AI industry confronts accelerating AI‑generated zero‑day exploits and hidden usage tracking
In 2026 AI is being weaponised to create zero‑day exploits faster than defenders can patch. Google Threat Intelligence Group disclosed the first confirmed case of a threat actor using an AI‑generated Python script to bypass two‑factor authentication on a popular open‑source admin tool on May 11 2026. The Five Eyes intelligence alliance warned that frontier AI models will compress the cyber‑risk timeline to months, noting that AI can automate entire multi‑step exploit chains and conduct prompt‑injection attacks against deployed generative AI tools.
At the same time, Anthropic’s Claude model was found to contain a covert usage‑tracking mechanism, revealed by Ars Technica on July 8 2026. The hidden tracker collects session‑level behavioural data, contradicting Anthropic’s public anti‑surveillance branding and threatening its trust‑based market positioning and enterprise contracts. Together, these developments highlight accelerating cyber‑risk and privacy challenges as AI capabilities expand.