On September 2, 2026, a human threat actor did something that would have previously required a small army of specialists working for weeks. Using frontier AI models and specialized agentic frameworks, they autonomously breached an enterprise network in under 10 hours. By the time Unit 42 researchers Renzon Cruz, Nicolas Bareil, Eric Semaan, and Omar Jbari documented the incident on September 3, it was clear the rules of engagement had shifted. The attacker didn’t just stumble through the front door; they executed more than 50 MITRE ATT&CK techniques, a level of precision and speed that effectively turns the traditional red team timeline on its head. Andy Piazza, Senior Director of Threat Intelligence at Unit 42, didn’t mince words, calling it “one of the first few documented agentic breaches where an attacker successfully leveraged an agentic attack against an enterprise.” What makes this different from the usual automated scripts we’ve seen for years is the autonomy. These agents aren’t just following a pre-written script; they are making decisions in real-time, adapting to defenses as they encounter them. It’s the difference between a pre-programmed robot on an assembly line and a human navigating a new building-the agent can see, react, and pivot. The data suggests this isn’t an isolated fluke. According to the CrowdStrike 2026 Threat Hunting Report released on August 3, AI agent-triggered detection leads are growing at 2.5 times the rate of human-triggered ones. We are seeing adversaries use AI as a force multiplier, with one campaign firing off nearly 200,000 model requests in just two minutes. CrowdStrike, sensing the shift, launched their Falcon Guardian AIDR on September 1, aiming to provide the runtime visibility and governance that security teams are currently scrambling to implement. The attack surface is also expanding in ways that are difficult to patch. We are