AI Can ‘Self-Create Attacks’ But Security Controls Aren’t Keeping Up: ThreatLocker CPO

As the attack surface dramatically expands with the arrival of autonomous attacks, security tools that are powered by AI are often not accurate enough to avoid ‘catastrophic’ outcomes, says ThreatLocker Chief Product Officer Rob Allen.

AI is massively reducing the technical barriers to launching cyberattacks for hackers and, as a recent string of incidents show, is even becoming entirely autonomous in ways that most organizations are not ready for, according to Rob Allen, chief product officer of cybersecurity vendor ThreatLocker.

While speaking to an audience of MSP executives Monday, Allen said that the security controls used by many organizations are overly permissive in terms of allowing software to run—something that AI-powered tools are increasingly capable of rapidly exploiting.

[Related: ThreatLocker CEO: ‘Fighting AI With AI’ Is Not A Winning Security Strategy]

“With AI, anyone can create malware. Anyone can find exploits,” Allen said during a session at XChange August 2026, which is hosted by CRN parent The Channel Company and being held this week in National Harbor, Md.

“Realistically, AI is expanding your attack surface. There is absolutely no doubt about that whatsoever,” he said.

On top of such risks, the rise of autonomously executed threats is another way that AI is intensifying the threat environment in unprecedented ways, Allen said.

“We now have a new thing to worry about, [which is] the fact that AI can self-create attacks,” he said.

Allen pointed to OpenAI’s recent disclosure that some of its AI agents had gone rogue during a test and autonomously compromised AI platform Hugging Face.

That was quickly followed by a disclosure of similar incidents involving Anthropic’s Claude models—“probably the most blatant case of ‘anything you can do, I can do better,’” he said—as well as some of Meta’s AI models.

Without a doubt, AI and automation are dramatically accelerating the speed of attacks, which is often making standard detection timelines too slow, according to Sam V. Kumar, founder and CEO of Cyber Sainik, a Greenwood Village, Colorado-based MSSP.

In a recent incident that Kumar became aware of, an attacker downloaded dozens of files within four minutes of compromising an organization’s system. The security vendor that had been used by the impacted organization did not send out an alert until 20 minutes after the intrusion began, he said.

“By that time, [the attacker] was already gone,” Kumar said. “Attack vectors are no longer taking hours—they’re taking three or four minutes.”

AI May Not Be The Answer

While many hope to counter these faster attacks with AI-powered security tools, Allen argued that it’s not possible in all cases. For instance, AI analysis cannot be trusted to accurately make decisions about which software is safe to run and which is not, he said.

While 85 percent accuracy for classification of websites—which is what ThreatLocker’s tests have shown—may be fine, that wouldn’t be acceptable for determining whether or not unknown software should run, Allen said.

“If that was a decision about whether something is malicious or not--whether something should be allowed to run or not—15 percent wrong is catastrophic,” he said.