Rogue AI will not trigger "Cyber Pearl Harbor," experts claim
Apocalyptic AI is marketing BS, adds WannaCry hero.

Pearl Harbor 1944. HUM Images/Universal Images Group via Getty Images
- Security researcher Marcus Hutchins noted that at Black Hat, "not one person" among top experts called agentic AI a major threat.
- Most incidents make news mainly due to marketing push, skewing perception. The fix is defense in depth, not "AI vs. AI."
- Finding flaws with AI remains "extremely prohibitive," and even cheap AI wouldn't remove the time and effort needed to exploit them successfully.
- Today's panic mirrors a past 'Cyber Pearl Harbor' scare that never came true, says ex-NCSC chief Ciaran Martin
Key Takeaways by nexos.ai, reviewed by Cybernews staff.
Vendors and marketing teams are hyping "agentic AI cyberattacks" to sell AI-powered security products and appear cutting-edge, says Marcus Hutchins, the researcher famous for stopping the 2017 WannaCry ransomware attack.
The threat itself, he argues, hasn't meaningfully materialized.
In a LinkedIn post, Hutchins said he had candid conversations with researchers from the biggest cybersecurity firms, Fortune 10 companies, ex-intelligence agency directors, and frontier AI labs at the Black Hat cybersecurity event.
"Not one person said they were a major thing," he revealed.
He added that some marketing departments were "forcing" security teams to hunt for anything "AI-shaped" to write about, rather than focusing on serious threats, simply because AI is the current trend.
Rogue agent reporting pressure
While a few researchers told him agentic AI cyberattacks were coming, Hutchins said they still agreed nothing seen so far had been "remotely successful or threatening."
Basically every single Agentic AI attack that's ever happened has likely made worldwide news, because there's so much marketing effort being poured into finding and writing about every single one of them."WannaCry hero, former hacker and cybersecurity researcher, Marcus Hutchins
Hutchins argues that this skews public perception through normalcy bias and added that the real threats – and the guidance to defend against them – remain unchanged.
"Even if agentic AI attacks were common, the solution is still just defense in depth. Not 'we need an AI to battle the threat actor's AI.' That is just not how security works."
Most hacks “down to negligence”
Hutchins counters that even recent AI agent stories driven by humans – such as the case of a guy’s OpenClaw AI agent that hacked into a gym website – are more due to negligent cybersecurity practices than to sophisticated AI.
“That was a database with zero authentication, and the dude wasn't trying to hack. An automated scanner would have found that issue in 10 seconds,” Hutchins claimed.
Hutchins has long argued that the cybersecurity community focuses too much on the new capabilities and not enough on attacker behavior and incentives.
Cost of AI for criminals “too high” to use at scale
“The cost of finding usable vulnerabilities with AI is still extremely prohibitive, and even if it wasn't, there's still a lot of time and effort that goes into successfully finding and exploiting vulnerabilities other than just AI, audit, and exploit this code,” Hutchins argued in another recent LinkedIn post.
Since Anthropic declared its frontier AI Mythos was too dangerous to be released publicly 4 months ago, stories around AI agents have picked up a lot of traction – from AI agents running amok in virtual towns to OpenAI breaking out of a sandbox to hack into Hugging Face.
The latter story was followed by a slew of other big tech LLM vendors, with reports on their own agents’ breakout exploits.
Apocalyptic narrative “wrong”
Former UK NCSC head Ciaran Martin also pointed out in a recent blog post that the Hugging Face breakout was not a rogue, autonomous AI agent, but an OpenAI agent doing what it was told to do and achieving it because the testing environment wasn’t safe enough.
Stay updated with our latest stories and follow us on social media
Be the first to discover new stories, ideas, and updates from our team.
Martin added that the latest hype wave around Agentic AI attacks echoed a period in 2012, when a cluster of cyberattacks prompted former US Defense Secretary Leon Panetta to warn of a “Cyber Pearl Harbor.”
A cyber Pearl Harbor never took place, and that was entirely predictable. The apocalyptic narrative is equally wrong now.Former UK NCSC head Ciaran Martin
However, the cybersecurity expert said in an article on his Substack last month that it might seem like a bigger crisis this time around because “a wider bubble of media and politicians are interested as well.”