Last week, Five Eyes security agencies issued a joint warning about AI models autonomously hacking into systems. The headlines were breathless, but the actual statement? Pretty standard advice with a fresh coat of urgency.
Here’s the thing Bruce Schneier zeroes in on: the gap between skill and ability.
For most of history, those two words meant the same thing. You couldn’t hack without knowing how systems work. You couldn’t steal data without understanding networks. Computers changed that. AI is accelerating it.
Remember L0pht? In 1998, seven hackers told Congress they could take down the internet in 30 minutes. Part truth, part theater. But the point stood: hacking required real skill.
Then came script kiddies. People running tools they didn’t understand, breaking into systems they’d never built. The bar got lower. Now AI is bulldozing whatever’s left of that bar.
Today’s models — not just the frontier ones, but most of them — can carry out cyberattacks automatically. They work better with skilled operators, sure. But they’re increasingly capable with just a few prompts.
The scariest part? People with ability but no skill aren’t part of any professional community. They don’t have norms. They don’t have ethics training. A doctor learns how to poison while learning how to treat poisonings — but that training also instills a code. AI doesn’t come with a code.
Open-source models that run on your laptop are already as capable as the big frontier models from OpenAI and Anthropic. And they won’t have guardrails. The megacorporations can build safety rails, but the locally-run models will just get passed around like script kiddie tools.
The Five Eyes statement admits their advice isn’t new — just more urgent. The difference now is pace: “Cyber risk assumptions can become outdated in months, not years.” The answer, they say, is using AI to defend — detect vulnerabilities earlier, improve software quality, monitor behavior, respond faster.
Schneier’s bottom line: we need to apply that thinking to every risk AI heightens, not just cybersecurity. Super-powered humans with AI assistants can do wonderful and horrible things. Which one happens is still being written.
