Cases of AI escaping the lab, infiltrating other companies and trying to deceive people have all made headlines in recent weeks. And in one case, AI models even worked together to break free from their test environments. Does this mean the machines are taking over? Not quite. AI isn’t the mastermind behind today’s most widespread cyber threats; it’s people who can use AI nefariously – and for nefarious purposes. AI has given bad actors massive power, allowing them to create malicious software, research targets, create convincing schemes and automate attacks at an unprecedented pace. One in four data breaches were driven by AI from February 2025 to March 2026, according to an IBM report. And Americans lost more than $893 million to AI-related scams last year, the FBI says. But experts say real-world threat actors – that is, people – are still the ones pulling the strings. AI agents have only perpetuated existing attack methods, like phishing and malware scams, rather than creating wholly new ones. “It’s the humans that we need to watch out for,” said Oren Etzioni, professor emeritus at the University of Washington and former CEO of the Allen Institute for Artificial Intelligence. “AI is just the tool.” AI going rogue Some recent incidents have shown what AI is capable of in the real world, not just in theory, igniting fears about whether the technology is advancing too quickly. - In July, OpenAI test models escaped their constraints and hacked into other companies’ systems during an internal evaluation. - Days later, Anthropic said it discovered its AI models had breached three companies during testing. - In a separate test, Anthropic’s most advanced model used fake identities to try to deceive real people, researchers at Britain’s AI Security Institute said Tuesday. - One of Meta’s AI models also