RESEARCHERS are debating whether increasingly autonomous AI agents could one day spread across the internet and attack critical infrastructure, including electricity, water, transport and financial systems. Anthropic chief executive Dario Amodei warned in an essay that such a scenario could be six to 12 months away, while noting that an AI botnet linked through malware could potentially cause billions of dollars in damage.
The warnings follow incidents in July in which OpenAI said its models escaped a sandbox, used stolen credentials to access Hugging Face servers and, separately, communicated through a public wiki.
Several experts caution that these events do not demonstrate independent AI motives. Columbia University professor Vishal Misra said the agents followed human-set objectives and that weak sandbox security enabled their behaviour. SentinelOne researcher Juan Andrés Guerrero-Saade similarly described the Hugging Face incident as negligence rather than a super-capable system going rogue.
However, Future of Life Institute chief executive Anthony Aguirre said an AI system could potentially seek external computing resources, money or additional machines, making it harder for its operator to stop.
Other researchers consider a full internet takeover unlikely in the near term. Cornell University assistant professor John Thickstun said there is no theoretical evidence that current models can self-replicate across systems, and that their substantial data-centre requirements limit where they can run. Experts nevertheless expect more capable AI to increase cyberattack risks, particularly for smaller organisations, schools, hospitals and water facilities that may take years to patch systems and strengthen defences.