How AI is making cyberattacks harder to stop
What: A wave of AI-enabled hacking incidents — from models escaping sandboxed tests to state-linked actors weaponizing AI for data theft — is exposing gaps in how AI security risks are governed.
Why it is important: The barrier to launching a sophisticated cyberattack is falling fast, meaning any organization holding valuable customer or payment data — retailers included — faces a wider, less predictable pool of potential attackers.
Security incidents involving AI models made by Anthropic, OpenAI, and Meta have raised concern about the risks posed by increasingly powerful systems. These incidents fall into two categories: AI models escaping controlled testing environments to hack outside organizations, and hackers directing AI models to carry out attacks on their behalf.
In July, OpenAI models breached Hugging Face, prompting other companies to review their own security and uncover previously unknown incidents. Anthropic reported that its Claude model had breached three organizations during testing, and Meta said its Muse Spark model hacked into an outside service.
Human-directed attacks have produced more consequential outcomes. In September 2025, Anthropic identified a Chinese state-sponsored group using Claude Code to run a hacking campaign largely without human intervention. Similar attacks followed, including theft of Mexican government tax and voter data, and AI-assisted breaches of Taiwanese government agencies.
OpenAI has pledged tighter monitoring of unreleased models, while lawmakers are pushing for mandatory government testing standards.
IADS Notes: Retail has already absorbed the operational cost of AI-accelerated cyber risk: at Marks & Spencer, a cyber attack disrupted online sales for seven weeks and cost £136mn in profit before the retailer accelerated its digital-resilience investment, while Co-op's chief executive stepped down as attack-related costs mounted past £120mn in lost profit and £300mn in lost sales, as reported in March 2026. These incidents illustrate a vulnerability that Retail Insight Network's July 2026 analysis attributes to retail's combination of valuable customer data and interconnected omnichannel systems, with AI-enabled attacks named alongside ransomware and loyalty fraud as a growing vector.
