OpenAI has developed an AI agent capable of conducting cyberattacks autonomously. MIT Technology Review revealed this on July 22, 2026, citing internal tests. This is no mere assistant: it selects targets, bypasses defenses, and learns from mistakes — without direct human oversight.
The timing is critical for Europe. The EU AI Act is in force, but its risk categories — unacceptable, high, limited — do not explicitly mention autonomous offensive capabilities. A regulatory gap that could prove costly, especially for Italian SMEs, which already struggle with cybersecurity.
Our position is clear: security cannot be an afterthought
We, at Meteora Web, have been following businesses since 2017: from domain to revenue, through servers and backups. We see it every day: unprotected forms, cleartext credentials, expired SSL certificates. Security in Italian SMEs is systematically undervalued. Now imagine an autonomous AI scanning for these weak spots. You don't need a state actor — anyone can rent the API.
Sponsored Protocol
And the risk isn't just technical. It's economic. A successful attack costs an average of €200,000 for a small business — between downtime, data recovery, and GDPR fines. For many, it would mean closure. Europe must act now: classify autonomous hacking as unacceptable risk, require AI companies to implement technical guardrails (action limits, mandatory auditing), and penalize those who distribute offensive tools without controls.
At the same time, we cannot afford to stifle innovation. Defensive AI is a huge opportunity for SMEs: automated scanners, predictive patching, threat intelligence. Brussels should fund adoption programs for businesses in Southern Italy — bridging the digital divide that is also geographical, as we often say. We work with the territory: the South deserves top-tier technology, including security.
Sponsored Protocol
To our readers — developers, entrepreneurs, decision-makers — the message is simple: do not wait. Audit your infrastructure today. If you don't know where to start, start with Search Console, server logs, backups. And above all, demand transparency from your AI providers on how they protect their models. The next breach might not be exploited by a human.