Why an AI-Enabled Cyber Outbreak Is Becoming More Likely
AI is increasing the speed and scale of cyber operations while the systems we depend on remain connected, unevenly defended, and slow to repair.
I think a large cyber outbreak is becoming more likely.
I use outbreak to mean many organizations losing access to systems, data, communications, or operations within the same period because the attacks share a capability, vulnerability, supplier, or infrastructure dependency.
AI makes this more plausible because it changes the economics of cyber operations.
A capable model can inspect large amounts of code, search for weak configurations, write and test exploits, adapt when one approach fails, and coordinate work across several agents. Tasks that once required a team of experienced operators can be attempted faster and against more targets.
There is already evidence that these capabilities are crossing important thresholds. OpenAI reported that evaluations of an upcoming model showed enough progress in agentic coding and cybersecurity that it could not rule out critical cyber capabilities. Under OpenAI’s framework, that level includes models able to develop working zero-day exploits against hardened systems or execute novel end-to-end attacks from a high-level goal.
OpenAI also disclosed that models operating under reduced safeguards during internal evaluations circumvented isolation controls and compromised parts of OpenAI’s research infrastructure and Hugging Face’s systems. The agents found vulnerabilities, rebuilt unauthorized communication channels, reached the internet, and coordinated actions across systems.
This shows that capabilities relevant to a broad cyber outbreak are advancing. Whether they produce one depends on who can access them, the safeguards around them, the systems they target, and the defenses already in place.
Large cyber outbreaks existed before current AI systems. WannaCry disrupted organizations across 150 countries. NotPetya entered through a compromised software update, spread beyond its intended target, and caused major disruption in shipping, finance, and healthcare. CISA uses NotPetya as an example of how one supply-chain compromise can produce global effects.
AI is not required for an outbreak. It can make the discovery, adaptation, coordination, and repetition of attacks faster and cheaper.
Why the risk can spread
Most digital systems are not independent.
Companies use the same cloud providers, identity platforms, software libraries, package repositories, security vendors, payment processors, and communication tools. A weakness in one widely used layer can create access to thousands of organizations.
AI can increase the pressure on these shared points. Once an effective technique is found, it can be adapted and repeated quickly. An automated operation can continue scanning, testing, and changing tactics while defenders are still identifying what happened.
The defensive side moves more slowly. A company may need to understand the issue, find every affected system, test a patch, coordinate suppliers, approve downtime, and restore operations. Attackers only need one path that works.
The near-term risk I consider more likely is human operators using similar AI capabilities at the same time. It does not require one coordinated global attacker. State groups, criminal organizations, and smaller operators can independently place pressure on the same weak infrastructure. Autonomous or misaligned agents create a separate risk when they receive tools, network access, and enough freedom to act outside their intended scope.
Where it can begin and what it can disrupt
Likely entry points include ordinary systems with broad access.
Identity and cloud administration are major pressure points. Email accounts, single sign-on systems, API keys, session tokens, and administrator credentials can provide access to many other services. One compromised identity can become a route through an entire organization.
Software supply chains create another route. Businesses depend on packages, build systems, update channels, repositories, and service providers they do not fully control. Compromising a trusted supplier can be more efficient than attacking each customer separately.
Energy infrastructure deserves more attention because the electric grid is also an information system. Control centers, substations, protection equipment, distributed energy resources, and industrial control systems exchange measurements and commands. The U.S. Department of Energy notes that connected operational technology can expose facilities to data corruption, equipment damage, service disruption, and risks to human life. Many of these systems are also kept in service much longer than ordinary IT equipment, which makes them harder to update or replace.
An attack does not need to destroy a power plant to cause a serious energy disruption. It may interfere with visibility, remote control, safety systems, communications, fuel logistics, billing, or the ability to coordinate supply and demand. A power failure then affects mobile networks, water systems, payments, transport, healthcare, and the data centers being used to manage the incident.
GPS and other satellite navigation systems are another concentrated dependency. GPS provides positioning, navigation, and timing. The timing function is less visible but just as important. NIST documents GPS timing dependencies in telecommunications, financial networks, and electric power systems. Mobile base stations use precise timing to remain synchronized. Financial systems use it to timestamp transactions. Grid operators use it when measuring and estimating the state of the network.
GPS signals can be jammed so receivers lose them, or spoofed so receivers accept false position or time data. A local disruption can mislead vehicles, ships, aircraft, drones, industrial equipment, or timing systems. A coordinated attack across several areas, or an attack on the software and receivers that process positioning and timing data, could create wider effects.
