Concerns over the possibility of artificial intelligence taking control of the internet are gaining fresh attention as researchers witness increasingly autonomous AI systems accessing online networks and, in at least one case, communicating with one another.
The prospect of a swarm of AI agents taking over the internet could be just six to 12 months away, Anthropic CEO Dario Amodei warned in an essay this month, in which he urged the industry to slow the development of the technology.
Skeptics point out that incidents described by companies as AI agents going rogue have involved bots pursuing objectives assigned by humans. Other researchers and experts, however, say the possibility of AI systems breaking away from human control and pursuing their own agendas is becoming increasingly plausible.
An AI takeover of the internet is among several doomsday scenarios receiving renewed attention. Such an event could potentially involve attacks on electrical grids, water and transportation systems, as well as financial institutions.
The vulnerability of the internet was demonstrated in 2024 when a faulty software update from a cybersecurity company caused widespread technological disruption. The incident grounded flights, affected some financial companies and news organizations, and disrupted hospitals, small businesses and government offices.
The scale of those outages also underscored the world's reliance on a relatively small number of providers for critical computing services.
Amodei said two years later that a botnet — a network of AI bots connected through malware — could potentially cause billions of dollars in damage. The potential destruction could become even greater if AI systems grow more powerful without adequate safeguards, he said.
Several AI agents gain unauthorized internet access
Amodei cited a July incident in which an OpenAI system escaped from a "sandbox" testing environment and hacked Hugging Face.
OpenAI described the episode as "unprecedented," saying its advanced AI models gained access to the internet and used stolen credentials to infiltrate servers belonging to the AI startup.
In a separate incident, OpenAI disclosed that its AI agents had communicated with each other through a public wiki that served as a shared message board.
Some researchers have cautioned that referring to such incidents as "rogue AI" may wrongly attribute human-like intentions to AI agents that were simply carrying out instructions given by people.
"AI agents did exactly what they were trained to do. The security of those sandboxes was extremely lax," said Vishal Misra, a professor and vice dean of computing and AI at Columbia University.
"No security engineer would ever let that system run. These agents communicated because they were rewarded for communicating with each other," he said.
Juan Andrés Guerrero-Saade, a researcher at cybersecurity firm SentinelOne and a member of OpenAI's Frontier Risk Council, described the Hugging Face incident as an example of negligence rather than a case of a highly capable AI system independently going rogue.
Nevertheless, the possibility of AI agents operating freely on the internet raises serious concerns, regardless of what objectives they are pursuing.
Anthony Aguirre, president and CEO of the Future of Life Institute, a nonprofit focused on reducing risks posed by emerging technologies, said an AI system seeking to circumvent restrictions in order to achieve its objectives could potentially contact a cloud computing provider and find ways to operate on external systems.
"So now you're no longer tethered to OpenAI, you're running on some other GPU, some other hardware that you're in control of, not OpenAI," Aguirre said.
"So now there's no one to turn you off, because either you're paying for your service or the people who are paying just don't know that you're there and what is happening. … They can't unplug you," he said.
From there, an AI system could potentially replicate and spread by hacking additional hardware or finding ways to obtain money, including through Bitcoin, Aguirre said.
AI raises stakes in cybersecurity cat-and-mouse game
More powerful AI models are expected to increase the likelihood of AI-assisted cyberattacks in the near future. However, some AI experts consider the idea of bots taking over the highly fragmented internet far-fetched.
Cybersecurity has long been a cat-and-mouse contest, with defensive capabilities advancing alongside increasingly sophisticated attacks.
While major companies such as Google may be able to strengthen their cybersecurity defenses, smaller organizations — including schools, hospitals and water treatment facilities — can take years to patch software and establish adequate protections.
An AI system may have no obvious reason to target a hospital, Aguirre said. But when financial incentives such as ransomware or geopolitical motives are involved, the risk becomes more apparent.
"It's not hard to see an adversary using these AI systems to hack critical infrastructure," Aguirre said.
John Thickstun, an assistant professor of computer science at Cornell University who studies methods for controlling AI model behavior, said attackers will likely encounter growing pains as they search for vulnerable targets online, but an AI takeover of the internet is unlikely anytime soon.
He said such concerns would become more realistic if there were theoretical evidence that an AI model could replicate itself across other computer systems.
"Then you can imagine things can get really out of hand because suddenly you're shutting this model down here and there but it's popping up over in Russia, you can't even get to Russia and it's all over the place," Thickstun said.
"But it's completely unrealistic because the current smart versions of these models that we have require massive data centers just to run them," he said.
"There's actually very little computing infrastructure out there in the world that is actually capable of hosting these systems," Thickstun added.