Artificial intelligence was sold as the next great productivity revolution. It would help us write documents, analyse data, discover medicines, educate children, and automate tedious work. Those promises remain real. Yet, like every powerful technology before it, AI has another side. The same systems that help ordinary people solve everyday problems can also help criminals automate cyberattacks, generate convincing scams, write malicious software, and scale their operations in ways previously impossible.

Recent research by Cato Networks illustrates just how quickly this transformation is occurring. According to their investigation, a Russian-speaking threat actor known as "Trim" did not steal advanced AI models or hack into the companies that built them. Instead, he systematically learned how to bypass the safety guardrails built into publicly available frontier AI systems and repackaged them into a commercially marketed offensive cyber platform. Rather than building an AI from scratch, he simply weaponised one that already existed.

This represents an important shift in cybercrime. For years, sophisticated cyberattacks required highly skilled programmers who spent years mastering malware development, exploit writing, and penetration testing. Frontier AI dramatically lowers that barrier. A moderately capable criminal can now use an AI assistant to accelerate coding, analyse vulnerabilities, automate reconnaissance, generate phishing campaigns, and rapidly adapt malware. The AI becomes a force multiplier rather than a replacement for the human attacker.

The lesson extends well beyond one hacker.

Every major AI platform is built upon the assumption that safety guardrails can prevent misuse. These guardrails refuse certain requests, block obviously malicious prompts, and attempt to distinguish legitimate security research from criminal activity. Unfortunately, guardrails are not absolute barriers. They are behavioural constraints applied to statistical models. Determined adversaries continually experiment with prompt engineering, indirect instructions, role-playing scenarios, chained requests, and modified system prompts until they discover combinations that circumvent the intended restrictions. Once one criminal discovers an effective technique, underground forums rapidly distribute it to thousands of others.

This follows a familiar historical pattern. Every transformative technology has eventually been militarised or criminalised. Radio became propaganda. Aircraft became bombers. The internet became a platform for organised cybercrime. Artificial intelligence is unlikely to prove an exception.

The danger is not merely that AI makes existing attacks faster. It changes their economics. Cybercrime has traditionally required significant human labour. Phishing emails had to be written manually. Malware needed continual modification. Victims required individual attention. AI allows many of these processes to be automated while simultaneously making them more convincing. Grammar mistakes disappear. Personalisation improves. Fake customer support agents become increasingly believable. Deepfake audio and video add another layer of deception.

Meanwhile, defenders face an asymmetric problem. Attackers need only discover one successful technique. Defenders must secure everything. AI therefore tends to increase the speed of both attack and defence, but the initial advantage often lies with the attacker because automation reduces the cost of experimentation. Researchers increasingly warn that, in the short term at least, frontier AI may disproportionately benefit offensive operations unless defensive systems evolve equally rapidly.

So what can be done? Here is what has been suggested on the internet, and I summarise.The first requirement is accepting that AI itself has become part of the attack surface. Organisations cannot simply install antivirus software and assume the problem has been solved. Security architectures must now monitor AI interactions, detect prompt manipulation, identify unusual agent behaviour, and continuously test whether AI systems can themselves become pathways into broader networks. AI security must become an integral part of cybersecurity rather than an optional add-on.

Secondly, AI developers must recognise that safety cannot rely solely upon prompt filtering. Multiple layers of defence are required. Better model isolation, stronger authentication, behavioural monitoring, anomaly detection, independent auditing, continuous red-teaming, and rapid response capabilities all become essential. No single safeguard will be sufficient because determined attackers constantly adapt.

Thirdly, governments and industry should improve information sharing without unnecessarily stifling innovation. Cybercriminal techniques spread remarkably quickly across underground communities. Defensive intelligence must spread at least as rapidly among legitimate organisations. Collaboration between AI developers, cybersecurity researchers, businesses, and law enforcement will become increasingly important.

Finally, individuals must develop a healthy scepticism toward digital communications. As AI-generated phishing emails, cloned voices, synthetic videos, and fraudulent websites become increasingly convincing, the old assumption that obvious errors reveal a scam will no longer hold. Verification through independent channels, strong authentication, password managers, multi-factor authentication, and regular software updates become even more important.

Artificial intelligence itself is not the enemy. Like electricity, nuclear energy, or the internet, it is a powerful general-purpose technology that can serve both constructive and destructive purposes. The real challenge lies in recognising that every technological revolution creates opportunities for both civilisation and crime.

The weaponisation of mainstream AI should therefore surprise no one. Human beings have always adapted new tools for conflict and exploitation as quickly as they adapted them for progress. The real question is not whether criminals will continue to weaponise frontier AI. They undoubtedly will. The question is whether governments, companies, and ordinary citizens can develop equally sophisticated defences before the balance tips too far in favour of the attackers.

https://www.catonetworks.com/blog/cato-ctrl-how-one-threat-actor-turned-frontier-ai-into-an-offensive-platform/

https://www.foreignaffairs.com/china/when-china-gets-its-own-mythos