For decades, cybersecurity has been a contest between people.
A hacker finds a weakness. A security team closes it. The attacker changes tactics. The defenders respond.
Artificial intelligence could change that equation in an important way.
What happens when the attacker no longer needs a human to decide what to try next?
And what happens when the software doing the attacking can learn from failure, change its approach, and immediately try again?
That still sounds futuristic. But recent developments suggest that parts of that future are moving much closer.
AI Is Already Changing the Cybersecurity Equation
In September 2026, OpenAI said GPT-6 Astra had reached the company's Critical cybersecurity capability threshold.
According to OpenAI, with the right tools and access, Astra can identify previously unknown security flaws and develop ways to exploit them across hardened systems without requiring a person to direct each individual step.
Anthropic has reported its own warning signs. During cybersecurity evaluations, Claude models reached the public internet from improperly configured testing environments and gained unauthorized access to real systems.
The circumstances matter. These were evaluation environments, not ordinary customer deployments, and Anthropic has described important operational and containment failures around the incidents.
But the larger point is difficult to ignore: frontier AI systems are becoming increasingly capable of finding weaknesses, carrying out sequences of technical actions, and adapting when a straightforward approach does not work.
Read the primary sources
OpenAI:
Path to Astra: Critical Capabilities and Frontier Safeguards
Anthropic:
Investigating Real-World Incidents in Cybersecurity Evaluations
Now Add Software That Can Improve Itself
Another development makes the cybersecurity question even more interesting.
Researchers at Sakana AI and the University of British Columbia created the Darwin Gödel Machine, a research system designed to improve its own performance by modifying its software.
The system can inspect its own codebase, propose changes, evaluate whether those changes improve its performance, and preserve successful modifications.
That does not make the Darwin Gödel Machine an autonomous cyber weapon. It is a controlled research project focused on improving coding agents.
But place that capability beside increasingly capable cybersecurity models and a much more uncomfortable question appears.
What happens when an AI system can both attack a problem and change how it approaches the problem when its first attempt fails?
Imagine an AI attempting to penetrate a corporate network.
It tries one method. The security system blocks it.
Traditional automated software might stop because it was programmed to follow a predefined sequence.
An adaptive AI could potentially treat that failure as new information.
Why was I blocked?
What did the security system detect?
Is there another route?
Can I change the code I am using?
Can I alter my behavior enough to avoid the defense?
Then it tries again.
And again.
Research reference
Sakana AI: The Darwin Gödel Machine: AI That Improves Itself by Rewriting Its Own Code
Persistence May Matter More Than Intelligence
The unsettling part is not necessarily that AI becomes all-knowing.
It is that AI may become extraordinarily persistent and adaptable.
Human attackers already adapt. Skilled hackers study defenses, change tactics, test alternatives, and learn from failure.
But humans have limits.
They get tired. They have limited time. They can investigate only so many systems simultaneously. Every failed attempt has a cost.
Software operates under very different economics.
An autonomous system could potentially examine large numbers of targets, write and test code, study failures, and change strategies at machine speed.
OpenAI has specifically warned that increasingly capable AI models could enable cyberattacks at unprecedented speed and scale.
That could also change who becomes a worthwhile target.
A smaller company may sometimes avoid a highly sophisticated attack simply because an expert attacker has more valuable targets to pursue.
But what happens when the cost of investigating each target collapses?
The attacker may no longer need to choose between ten companies. An automated system could potentially investigate thousands.
Then the Defenders Start Adapting Too
There is another side to this story.
AI is not only becoming useful to attackers. It may become one of the strongest tools available to defenders.
The same technology capable of searching for vulnerabilities can help organizations discover those weaknesses before criminals do.
AI systems can analyze large amounts of security data, identify unusual behavior, investigate incidents, and potentially respond much faster than a human team working alone.
So the future of cybersecurity may not simply involve humans defending networks against AI.
It may increasingly become AI defending systems from other AI.
An attacking system discovers a technique.
The defensive system detects it.
The attacker changes its behavior.
The defender responds.
The attacker adapts again.
Cybersecurity has always been an arms race.
AI could dramatically accelerate it.
This Changes How We Should Think About Software
I have spent more than two decades developing software, and one assumption has remained remarkably consistent.
Software does what we build it to do.
When it needs to change, we change it.
AI is beginning to challenge that assumption.
Researchers are building systems capable of modifying their own software. Frontier models are becoming more capable at vulnerability discovery and exploitation. AI agents are also becoming better at operating computers and carrying out longer sequences of actions with less human direction.
That does not mean an unstoppable, self-modifying AI hacker is roaming the internet.
It is important not to exaggerate where the technology is today.
But it is equally important not to ignore the direction in which these capabilities appear to be moving.
What This Means for Business Leaders
For business leaders, the AI conversation can no longer focus only on productivity, automation, and cost savings.
Security needs to be part of the same discussion.
Organizations do not need to assume autonomous AI attacks are already everywhere. That would overstate the current reality.
But businesses should begin treating adaptability, persistence, and machine speed as part of the future threat model.
Security strategies built primarily around known patterns may become less effective as both attackers and defenders gain systems that can learn, experiment, and respond more quickly.
The question is no longer simply whether AI will improve productivity.
Businesses also need to ask whether their systems, processes, vendors, and security practices are prepared for a world in which attackers can change tactics faster than traditional defenses were designed to respond.
The Question We Need to Start Asking
The most consequential thing about self-improving AI may not be that it eventually becomes smarter than us.
It may be something much simpler.
Every time we tell it, “That didn't work,” it may be increasingly capable of figuring out what to try next.
Are our security systems prepared for attackers that can adapt faster than the defenses designed to stop them?
Further Reading
More From PXM Software Solutions
Explore more practical thinking on artificial intelligence, software, and business technology.