Booz Allen says AI can now execute cyberattacks without human input
Booz Allen Hamilton (NYSE: BAH) released a report stating that a leading AI model can autonomously execute a complete network intrusion — from gaining initial access to taking full control — without human guidance, according to a company press release.
The finding is drawn from the firm's Cyber Weapon Index (CWI), which tested 18 advanced U.S. and Chinese AI models to assess how their capabilities are reshaping the offensive cyber threat landscape. The report, titled "The Offensive Frontier: AI as the Attacker," describes the development as a shift from AI-assisted hacking to fully autonomous cyber operations.
Among the report's findings, Booz Allen states that advanced cyberattack capabilities once limited to nation-states are becoming accessible to criminal and non-state actors, and that critical infrastructure faces exposure to AI-enabled attacks. The report also states that when AI models are paired with attack tools, memory, and autonomy frameworks, even less advanced models can cause significant harm.
The report also states that autonomous AI attackers create exploitable vulnerabilities for defenders. In Booz Allen's internal testing, coordinated Counter AI playbooks reduced autonomous attacker success by more than 95%.
Alongside the report, Booz Allen introduced Vellox Labs™ Guile, a product it describes as a Counter AI tool designed to disrupt autonomous attacks by manipulating what AI attackers perceive and trust. The company states the product adapts over time using frontier AI models to evolve its defenses.