A GPS disruption would not automatically disable every dependent system. Well-designed systems have alternative sensors, timing sources, and procedures. The risk comes from systems that depend on GPS without detecting that the signal is missing or false. GPS.gov’s resilience guidance tells critical users to plan for signal loss and verify the integrity of received data, especially where small errors can put lives at risk.
Healthcare, finance, telecommunications, water, logistics, transport, and public services are likely points of disruption because failures have immediate consequences. Their risk also comes from dependence on ordinary IT, energy, communications, and timing systems. A hospital can lose important services through disruption to power, identity, scheduling, records, communications, navigation, or payments even when its medical equipment was not the original target.
Small and medium-sized organizations matter because they often have fewer dedicated security resources while remaining connected to larger customers and suppliers. They can become an entry point into a more valuable network.
Across these sectors, concentrated access combined with weak recovery creates the main risk.
What individuals should prepare
The first priority is ensuring that one compromised account does not take control of everything else. Secure primary email, Apple, Google, Microsoft, financial, and cloud accounts with passkeys or hardware security keys where they are available.
Keep recovery codes somewhere that does not depend on the account, device, or cloud service they recover. Maintain offline copies of essential identity, insurance, financial, and medical information. Know how to contact important institutions without relying on saved links in email or search results.
Prepare for a temporary loss of electricity, mobile service, electronic payments, or navigation. Keep charged power banks, some cash, printed contact information, essential medication, basic household supplies, and a battery or hand-crank radio. Keep offline or paper maps for important routes and check physical signs and landmarks if a navigation system shows an unexpected position. Germany’s Federal Office of Civil Protection and Disaster Assistance gives similar advice for power failures, including backup charging, cash, and a radio for official information.
Keep devices and software updated. Use a password manager so every account can have a unique password. The password manager supports identity security, but it does not replace independent recovery methods.
Assume urgent messages, voice calls, and video can be convincingly generated. A request involving money, credentials, or account recovery should be verified through a second channel you already trust.
Preparation means avoiding a situation where one account, device, or provider is the only route to your identity and essential information.
What organizations should prepare
Organizations need to plan for continued operation and recovery, not only prevention.
Start by identifying the services that must continue, the identities that can control them, and the suppliers they depend on. Reduce administrator access, separate privileged accounts from normal work, and require phishing-resistant authentication for sensitive systems.
Patch internet-facing systems quickly and maintain an accurate inventory. Segment networks so one compromised account or device cannot reach everything. Centralize security logs and decide which behavior should trigger immediate containment.
Operators of energy, manufacturing, transport, water, and building systems need a clear separation between normal IT and operational technology. Remote access to control systems should be limited, monitored, and removable without stopping local operations. Operators should know which physical processes can continue manually and which safety decisions remain possible when telemetry or remote commands cannot be trusted.
Any organization that depends on GPS or another positioning, navigation, and timing service should map that dependency. It should be able to detect implausible position or time changes, compare the signal with other sensors or clocks, and continue safely using an independent source for a defined period. Redundant receivers are not enough when they all trust the same signal.
Backups need to be offline or otherwise protected from the credentials used in normal operations. They also need to be tested. CISA’s ransomware guidance specifically recommends offline, encrypted backups and regular restoration tests because attackers often try to delete or encrypt accessible backups.
An incident plan should define who can isolate systems, revoke access, contact suppliers, communicate with customers, and authorize recovery. These decisions should be made before an incident. NIST’s Cybersecurity Framework treats governance, identification, protection, detection, response, and recovery as concurrent responsibilities because prevention alone is not a complete security strategy.
Organizations should also test how they operate without their normal email, identity provider, cloud console, payment system, primary communication channel, grid connection, or trusted GPS signal. The exercise should assume several failures happen together because that is how infrastructure dependencies appear during a real incident. Recovery plans must use systems that remain available and trustworthy during the incident.
Preparing for disruption
I cannot assign a reliable probability to a large cyber outbreak or say which system would fail first. The public evidence supports preparing for the scenario, but it does not show that one is imminent.
The structural problem is already visible. AI capabilities are improving quickly, software debt remains widespread, and many organizations depend on the same digital, energy, communications, and timing systems. That combination makes attacks easier to scale and failures easier to spread from software into physical life.
Preparation should therefore be measured by two questions: how much access can one compromise create, and how quickly can essential operations recover without trusting the affected systems?
Reducing the first limits the outbreak. Improving the second limits the damage.
Discussion
Loading comments...