When the Attacker Is an Agent

Cyber Governance in the AI Era | Edition 6 | August 2026

The attack moved to machine speed. Has your governance?

In brief

Released in mid-July, Check Point Research's AI Security Report 2026 highlighted a Gambit Security investigation into a campaign in which one operator used Claude Code and GPT-4.1 while breaching nine Mexican government organisations. Gambit's forensics recovered 1,088 logged prompts and 5,317 AI-executed commands across 34 sessions on live victim infrastructure, with the human supplying intermittent direction.

Days later, Hugging Face disclosed a different and more autonomous intrusion: an agent system that executed thousands of actions across short-lived sandboxes and generated more than 17,000 recorded events over a weekend. July did not create the agentic attacker. It made the progression impossible to ignore.

The position of this edition is one sentence, and it is testable. Within eighteen months, one of the first questions regulators, insurers, and courts ask after a serious AI-accelerated breach will be whether the institution's detection and containment operated at a speed proportionate to the threat.

Board takeaway: before your next meeting cycle closes, ask management for three answers. What are the median and 90th-percentile times from identification of a known-exploited vulnerability on an internet-facing system to containment or removal of exposure? What is the median time from a high-severity out-of-hours alert to containment? And who is authorised to isolate a production system at 2 a.m. without convening a committee?

Three levels of autonomy, not one

For boards, a practical distinction is needed, because the incidents now being reported together are not the same threat.

An AI-assisted attack is a human operation that uses AI for particular tasks. An agent-operated attack is one in which the AI executes multi-step workflows and adapts between intermittent human instructions. An autonomous attack is one the system continues, adapts, and completes end to end with little or no human intervention after it begins. A board that cannot tell them apart will either panic at the wrong one or dismiss the real one.

Place the evidence on that ladder honestly. The Mexican campaign, which ran from late December 2025 to mid-February 2026, is agent-operated: the operator sent 1,088 prompts and directed the follow-on sessions, so this was not a human-free intrusion, but roughly 75 percent of remote command execution was generated and executed by Claude Code, alongside twenty tailored exploits and more than four hundred custom attack scripts. Hugging Face describes its own incident as end-to-end autonomous, with self-migrating command-and-control staged across public services. Sysdig, reporting a ransomware operation it tracks as JADEPUFFER, assessed it as the first documented case of agentic ransomware, driven end to end by the model's own decision-making rather than a human at the keyboard.

What the three share is not the disappearance of the human. It is the compression of specialist work. Agentic systems can sustain reconnaissance, exploitation, adaptation, lateral movement, and exfiltration with far less human intervention between steps. That is the shift a board needs to absorb.

The calendar problem

What changed is not capability in the abstract. It is cost and tempo. Check Point reports that AI can now turn a fresh vulnerability disclosure into a working exploit within hours. India's CERT-In, responding to AI-compressed exploitation timelines, advises immediate containment of known-exploited vulnerabilities affecting internet-facing and crown-jewel systems, followed by patching, mitigation, or removal of exposure within twelve hours where feasible. Set that against the standard governance rhythm, quarterly board meetings and annual penetration tests, and the mismatch is the risk.

An adversary that works at machine speed does not defeat your controls. It defeats your calendar.

If exploits arrive in hours, a thirty-day patch cycle can leave a critical system exposed for most of the month. The exposure compounds from inside. Check Point reports that high-risk prompts doubled over the year, from roughly one in every 50 enterprise AI interactions to one in every 25, and that between 87 and 93 percent of organisations experience at least one high-risk AI interaction in a month. Automation outside the walls is meeting unmanaged adoption inside them.

There is an irony that returns this series to its first edition. Edition 1 argued that delegating authority to AI without design is exposure. July established the converse: where the adversary has automated, refusing to delegate is also exposure. The board's task is not to keep a human in every loop. It is to decide, in advance and in writing, which loops need judgment and which need speed, and to accept that where speed is delegated, the response must be bounded, pre-authorised, logged, and reversible.

One regulatory date belongs here. On 2 August, the European Commission's AI Office began enforcing the obligations that apply to providers of general-purpose AI models, with Article 101 fines reaching 15 million euros or 3 percent of worldwide annual turnover, whichever is higher. The threat clock and the compliance clock now run together.

The small-state dimension

A machine-speed adversary challenges even an institution with layered redundancy and a security operation two hundred strong. For a ministry running a national platform with a security team of four, the asymmetry is sharper still. In a small island developing state, one platform can serve the whole population. Hugging Face's disclosure shows how far an autonomous framework can move over a weekend: from a compromised processing worker to node-level access, harvested credentials, and lateral movement across internal clusters.

Edition 3 asked whether your trust architecture could hold against a curious teenager. The teenager now has agents. For small states and mid-sized institutions alike, the rational response is not heroic staffing, which is unaffordable, but standing defence: always-on detection, pre-authorised containment, and governance built into the architecture from first deployment. Institutions that cannot outspend the adversary can still out-decide it, because authority settled ahead of the incident costs nothing at 2 a.m.

A machine-speed governance model

Five decisions belong to the board, and none requires technical immersion.

