
The information displayed in the AIM should not be reported as representing the official views of the OECD or of its member countries.
Cybercriminals are increasingly using AI systems, such as agentic AI and embedded LLMs, to automate and accelerate cyberattacks, including malware and ransomware campaigns. These AI-enabled attacks have already caused harm by increasing the speed, scale, and complexity of cyber threats, challenging defenders and disrupting organizations globally.[AI generated]
Why's our monitor labelling this an incident or hazard?
The article explicitly involves AI systems used for vulnerability discovery and patching, as well as their potential use by attackers and governments for offensive purposes. Although no direct harm is reported, the article clearly outlines plausible future harms stemming from AI's role in accelerating the vulnerability discovery race, which could disrupt critical government hacking operations and escalate cyber conflicts. This fits the definition of an AI Hazard, as it plausibly leads to significant harms but does not describe a realized incident. The discussion about potential policy responses and the dual-use nature of AI further supports this classification as a hazard rather than an incident or complementary information.[AI generated]