On July 22, 2026, MIT Technology Review’s The Download newsletter highlighted two major stories: NASA’s new space telescope and OpenAI’s autonomous hacking system. Not a mere assisted penetration testing tool — an AI agent that can plan, execute, and adapt cyberattacks on its own.
OpenAI frames it as a defensive weapon: find vulnerabilities before criminals do. But the real question is: who controls it? And what happens when it falls into the wrong hands — or, worse, when it’s deployed by companies without rigorous oversight?
Why does this matter for European SMEs? Because over 90% of businesses in the EU have fewer than 10 employees, and cybersecurity is still treated as an optional cost. If an AI agent can now scan a WooCommerce store and find a plugin vulnerability in seconds, the threat is no longer theoretical. It’s direct. And it affects the clothing shop down the street running a theme three years out of date.
Sponsored Protocol
We, at Meteora Web, see this every day: servers with no backup, forms without CSRF protection, expired SSL certificates. Once automated AI hacking scales, many Italian SMEs won’t survive the first wave — not because of incompetence, but because the digital divide is cultural. A website is still seen as a showcase, not a critical asset that must be defended.
Our stance
Our stance is clear: AI as an amplifier can be a blessing or a curse. OpenAI must lock down its agent with robust guardrails, but Europe must act now. The EU AI Act is a good start, but it doesn’t impose concrete transparency and liability requirements on developers of offensive AI tools. European SMEs cannot afford to be guinea pigs. We need mandatory security audits for AI software, certification schemes, and tax incentives for infrastructure upgrades. Without that, the digital divide becomes a vulnerability chasm.
Sponsored Protocol
What to do? If you’re a developer or business owner in Europe, start with three immediate actions: 1) update plugins, themes, and CMS today — not tomorrow. 2) enable a web application firewall (WAF), even a free one on shared hosting. 3) run automated penetration tests at least once a quarter — if hackers are automating, so should you. We’ve been doing this for years on our clients’ projects. Not because we’re paranoid, but because a site taken down by an attack costs more than a security upgrade. Always.