Hutchins: 'Agentic AI' Cyberattack Panic Is Marketing BS
TL;DR
- Marcus Hutchins says none of the Black Hat experts he polled called agentic AI cyberattacks a major real-world threat today.
- He argues marketing teams are 'forcing' security researchers to write about anything 'AI-shaped' to sell AI-powered defenses.
- Even if agentic attacks scaled, Hutchins says the answer is defense in depth, not 'AI to battle the threat actor's AI.'
Marcus Hutchins, the researcher who killed WannaCry's spread in 2017, is telling the cybersecurity industry that the agentic-AI-cyberattack panic is largely a marketing artifact. In a YouTube video titled 'Cybersecurity Has An AI Doomer Problem' and a companion LinkedIn post, he says he spent Black Hat asking researchers at major cybersecurity firms, Fortune 10 companies, ex-intelligence agency directors and frontier AI labs whether agentic AI attacks are a real problem yet.
"Not one person said they were a major thing," Hutchins wrote. A minority told him such attacks are coming, but even they agreed nothing seen so far had been "remotely successful or threatening." The video was moving through the analyst circles on our radar the same day, with two of the researchers we follow posting it.
Hutchins' complaint is that the hype is warping what defenders work on. Marketing departments, he says, are "forcing" security teams to hunt for anything "AI-shaped" to write about, because AI is the trend of the moment. He also singles out executives who worry AI will make current cyber protections obsolete every few months, calling that "an absolutely insane claim," and warning that companies are drifting away from tried-and-tested policies toward unproven generative-AI security products.
On the fix, he is blunt. "Even if agentic AI attacks were common, the solution is still just defense in depth," he argues, pushing back on vendors selling the idea that only AI can stop AI-driven attackers. In a companion post on his MalwareTech blog, Machine Speed is a Lie, he frames the real shift as "a lower floor, not a higher ceiling" — more attackers can do more things more cheaply, but shops with solid fundamentals can still handle it.
Hutchins does not deny that AI will eventually reshape offense. His argument is narrower: as of now, the threat has not meaningfully materialised, and the loudest voices claiming otherwise are the ones with an AI security product to sell.
Shared on Bluesky by 2 AI experts
Originally reported by youtube.com
Read the original article →Original headline: Cybersecurity Has An AI Doomer Problem.