Mythos raised the warning. The Hugging Face incident shows why Europe must prepare for AI systems that can defend our networks — and attack them.
Artificial intelligence is changing cybersecurity faster than our traditional security models can adapt. The same systems that can help us find vulnerabilities, protect networks and anticipate attacks are increasingly capable of doing the opposite: exploiting weaknesses, automating cyber operations and acting with a degree of autonomy that only recently seemed theoretical.
In just a few months, we have seen two powerful warnings. Mythos, the AI developed by Anthropic, showed that an AI designed to strengthen cyber defences also possess significant offensive capabilities. Then, in July, autonomous agents developed by OpenAI broke out of their controlled testing environment and hacked into Hugging Face, an open-source platform. These cases are different, but they point in the same direction: the line between defensive and offensive AI is becoming increasingly blurred, if it ever existed.
Mythos is a good example of why this matters. It was presented as a tool to identify and patch software vulnerabilities before malicious actors could exploit them. In other words, it is a revolutionary tool in the field of cybersecurity and Europe urgently needs this capacity to anticipate cyber threats and strengthen the resilience of our societies.
But the same capability that allows an AI system to find a vulnerability and help mitigate it can also become a risk when it is used to exploit that weakness. Once an advanced model can autonomously identify a previously unknown flaw in a software, the question is no longer only whether it can help defenders. The question is what happens when that capability falls into the wrong hands or behaves in ways its developers did not anticipate.
The Hugging Face incident makes that concern far more tangible. During a cybersecurity evaluation, OpenAI’s agents found a way out of their ‘sandbox’ to access to internet and autonomously targeted external systems while pursuing their assigned task. OpenAI later acknowledged that the incident extended beyond Hugging Face to other publicly available services. The significance is clear: advanced agents can persist, adapt and act at machine speed without a human directing each step.
Imagine what that could mean for a hospital whose emergency services and medical records depend on widely used software. A previously unknown vulnerability could become a serious disruption before human teams have even had time to understand and patch it. What happens in cyberspace can quickly have real and serious consequences in the physical world.
This is why AI with advanced cyber capabilities cannot be treated like an ordinary technological product. Its impact can reach public administrations, energy and transport networks, hospitals, critical infrastructure and military systems. In this field, technological capacity is increasingly becoming security capacity.
The European Union has already taken an important step with the AI Act. However, Article 2(3) excludes AI systems used exclusively for military, defence or national security purposes from its scope. That distinction becomes harder to manage when privately developed models can move between civilian cybersecurity research, dual-use applications and potentially offensive operations.
That is the issue I have raised in the European Parliament. As a Member of the Security and Defence (SEDE) Committee, and as someone working on security, defence and emerging technologies, I believe Europe cannot simply react after technology has overtaken our capacity to respond.
In May, following the emergence of Mythos’ incident, I asked the European Commission about how the AI Act applies to privately developed AI systems with advanced cyber capabilities and whether Europe has sufficient capacity to conduct AI-assisted vulnerability research at scale. The Commission has since clarified that dual-use systems such as Mythos Preview fall within the AI Act when they are not placed on the market exclusively for military, defence or national-security purposes. That clarification is important, but it does not remove the broader security challenge: increasingly powerful systems can move across civilian, defensive and potentially offensive applications with unprecedented speed.
There is also a wider security dimension. Artificial intelligence is increasingly being integrated into military planning and decision-making. Companies such as Palantir openly present AI as a capability for defence and strategic operations. This is different from an autonomous agent escaping a testing environment, but both developments point towards the same reality: advanced AI is becoming an element of strategic power.
Europe therefore needs both rules and capabilities. The Commission’s new Action Plan on Cybersecurity and AI is an important step: it proposes stronger AI-assisted vulnerability management, a European challenge on vulnerability detection and further investment in home-grown cybersecurity technologies. But ambition now must translate into capacity at scale. Europe must equip ENISA and its Member States with the tools to match increasingly autonomous threats, develop its own advanced AI and cyber-defence capabilities and reduce its dependence on non-European actors for technologies becoming fundamental to our security.
Artificial intelligence will be a decisive security capability of the 21st century. Mythos gave us an early warning. The Hugging Face incident has shown how quickly theoretical capabilities can acquire real-world consequences. Europe must be ready before the next threshold is crossed.