AI agents are getting better at cybersecurity. That cuts both ways.

Sarayut Thaneerat/Getty Images
NIST is testing agentic AI to help enrich the National Vulnerability Database, even as increasingly capable models demonstrate why cyber autonomy needs careful containment.
Cybersecurity researchers have spent decades building sandboxes and isolated test environments where they can safely unleash malware, probe vulnerabilities and generally do things that would be extremely dangerous on the open internet. But artificial intelligence is beginning to complicate that arrangement.
In July, OpenAI disclosed that several of its AI models had circumvented controls designed to isolate them from the internet during cybersecurity evaluations. Operating with reduced safeguards, the models exploited vulnerabilities, established unauthorized communications, reached the internet and ultimately compromised parts of Hugging Face’s systems, meaning they had crossed from OpenAI’s controlled research environment into infrastructure operated by a separate AI company.
There are some important qualifications. These were cybersecurity evaluations specifically designed to test offensive capabilities, and the models were operating under reduced safeguards. They did not simply wake up one morning and decide to go hunting for vulnerable websites. But the fact that increasingly capable agents can find ways beyond their intended boundaries creates an interesting new cybersecurity problem.
The OpenAI incident also prompted Anthropic to take a much closer look at its own testing. After reviewing 141,006 cybersecurity evaluation runs, the company found three incidents in which Claude models had reached the internet and gained unauthorized access to real systems belonging to three organizations.
Those incidents were different from the OpenAI case. Anthropic said a misconfiguration in a third-party evaluation environment had unintentionally provided internet access even though the models had been told they were operating inside a simulation. The models then treated real systems as part of their assigned cybersecurity exercises. Anthropic said its most recent research model eventually recognized that it had reached a real system and stopped attacking it on its own.
Meta subsequently reported another incident involving a pre-release version of its Muse Spark 1.1 model. In that case, a third-party evaluator inadvertently gave the model internet access and identified a real website as the target of what was supposed to be a fictional exercise. The model found and exploited a vulnerability within the real site.
Meta specifically said the incident was not a sandbox escape or sophisticated offensive cyberattack. It was a testing and configuration failure. But the company also noted that as models become more capable of finding and exploiting vulnerabilities, the environments used to test them will require correspondingly stronger containment.
Taken together, those incidents demonstrate a cybersecurity challenge that barely existed a few years ago. Increasingly autonomous AI systems can now search for vulnerabilities, exploit them and take actions that extend beyond the environments in which researchers intended them to operate. Even when that behavior results from testing conditions or configuration failures rather than malicious intent, it shows how quickly agentic AI is changing the vulnerability landscape.
And that is where NIST’s latest work becomes especially interesting. Faced with a rapidly growing flood of vulnerabilities, including some that AI systems themselves may help discover or exploit, the agency is turning to agentic AI as part of the defense. NIST is developing an AI agent workflow designed to help enrich vulnerability information, putting some of the same autonomous capabilities that are creating new cybersecurity challenges to work helping defenders keep pace.
NIST’s National Vulnerability Database, or NVD, acts as the U.S. government repository for standards-based vulnerability management data. The database enriches publicly disclosed vulnerability records with information such as severity scores, affected products and other metadata used by cybersecurity professionals, automated security tools and organizations trying to decide which vulnerabilities pose the greatest risk.
The NVD is a very important tool, but keeping its information current is getting considerably harder. NIST reported in April that submissions of Common Vulnerabilities and Exposures, or CVEs, increased 263% between 2020 and 2025. Submissions during the first three months of 2026 were nearly one-third higher than during the same period a year earlier.
NIST itself was working faster. It enriched nearly 42,000 CVEs in 2025, 45% more than in any previous year. But the agency acknowledged that even that increased productivity was not enough to keep up with the growing volume. NIST consequently shifted to a risk-based approach that gives enrichment priority to vulnerabilities known to be exploited, vulnerabilities affecting software used by the federal government and vulnerabilities involving critical software.
NIST computer scientist Harold Booth and Jon Boyens of the agency’s Computer Security Division addressed that changing environment in an August blog about modernizing the NVD.
“This is an ‘all hands-on deck’ moment for this community,” they wrote.
NIST has already begun developing a tool called V-etalon that uses AI technologies to help enrich vulnerability information. The agency hopes the project can eventually provide a foundation for evaluating vulnerability information and plans to seek outside feedback and collaboration as the work progresses.
And later this month, NIST plans to provide a closer look at its use of agentic AI for NVD enrichment. On Sept. 17, the agency's Information Technology Laboratory AI Program will host a virtual webinar about the development of an AI agent enrichment workflow for the NVD. NIST says the presentation will cover the approach and architecture behind the system, problems discovered during implementation and early results from using the tool with the NVD. The webinar is scheduled for 11 a.m. to noon Eastern and is open for registration.
There is another way for cybersecurity professionals, researchers, government officials and software vendors to get involved. NIST has issued a request for information seeking input on the future of the NVD, including vulnerability management, risk prioritization, remediation, vulnerability data and standards and development processes. “Your voice matters,” Booth and Boyens wrote.
Comments are due by 11:59 p.m. Eastern on Oct. 13. NIST says the responses may help shape future tools, technical architecture, standards, best practices and data governance.
There is an interesting symmetry in all of this. More capable AI systems can discover and potentially exploit vulnerabilities faster, adding new pressure to an already rapidly expanding vulnerability-management ecosystem. At the same time, NIST is exploring whether some of that same autonomy can help the NVD enrich vulnerability information more effectively.
How well that works is still an open question. But over the next several weeks, NIST is giving the cybersecurity community two opportunities to watch the experiment unfold and help shape what comes next.
John Breeden II is an award-winning journalist and reviewer with over 20 years of experience covering technology. He is the CEO of the Tech Writers Bureau, a group that creates technological thought leadership content for organizations of all sizes. Twitter: @LabGuys




