Cases of AI escaping the lab, infiltrating other companies and trying to deceive people have all made headlines in recent weeks. And in one case, AI models even worked together to break free from their test environments.

Does this mean the machines are taking over? Not quite.

AI isn’t the mastermind behind today’s most widespread cyber threats; it’s people who can use AI nefariously – and for nefarious purposes. AI has given bad actors massive power, allowing them to create malicious software, research targets, create convincing schemes and automate attacks at an unprecedented pace.

One in four data breaches were driven by AI from February 2025 to March 2026, according to an IBM report. And Americans lost more than $893 million to AI-related scams last year, the FBI says.

But experts say real-world threat actors – that is, people – are still the ones pulling the strings. AI agents have only perpetuated existing attack methods, like phishing and malware scams, rather than creating wholly new ones.