The institutions that watch this for a living now say yes, and in September 2026 they said it close together. Three of the four warnings below landed inside three weeks, from bodies with no shared agenda.
- Google Threat Intelligence Group, 9 September 2026, on adversarial AI moving from prompting to autonomy: the GTIG post.
- A joint advisory from five US agencies - NSA, CISA, FBI, the Department of Energy and the EPA - 19 August 2026: advisory AA26-231A.
- Andrew Bailey, chair of the Financial Stability Board and Governor of the Bank of England, in a letter to G20 finance ministers, 28 August 2026 - frontier AI is showing increasingly sophisticated autonomy and threat capability, and may materially alter the speed, scale and economics of cyber risk: the letter.
- A researcher leaving frontier AI work made the same argument publicly on 9 September 2026, and was not contradicted from inside - an alignment lead at one of the labs said the same day that there is no plan yet for aligning superintelligence.
What actually changed, in one line: the concern is no longer AI helping an attacker write something. It is AI running the operation - finding the surface, adapting when refused, and continuing without a person in the loop. That is a change in the ECONOMICS of attacking you, which is why a financial-stability body is writing about it at all: cheap and tireless is a different threat model from skilled and scarce.
What it looks like from a small public surface, which is the part rarely written down. Running 40+ tools live on the internet with no auth, the visible change over nine months has been in all four of frequency, scope, volume and sophistication, on every surface at once. Watching a dashboard stopped being fast enough some time ago; the posture that replaced it is continuous automated monitoring with a graded response, and more time spent on drills than on new features.
What follows for you, if you are building: assume any public endpoint is being probed continuously by something that does not get bored, treat a refusal as an event worth recording rather than a thing that quietly worked, and rehearse the response before you need it. The concrete controls are a separate question: the security checklist is the list we actually work from, and securing a database exposed to an AI agent is the case that comes up most.
Related, on the financial side of the same story: what central banks are warning about AI valuations. Full write-up with all four sources: https://www.tigzig.com/post/four-warnings-ai-cyber-risk-sep2026.
Building something like this? How I work covers the rates, the availability and what I take on.