started · updated
AI proliferation lowers barriers for cyberattacks and vulnerability discovery
The proliferation of high-performance open-weight AI models is lowering the barrier for cyberattacks. Unlike closed models, which are subject to vendor monitoring and safety guardrails, open-weight models can be downloaded and modified. This allows attackers to create “uncensored” versions that bypass safety restrictions, facilitating more efficient reconnaissance and vulnerability discovery.
A report from the Google Threat Intelligence Group (GTIG) noted that AI is being integrated into nearly every stage of the cyberattack workflow. This includes the use of LLMs to identify complex logic errors in software that traditional scanners might miss. While fully autonomous AI attacks are not yet widespread due to computational costs, AI is increasingly used to assist human actors in finding profitable targets, such as financial and cryptocurrency systems.
Cynthia Kaiser, a former FBI official and current senior vice president at Halcyon, highlighted a surge in criminal AI activity on the dark web. She reported that AI-related posts on these platforms rose from 38 in December 2025 to approximately 1,500 by February 2026, signaling a rapid increase in the availability of tools for ransomware and other malicious activities.
Entities
Accenture · FBI · Google Threat Intelligence Group · Halcyon