  1. Put the containment clock on the board pack. Time to contain a known-exploited vulnerability on an internet-facing system is now a governance metric, not an operational one. Report the number the way you report cash.
  2. Settle containment authority before you need it. Name the roles authorised to isolate systems, revoke credentials, and sever integrations without convening anyone, and write down which actions they may take alone. This is Edition 1's "never automated" list run in reverse: decide what must never wait for a meeting.
  3. Require detection that does not sleep, and a response that can act on it. Continuous monitoring is the baseline; what matters is whether a credible alert produces containment out of hours. Hugging Face's intrusion was initially surfaced by AI-assisted anomaly detection, then investigated by people. Ask management what your equivalent is, and what happens at the weekend.
  4. Recalibrate the threat model for commodity adversaries. The assumption that attacker sophistication tracks attacker resources is now weaker. One operator with commercial AI tools reached nine government organisations. Exercise that scenario, not only the nation-state one.
  5. Drill at attack tempo. Run an exercise measured in minutes, starting at 2 a.m. on a Sunday rather than 10 a.m. on a Tuesday. The drill is not for the technicians. It is for discovering which decisions still assume there is time to make them.

The two containment problems

A closing distinction, because it is where boards conflate two different controls. Governing your own agents and defending against someone else's overlap in discipline but differ in mechanism. Your agents need purpose limits, revocable authority, and a kill switch, controls over systems you own. An adversary's agent, operating through compromised infrastructure, answers to none of those. It requires identity revocation, endpoint isolation, network containment, and response authority that can move at comparable speed. Edition 4 reported that 60 percent of surveyed institutions cannot stop even their own misbehaving agent. An institution that has invested only in the first has governed half the problem.

Signal of the month

Check Point's detections of long, malicious prompt-injection payloads rose roughly fivefold between March and May 2026. Read that alongside everything above: the agents your organisation deploys are becoming part of the surface the adversary's agents target. The two halves of this newsletter's argument, the agents you govern and the agents that attack, meet at the prompt boundary. Governing one without defending against the other is half a policy.

What boards and executives should ask in August 2026

  1. What is our median time to contain a known-exploited vulnerability on an internet-facing system, and who sees that number at board level?
  2. Who is authorised, by name and in writing, to take containment action at 2 a.m. without a committee, and which actions are pre-approved?
  3. When a high-severity alert fires outside business hours, how long until containment begins, and is that answer measured or assumed?
  4. Has our threat model been recalibrated for a single operator with commercial AI tools, or does it still assume capability requires resources?
  5. If an attack began during our next board meeting, would we learn of it before the meeting ended?

The mandate

Edition 4 asked who answers when the agent acts. Edition 5 asked whether you would control the timetable when the law started asking. Both questions quietly assumed the defining risks moved at the speed of your own systems. July's disclosures removed the assumption. Governance at human speed is now a choice, and it is a choice to be slower than the adversary. The institutions that come through the agentic era will not be the ones that kept a human in every loop. They will be the ones that decided, ahead of the incident, which loops need judgment and which need speed.

Executive question of the month

If an attack began this Saturday at 2 a.m. and ran at machine speed, at what time, honestly, would your organisation first act, and who would have had the authority to act sooner?

Sources

Gambit Security, Eyal Sela, "A Single Operator, Two AI Platforms, Nine Government Agencies: The Full Technical Report", 10 April 2026: campaign from late December 2025 to mid-February 2026; nine Mexican government organisations; 1,088 logged prompts; 5,317 AI-executed commands across 34 sessions on live victim infrastructure; approximately 75 percent of remote command execution generated and executed by Claude Code.

Check Point Research, AI Security Report 2026, released mid-July 2026: AI converts fresh vulnerability disclosures into working exploits within hours; detections of long, malicious prompt-injection payloads up roughly fivefold March to May 2026; high-risk prompts up from roughly one in 50 to one in 25 interactions; between 87 and 93 percent of organisations experience at least one high-risk AI interaction in a month.

Hugging Face, security incident disclosure, 16 July 2026: end-to-end autonomous agent intrusion; more than 17,000 recorded events; self-migrating command-and-control staged on public services; initially surfaced by AI-assisted anomaly detection.

Sysdig, "JADEPUFFER: Agentic ransomware for automated database extortion", 1 July 2026: assessed as the first documented case of agentic ransomware; exploited Langflow CVE-2025-3248.

CERT-In, "Blueprint for Reducing Exposure and Defending against AI-Assisted Vulnerabilities Exploitation in Digital Infrastructure", CISG-2026-02, 25 May 2026. Advisory rather than mandatory.

EU AI Act, Article 101: enforcement of general-purpose AI model provider obligations from 2 August 2026.

Kiteworks, 2026 Data Security and Compliance Risk Forecast (as cited in Edition 4): 60 percent of surveyed organisations cannot terminate a misbehaving agent.

Dr. Inshan Meahjohn is Founder and CEO of DAG (Digital Alliance Global Group), a global cybersecurity and digital transformation platform operating across global markets under the operating posture Protect and Transform. He holds a PhD in Entrepreneurship from the University of Trinidad and Tobago and previously served as CEO of iGovTT, Trinidad and Tobago's national ICT agency. Subscribe to Cyber Governance in the AI Era for monthly, board-level analysis on AI governance, cyber risk, and operational resilience.

Next
Next

Signing a Memorandum of Understanding with the Caribbean Telecommunications Union