)

* [Endpoint Privilege Manager](https://www.paloaltonetworks.com/idira/human/endpoint-privilege-manager?ts=markdown)

* [Identity Governance](https://www.paloaltonetworks.com/idira/human/identity-governance?ts=markdown)

* [Workforce Password Management](https://www.paloaltonetworks.com/idira/human/workforce-password-management?ts=markdown)

* [Agentic Identities](https://www.paloaltonetworks.com/idira/agentic?ts=markdown)

* [Secrets Management](https://www.paloaltonetworks.com/idira/machine/secrets-management?ts=markdown)

* [Unified Secrets Governance](https://www.paloaltonetworks.com/idira/machine/unified-secrets-governance?ts=markdown)

* [Application Credentials Delivery](https://www.paloaltonetworks.com/idira/machine/application-credentials-delivery?ts=markdown)

* [Vendor Privileged Access](https://www.paloaltonetworks.com/idira/human/vendor-privileged-access?ts=markdown)

* [Threat Intel and Incident Response Services](https://www.paloaltonetworks.com/unit42?ts=markdown)

* [Prepare for Emerging Risks](https://www.paloaltonetworks.com/unit42/frontier-ai-defense?ts=markdown)

* [Strengthen Your Defenses](https://www.paloaltonetworks.com/unit42/strengthen-your-defenses?ts=markdown)

* [Build Your Security Strategy](https://www.paloaltonetworks.com/unit42/build-your-security-strategy?ts=markdown)

* [Understand the Adversary](https://www.paloaltonetworks.com/unit42/threat-intelligence?ts=markdown)

* [Respond to a Cyber Attack](https://www.paloaltonetworks.com/unit42/respond?ts=markdown)  
  Company

* [About Us](https://www.paloaltonetworks.com/about-us?ts=markdown)

* [Careers](https://jobs.paloaltonetworks.com/en/)

* [Contact Us](https://www.paloaltonetworks.com/company/contact-sales?ts=markdown)

* [Corporate Responsibility](https://www.paloaltonetworks.com/about-us/corporate-responsibility?ts=markdown)

* [Customers](https://www.paloaltonetworks.com/customers?ts=markdown)

* [Investor Relations](https://investors.paloaltonetworks.com/)

* [Location](https://www.paloaltonetworks.com/about-us/locations?ts=markdown)

* [Newsroom](https://www.paloaltonetworks.com/company/newsroom?ts=markdown)  
  Popular Links

* [Blog](https://www.paloaltonetworks.com/blog/?ts=markdown)

* [Communities](https://www.paloaltonetworks.com/communities?ts=markdown)

* [Content Library](https://www.paloaltonetworks.com/resources?ts=markdown)

* [Cyberpedia](https://www.paloaltonetworks.com/cyberpedia?ts=markdown)

* [Event Center](https://events.paloaltonetworks.com/)

* [Manage Email Preferences](https://start.paloaltonetworks.com/preference-center)

* [Products A-Z](https://www.paloaltonetworks.com/products/products-a-z?ts=markdown)

* [Product Certifications](https://www.paloaltonetworks.com/legal-notices/trust-center/certifications?ts=markdown)

* [Report a Vulnerability](https://www.paloaltonetworks.com/security-disclosure?ts=markdown)

* [Sitemap](https://www.paloaltonetworks.com/sitemap?ts=markdown)

* [Tech Docs](https://docs.paloaltonetworks.com/)

* [Unit 42](https://unit42.paloaltonetworks.com/)

* [Do Not Sell or Share My Personal Information](https://panwedd.exterro.net/portal/dsar.htm?target=panwedd)
  ![Palo Alto Networks Logo](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/pan-logo-dark.svg)

* [Privacy](https://www.paloaltonetworks.com/legal-notices/privacy?ts=markdown)

* [Trust Center](https://www.paloaltonetworks.com/legal-notices/trust-center?ts=markdown)

* [Terms of Use](https://www.paloaltonetworks.com/legal-notices/terms-of-use?ts=markdown)

* [Documents](https://www.paloaltonetworks.com/legal?ts=markdown)

Copyright © 2026 Palo Alto Networks. All Rights Reserved

* [![Youtube](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/social/youtube-black.svg)](https://www.youtube.com/user/paloaltonetworks)
* [![Podcast](https://www.paloaltonetworks.com/content/dam/pan/en_US/images/icons/podcast.svg)](https://www.paloaltonetworks.com/podcasts/threat-vector?ts=markdown)
* [![Facebook](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/social/facebook-black.svg)](https://www.facebook.com/PaloAltoNetworks/)
* [![LinkedIn](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/social/linkedin-black.svg)](https://www.linkedin.com/company/palo-alto-networks)
* [![Twitter](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/social/twitter-x-black.svg)](https://twitter.com/PaloAltoNtwks)
* EN  
  Select your language
