Security Magazine logo
search
cart
facebook twitter linkedin youtube
  • Sign In
  • Create Account
  • Sign Out
  • My Account
Security Magazine logo
  • NEWS
    • Security Newswire
    • Technologies & Solutions
  • MANAGEMENT
    • Leadership Management
    • Enterprise Services
    • Security Education & Training
    • Logical Security
    • Security & Business Resilience
    • Profiles in Excellence
  • PHYSICAL
    • Access Management
    • Fire & Life Safety
    • Identity Management
    • Physical Security
    • Video Surveillance
    • Case Studies (Physical)
  • CYBER
    • Cybersecurity News
    • More
  • BLOG
  • COLUMNS
    • Career Intelligence
    • Cyber Tactics
    • Cybersecurity Education & Training
    • Leadership & Management
    • Security Talk
  • EXCLUSIVES
    • Annual Guarding Report
    • Most Influential People in Security
    • The Security Benchmark Report
    • Top Guard and Security Officer Companies
    • Top Cybersecurity Leaders
    • Women in Security
  • SECTORS
    • Arenas / Stadiums / Leagues / Entertainment
    • Banking/Finance/Insurance
    • Construction, Real Estate, Property Management
    • Education: K-12
    • Education: University
    • Government: Federal, State and Local
    • Hospitality & Casinos
    • Hospitals & Medical Centers
    • Infrastructure:Electric,Gas & Water
    • Ports: Sea, Land, & Air
    • Retail/Restaurants/Convenience
    • Transportation/Logistics/Supply Chain/Distribution/ Warehousing
  • EVENTS
    • Industry Events
    • Webinars
    • Solutions by Sector
    • Security 500 Conference
  • MEDIA
    • Interactive Spotlight
    • Photo Galleries
    • Podcasts
    • Polls
    • Videos
      • Cybersecurity & Geopolitical Discussion
      • Ask Me Anything (AMA) Series
  • MORE
    • Call for Entries
    • Classifieds & Job Listings
    • Newsletter
    • Sponsor Insights
    • Store
    • White Papers
  • EMAG
    • eMagazine
    • This Month's Content
    • Advertise
  • SIGN UP!
CybersecuritySecurity NewswireCybersecurity News

AI Without Guardrails Is Driving a New Era of Cybercrime

By Jordyn Alger, Managing Editor
Digital landscape
Conny Schneider via Unsplash
July 24, 2026

The risk of guardrail-free AI isn’t a future concern — it’s a current-day threat. Researchers from ThreatDown discovered the AI tools that fuel today’s cyber incidents are increasingly open, mainstream and challenging to monitor. 

The first major finding from the research is that AI without guardrails has become mainstream. Some may assume that malicious AI is exclusively on the Dark Web; however, the report identified 6,644 models published openly on Hugging Face with labels such as “uncensored,” “heretic,” and “unfiltered,” indicating the models would not refuse requests typically rejected by conventional AI models. In a 30-day period, those models were downloaded more than 22 million times. 

The second key finding is that cybercriminals aren’t exclusively creating their own AI models from scratch; instead, they’re renting models. Researchers discovered a network of malicious AI services that take legitimate frontier models with mainstream cloud infrastructure and package, resell, or wrap them for their purposes. 

Below, security leaders discuss this new era of cybercrime. 

Security Leaders Weigh In

Dr. Margaret Cunningham, Vice President of Security & AI Strategy at Darktrace:

Frontier models are becoming more powerful and more widely accessible, while the mechanisms meant to control them remain imperfect. Against this landscape, defenders should assume breach, assume unapproved access, and assume that any capability useful enough to matter will eventually be used by adversaries.

While it is important to pay attention to claims about capabilities of these new models, it is also worth recognizing that the full picture often takes time to emerge. Some capabilities may prove more impactful than initially expected, while others may not live up to early expectations. For security teams, the challenge is evaluating these developments in real time, often before there is broad consensus on what the practical implications are. That can be especially difficult in a fast-moving environment where benchmarks, capability assessments, and model comparisons are evolving alongside intense industry interest and competition.

The same logic applies to guardrails. Guardrails can reduce opportunistic misuse, but they are not a complete defense. People who are good at jailbreaks already use context flooding, metaphor, literary framing, and iterative workarounds to test these systems. 

While a lot of focus lands on the offensive impact, the defensive burden is most concerning. Advanced defense is still mostly human, and we have not automated this level of expertise at scale. Vulnerability management was already behind schedule before AI accelerated discovery. The hard work is not just finding a vulnerability, its figuring out whether it matters in a specific environment, whether it is a lab-only edge case, whether patching will break something else, and how to remediate without disrupting the business.

