The fear arrived fully formed the moment large language models could write code. If an AI can program, it can write malware, and if anyone can ask it to, then every bored teenager and petty crook just became a world-class hacker. The recent recall of Anthropic's Fable 5, pulled in part over worries it could help find software vulnerabilities, poured fresh fuel on the idea. So it is worth asking what the evidence actually shows. The short version: AI is helping attackers, but the leap from helping to unstoppable is mostly in our heads.
What is real
This is not a myth in the sense of being invented. The International AI Safety Report 2026 is clear that AI cyber capabilities have improved and that real attackers, including some tied to nation-states, are now using these tools in live operations. There are documented cases, including an AI-assisted tool that ran automated reconnaissance and credential harvesting against firewall devices, compromising hundreds of them across dozens of countries. Anthropic itself has mapped a year of AI-enabled threats. The capability is genuine and worth taking seriously.
Where the myth takes over
The exaggeration creeps in around the word unstoppable. A few things get lost in the panic.
The uplift is real but bounded. Most successful attacks still rely on old, boring methods: stolen passwords, unpatched systems, someone clicking a bad link. AI makes parts of the job faster, especially the writing of convincing phishing messages, but it has not invented a new physics of breaking in. The hard parts of a serious intrusion remain hard.
The evidence is also thinner than the headlines suggest. That same safety report notes that attributing an attack to AI is genuinely difficult. Threat intelligence rarely lets anyone say with confidence that a given breach happened because of AI rather than alongside it. A rise in attacks that coincides with the AI boom is not proof that AI caused the rise.
And the part most often forgotten: defenders got the same upgrade. The tools that help find a vulnerability also help patch it. Security teams now use AI to triage alerts, scan their own code, and spot intrusions faster than a human analyst could manage alone. This is an arms race, not a one-sided rout, and framing it as the latter mostly serves to frighten people who are already overwhelmed.
The sensible reading
Treat the hacker-superweapon story the way you would treat any claim that a single technology has tipped the balance forever. AI has lowered some barriers and sped up some attacks, and that deserves real defensive investment. It has not turned the average scammer into a state-grade adversary, and the evidence that it has is, on inspection, mostly vibes. The honest position is the uncomfortable middle: more capable attackers, more capable defenders, and a security landscape that looks busier rather than fundamentally lost. It is the same tension we examined when an AI agent everyone had installed turned out to have a security problem.
If you want a practical takeaway, it is the dull one that was always true. Patch your systems, use a password manager, turn on multi-factor authentication. The basics that stopped most attacks last year still stop most of them now, AI or not.
Sources
- i. arxiv.org
- ii. www.anthropic.com
- iii. www.securityweek.com
Commentarii · 0