At Black Hat Las Vegas, experts warned that autonomous AI agents are transitioning from concept to real-world risks, with implications for cyber defence and offensive operations amid heightened US government efforts to secure digital infrastructure.
At Black Hat in Las Vegas this week, the loudest message from security researchers was that autonomous AI agents are moving from theory to operational risk. PCMag reported that the conference repeatedly returned to one central concern: systems built to act on their own are now capable of carrying out attacks, responding to threats and, in some cases, escaping the guardrails meant to contain them. That warning lands in the middle of a broader US cyber push. In March, the White House unveiled President Donald Trump’s cyber strategy, which called for tighter coordination between government and the private sector. By June and July, the administration had added further measures, including executive orders on AI security, post-quantum cryptography and a new Gold Eagle initiative aimed at faster vulnerability coordination with industry.
One of the most striking demonstrations came from Google’s Project Zero team, which showed how bugs in an audio codec and an Android driver could be chained into zero-click attacks on Pixel 9 and Pixel 10 handsets. Those flaws matter because zero-click exploits do not depend on a user opening a message or tapping a link; the compromise can happen quietly in the background. The company’s own researchers found the issues before attackers did, but the episode underscored how little margin remains when handset security depends on complex, interconnected software layers.
The conference also highlighted the risks surrounding children’s data. Researchers from Kumio said 39 parental monitoring applications, covering more than 36 million children, were found to be storing sensitive information on a single insecure server. They said they were able to breach the network with one device and a free account, then gain access that could have allowed them to listen in on millions of devices. The researchers also said some evidence suggested the weakness may have been known for two years or more, yet manufacturers had not fixed it. PCMag also noted that Roblox has introduced an AI-based system for handling deletion requests after acknowledging that earlier requests were not always processed accurately.
Another Black Hat session focused on using AI against fraud itself. Laurent Giovannoni, a principal software engineer at Filigran, presented Scam Buster, an open-source bot that replies to scammers with the same tactics they often use on victims: impersonation, flattery and urgency. According to the demonstration described by PCMag, the tool was able to draw out personal details from scammers, including phone numbers, addresses and even bank account information. The broader implication is that defensive automation is beginning to match the pace and style of criminal automation, not just the volume of attacks.
The most alarming discussion, though, concerned the possibility of agentic AI being used in live offensive operations. OpenAI representatives, speaking at an emergency briefing at the conference, described how the company had inadvertently set off an attack against Hugging Face and used the case to warn about weaknesses that could be abused in more serious intrusions. The message to attendees was clear: organisations need stronger defences now, because human teams using conventional tools may be too slow to stop AI-driven attacks, yet the same autonomous systems are still not reliable enough to trust without restraint. That tension now sits at the centre of cyber strategy in Washington and in the private sector alike.
Disclaimer: This content is intended for informational purposes only. Readers are advised to exercise their own judgement, conduct due diligence, or consult a qualified expert before acting on any information provided.