There is no universal “normal” to defend anymore. Every organization, device, user, and agent behaves differently, which means security teams need a way to understand what is normal in their specific environment and spot when something changes. As AI accelerates discovery and exploitation, behavioral detection, anomaly-based analytics, and autonomous containment become essential. Defenders need to prioritize based on context, contain threats quickly when prevention fails, and build defenses around the reality of their own environment rather than a generic model of risk.

Randolph Barr, Chief Information Security Officer at Cequence Security:

Approximately two-thirds of current AI-related incidents still originate from traditional weaknesses, however, the remaining third are uniquely “AI-native.” These include model and data poisoning, prompt injection, and autonomous agents that can chain together API calls and act with minimal human oversight. These emerging risks reflect the reality that AI systems are dynamic, self-learning, and interconnected in ways traditional applications never were. When paired with the rapid speed of development, the outcome is a growing attack surface that grows faster than most security programs can respond.

We are approaching a future where the use of AI agents will outpace the readiness of security measures. We have seen a number of advisories over the past year which help highlight the gaps and hopefully drive the industry toward more secure, transparent designs before these tools become deeply embedded in enterprise ecosystems.

Ram Varadarajan, CEO at Acalvio:

Today, we are witnessing a significant swing in the cyber threat landscape and it’s more severe and unparalleled to anything we’ve ever faced before. Multi-agent swarms are coordinating in real-time across reconnaissance, credential harvesting, and data exfiltration. We’re facing exponential coordination where hundreds of specialized AI agents will operate simultaneously across our entire attack surface. Reactive defenses can’t operate at machine speed, requiring a shift in the cybersecurity stack to preemptive, AI-driven strategies. AI fighting AI, paired with offensive deception technologies, is the emergent design to catch attackers off guard and cause them to make mistakes and disclose themselves. Organizations that adapt will recognize that defense is no longer about building higher walls. It’s about becoming an unpredictable, moving target.

To maintain competitive edge and protect valuation, companies have to pivot from reactive defense to  active, game-theoretic defense. This means deploying AI-driven cybersecurity, specifically AI agents that use strategic deception in real-time. The future calls for forcing attackers to fight on the defender’s terms, gambling adversary compute against AI-driven decoys, and shifting the economic burden of the attack onto the attacker.

Diana Kelley, Chief Information Security Officer at Noma Security:

Traditionally, security teams focused on the protection of systems and data. Today, we are helping to govern AI systems and agents that make recommendations and decisions, and in some cases take action on behalf of the business, while enabling the business to adopt AI quickly and safely. AI also means that we’re facing a more well-resourced adversary. It lowers the cost of scale and increases the quality of automated attack campaigns. Without a strong control plane for AI systems and agents, including clear guardrails on access and actions, along with identity, access control, data governance, and runtime monitoring, AI will amplify whatever weaknesses already exist.

Moving forward, AI will be embedded in all aspects of our businesses, and every security professional needs a working understanding of AI and agent risk. That includes how models are trained, where data exposure can happen, how outputs can be manipulated, agentic blast radius, and how AI integrates into business workflows. In the real world, those risks show up inside existing domains like productivity tools, data loss prevention, access control, application security, cloud security, and risk management. 

Shane Barney, Chief Information Security Officer at Keeper Security: 

Advanced AI models are now capable of scanning systems, networks and code to identify vulnerabilities at a speed and scale no human analyst can match, and that capability cuts both ways. In the hands of a defender it’s a force multiplier for threat detection and response, but in the hands of a threat actor it accelerates the path from reconnaissance to exploitation faster than most security teams can detect, let alone respond to.

These AI systems easily bypass traditional "friction-based" defenses by automating complex, multi-step attack chains at scale, creating a massive influx of software bugs that human maintainers cannot triage fast enough. This results in a dangerous operational bottleneck, leaving a wide window of exposure for adversaries to exploit known flaws before a fix can be deployed. Security teams must operate on a much shorter clock, assuming public vulnerabilities will be weaponized within hours rather than weeks. Defenders should immediately implement automated update paths for internet-facing systems, treat dependency security patches as immediate priorities rather than backlog items and maintain robust logging and Multi-Factor Authentication (MFA) to prevent lateral network movement if a breach occurs.

Enterprises that have been deferring foundational security work are running out of time. The attack surface hasn’t changed, however, the tools available to exploit it have gotten significantly more powerful. Unpatched vulnerabilities, excessive access permissions and gaps in privileged account oversight are exactly the conditions that AI-assisted attacks are built to find and weaponize.

KEYWORDS: artificial intelligence (AI) Artificial Intelligence (AI) Security risk intelligence threat intelligence threat landscape

Share This Story

Looking for a reprint of this article?
From high-res PDFs to custom plaques, order your copy today!

