OpenAI has developed an AI agent capable of conducting cyberattacks autonomously. A July 2026 MIT Technology Review report revealed the AI successfully passed penetration tests on real-world systems without human intervention, adapting its strategies in real time. This is not a lab teaser. It is a product ready for distribution — and sooner or later, it will be.
For European and Italian SMEs, this news carries enormous weight. In Italy, according to Clusit 2026 data, over 60% of cyber breaches hit companies with fewer than 50 employees. The average cost of a ransomware attack for an SME now exceeds €150,000, factoring in downtime and ransom. Now imagine an attacker AI that works 24/7, learns from failures, and never takes holidays. The gap between a protected SME and a vulnerable one is no longer luck: it is technical readiness.
Sponsored Protocol
We at Meteora Web see this every single day.
Missing backups. WordPress plugins years out of date. Passwords shared on Slack. The excuse is always the same: “We’re too small to be targeted.” With an autonomous hacker on the loose, there are no safe sizes anymore. The EU AI Act has set risk classification limits, but it was designed for static applications, not for agents that mutate in real time. While Brussels drafts amendments, the US invests in defensive cyber‑AI and China releases offensive models as black‑box tools. Europe risks repeating its cloud playbook: regulating while everyone else runs.
Here is what needs to happen. For developers: stop treating security as an afterthought. In our own projects we embed vulnerability scans, two‑factor authentication, and offsite backups from day one. It costs time, but it costs less than a breach. For business owners: demand periodic audits. A human penetration test is expensive; an AI agent will do it for pennies. The problem is if a malicious actor uses it before you do. For policymakers: mandate transparency on offensive capabilities of AI agents, create incentives for cyber‑hygiene in SMEs, and fund a European digital defense network. Enough with grants that pay for connectivity but not protection.
Sponsored Protocol
The autonomous hacker is out of the bottle. We can only decide whether to build our digital immune system now — or wait for the first incident to do it for us.