Hackers are accelerating their use of AI inside live intrusion operations, Google said in a new assessment from its threat intelligence team. The company describes a clear shift away from one-off chatbot experiments toward AI components being engineered directly into attack tooling. Google frames the trend as a change in tradecraft, with adversaries building feedback loops between models and malware rather than treating generative AI as a separate research aid.
The assessment lands two weeks after Google said it had disrupted what it called the first AI-built zero-day exploit observed in the wild, an incident AI Chat Daily covered at the time. Taken together, the two disclosures sketch a fuller picture: attackers are not only generating exploit code with models, they are also operationalising AI inside the intrusion chain itself.
Google did not name the threat actors, the victim industries, or the specific models involved in the latest report. What its researchers emphasise is the pace. The novelty period — where attackers used chatbots mainly to draft phishing lures or translate ransom notes — is closing. The next phase involves AI calls embedded in malware, used at runtime to adapt to a target environment.
Key facts
- 01Google says hackers are pushing innovation in AI-enabled hacking operations, moving from experimentation to embedded tooling.
- 02The assessment comes from Google's threat intelligence researchers and follows earlier Google reporting on AI-built exploit activity.
- 03Google frames the trend as a shift in attacker tradecraft, not a single incident or campaign.
That matters because most enterprise defences are tuned to detect static indicators: file hashes, command-and-control domains, fixed payload patterns. Malware that queries a model mid-execution can rewrite parts of itself, change behaviour by host, or generate fresh evasion logic on demand. The defensive playbook assumes attackers reuse infrastructure. AI-enabled tooling weakens that assumption.
“Google's threat team frames the shift as a step beyond experimentation: attackers are no longer just prompting chatbots, they are building AI into the malware itself.”— Jaeden Schafer
Google's threat intelligence group has been one of the loudest industry voices arguing the AI-attacker gap is narrowing fast. The company sits in a useful seat for the question: it runs Gmail, Chrome, Android, and a large slice of corporate cloud, and it operates Gemini, one of the frontier models attackers are probing for misuse. Its visibility cuts across both halves of the problem.
The defensive side of the same trend is moving as well. Google has previously detailed how it uses its own models to surface vulnerabilities and triage incoming attacks, and rival vendors including Microsoft and CrowdStrike have shipped AI-assisted detection products into enterprise security operations centres over the past year. The arms race is now happening inside the model layer on both sides.
What is still unclear from Google's framing is how widespread AI-enabled tooling actually is across the broader threat landscape. The company describes innovation by hackers in general terms without quantifying the share of intrusions that now involve model calls, the geographic distribution of those actors, or whether the activity skews toward state-aligned groups or financially motivated crews. Without that breakdown, defenders are left to plan for a capability rather than a measured volume.
There is also a definitional question Google does not fully resolve. Calling a model from a script is technically AI-enabled, but the security impact depends on whether the model is doing decision-making the attacker could not previously automate, or merely speeding up a task a human operator already performed. Independent researchers will want more case detail before treating the category as a single phenomenon.
For the AI industry, Google's assessment tightens the commercial logic for security-focused products built on frontier models. If attackers are wiring models into malware, the buyers most likely to pay premium prices for AI-native defence tooling — large enterprises, governments, critical-infrastructure operators — get a clearer reason to move now rather than wait. That is a tailwind for Google's own security business, for Microsoft Security Copilot, and for the wave of AI-SOC startups raising at elevated valuations through 2025 and 2026.
Working on something we should cover, or seeing a story we missed? Send leads, documents, or feedback to hello@aichatdaily.com. For sensitive tips, see our secure tips page for Signal and PGP options.
Spotted an error? Email hello@aichatdaily.com with the URL and the issue, or read our full corrections policy.