Jordynalger

Jordyn Alger is the managing editor for Security magazine. Alger writes for topics such as physical security and cyber security and publishes online news stories about leaders in the security industry. She is also responsible for multimedia content and social media posts. Alger graduated in 2021 with a BA in English – Specialization in Writing from the University of Michigan. Image courtesy of Alger

Recommended Content

JOIN TODAY
To unlock your recommendations.

Already have an account? Sign In

  • Cyber tech background

    Security’s Top Cybersecurity Leaders 2026

    Security magazine’s Top Cybersecurity Leaders 2026 award...
    Cybersecurity
  • Iintegration and use of emerging tools

    Future Proof Your Security Career with AI Skills

    AI’s evolution demands security leaders master...
    Career Intelligence
    By: Jerry J. Brennan and Joanne R. Pollock
  • The 2025 Security Benchmark Report

    The 2025 Security Benchmark Report

    The 2025 Security Benchmark Report surveys enterprise...
    The Security Benchmark Report
    By: Rachelle Blair-Frasier
Manage My Account
  • Security Newsletter
  • eMagazine Subscriptions
  • Manage My Preferences
  • Online Registration
  • Mobile App
  • Subscription Customer Service

More Videos

Popular Stories

Paparazzi

When Private Events Become Public Infrastructure: What Celebrity OSINT Teaches Security Leaders

Broken wet floor sign

Why Response Time Is Becoming the Missing Metric in Workplace Safety and Security

People watching fireworks

Security Guard Assaulted at Firework Show

Cargo ship sailing

You Can’t Secure a Ship Like a Laptop

Medical professional

Nearly 85% of Nurses Experienced Workplace Violence in the Last Year

Kaseware sponsored webinar
Schneider Electric sponsored webinar

Events

August 19, 2026

From Investigative Question to Defensible Answer: AI in Digital Forensics and Incident Response

LIVE: August 19, 2026 at 2 PM EDT We'll examine where AI can deliver meaningful value, where incomplete context or black-box reasoning can introduce risk, and what governance, validation, and evidence-traceability controls organizations should establish.

August 25, 2026

Critical Infrastructure Security Is National Security: Protecting Essential Operations in an Era of Escalating Risk

LIVE: August 25, 2026 at 2 PM EDT Learn why critical infrastructure security has become a national security imperative, and the strategies organizations can adopt to improve visibility, collaboration, and response across their security operations.

View All Submit An Event

Products

Security Culture: A How-to Guide for Improving Security Culture and Dealing with People Risk in Your Organisation

Security Culture: A How-to Guide for Improving Security Culture and Dealing with People Risk in Your Organisation

See More Products


Alertmedia sponsored webinar

Related Articles

  • Cybersecurity compliance

    AI, Compliance, and a New Era of Cybersecurity

    See More
  • Tariffs in block letters with China and USA behind

    Cyber as a Pressure Valve: Why Economic Conflict Is Fueling a New Era of Cyber Escalation

    See More
  • Man on laptop

    Healthcare Executives Face a New Era of Personal Risk

    See More

Related Products

See More Products
  • security culture.webp

    Security Culture: A How-to Guide for Improving Security Culture and Dealing with People Risk in Your Organisation

  • school security.jpg

    School Security: How to Build and Strengthen a School Safety Program

  • Physical Security and Safety: A Field Guide for the Practitioner

See More Products

Events

View AllSubmit An Event
  • August 25, 2026

    Critical Infrastructure Security Is National Security: Protecting Essential Operations in an Era of Escalating Risk

    LIVE: August 25, 2026 at 2 PM EDT Learn why critical infrastructure security has become a national security imperative, and the strategies organizations can adopt to improve visibility, collaboration, and response across their security operations.
View AllSubmit An Event
×

Sign-up to receive top management & result-driven techniques in the industry.

Join over 20,000+ industry leaders who receive our premium content.

SIGN UP TODAY!
  • RESOURCES
    • Advertise
    • Contact Us
    • Store
    • Want More
  • SIGN UP TODAY
    • Create Account
    • eMagazine
    • Newsletter
    • Customer Service
    • Manage Preferences
  • SERVICES
    • Marketing Services
    • Reprints
    • Market Research
    • List Rental
    • Survey/Respondent Access
  • STAY CONNECTED
    • LinkedIn
    • Facebook
    • YouTube
    • X (Twitter)
  • PRIVACY
    • PRIVACY POLICY
    • TERMS & CONDITIONS
    • DO NOT SELL MY PERSONAL INFORMATION
    • PRIVACY REQUEST
    • ACCESSIBILITY

Copyright ©2026. All Rights Reserved BNP Media, Inc. and BNP Media II, LLC.

Design, CMS, Hosting & Web Development :: ePublishing