A figure from the UK's AI Security Institute has been circulating in security circles: frontier AI models' ability to complete cyberattack tasks is doubling approximately every four months. If that rate holds, the math gets uncomfortable fast.

The AISI has been testing frontier AI systems on offensive cyber tasks since November 2023, publishing findings in its Frontier AI Trends Report. The numbers are real. In early 2024, leading AI models completed apprentice-level cyber tasks about 10% of the time on average. That figure is now around 50%. Models now exist that can complete tasks normally requiring over ten years of human expertise. On a standardised 32-step corporate network attack scenario, performance improved from 1.7 completed steps in August 2024 to 9.8 steps by February 2026, roughly a sixfold increase in eighteen months.

So should we be panicking?

Not quite. But not dismissing it either.

The doomsday version of this story goes like this: AI capabilities are improving exponentially, therefore at some near-future point AI will conduct cyber warfare autonomously and at scale, and defenders will be helpless. The AISI data gets cited as proof we are already on that curve.

What the data actually shows is narrower. The AISI figures measure performance on structured benchmark tasks. Those are not equivalent to real-world attacks, which require contextual adaptation, operational security, and decision-making across genuinely novel environments. As the NCSC noted in its April 2026 guidance for defenders, current AI models are most useful to attackers as a way to lower the skill floor, allowing less experienced bad actors to attempt attacks they previously could not, rather than as autonomous hacking agents working without human direction.

The acceleration is real and worth taking seriously in threat modelling. A jump from 10% to 50% on apprentice-level tasks in roughly two years matters for defensive planning. Security teams that have not updated their threat models to account for AI-assisted attacks are behind the curve.

But "capability on a benchmark is doubling" is not the same as "fully autonomous AI cyberattackers are imminent." The benchmarks test specific, constrained scenarios. The AISI's own guidance focuses on practical defensive measures, not an imminent ceiling scenario. The fear is grounded in a real trend. The specific catastrophist version of it runs considerably ahead of what the evidence shows.

Sources

  1. i. www.aisi.gov.uk
  2. ii. www.resultsense.com
  3. iii. www.resultsense.com

Commentarii · 0

Add · a · Comment