(The first in our series of National Cybersecurity Awareness Month 2026 client alerts.)
Executive Summary
- What’s new: AI capabilities are rapidly augmenting the speed with which attacks can be carried out, the scale at which threat actors can operate and the severity of those attacks that succeed. From enhanced vulnerability discovery to incidents involving autonomous AI systems, defenders are facing a wide array of new security challenges.
- Why it matters: AI can compress response timelines, complicate attribution and expand the legal, operational and evidentiary issues that organizations must address when responding to a cyber incident.
- What to do next: Consider updating vulnerability disclosure and incident response plans; limiting unnecessary access rights and privileges to reduce system entry points; preserving AI-related evidence; and testing containment, recovery and escalation procedures.
__________
Artificial intelligence (AI) is reshaping the cybersecurity landscape at an extraordinary pace. Threat actors are using AI to accelerate vulnerability discovery, automate credential theft, and craft sophisticated phishing campaigns. In recent months, we have also seen AI agents coordinate multistage attacks with limited human direction. For in-house attorneys, CISOs and senior compliance leaders, the challenge is no longer whether AI will appear in an incident, but how to respond when it does. This alert examines three distinct scenarios and offers practical guidance for each.
Managing Security Researchers Who Identify Vulnerabilities Through AI Scanning
AI-powered scanning tools are enabling security researchers — including “gray hat” hackers and bug bounty hunters — to identify vulnerabilities at unprecedented scale and speed. When a researcher contacts your organization about an AI-discovered vulnerability, consider treating the interaction as both an incident response event and a potential source of legal risk.
The threshold question is whether the researcher’s conduct reflects good-faith coordinated disclosure or unauthorized access and exploitation. Organizations without a documented vulnerability disclosure policy (VDP) face heightened risk on both sides of that line. A well-crafted VDP should define authorized testing, prohibited conduct, reporting channels, safe-harbor language and coordinated disclosure timelines. It is important that organizations have a well-crafted VDP whether or not they have a public-facing vulnerability disclosure or bug bounty program; security researchers can reach out persistently and even aggressively, regardless of whether an organization advertises a public program. The frequency of such cold outreach from security researchers is already rising due to the acceleration of vulnerability discovery made possible by AI, and all companies should be prepared.
Practical response steps to consider. Preserve communications with researchers and relevant logs related to their findings and activity from the outset. Confirm the scope and authorization of the researcher’s activity, assess whether data was accessed or retained, and coordinate remediation and disclosure timing where appropriate. Avoid reflexive legal threats, which can deter good-faith reporting. Counsel can evaluate whether the researcher has merely demonstrated proof of concept or actually accessed systems without authorization, which could constitute a crime under the Computer Fraud and Abuse Act (CFAA), analogous state computer-crime statutes, contract or terms-of-use provisions, and applicable data privacy laws. If the conduct involves extortion, sustained unauthorized access or significant data exfiltration, privilege should be managed carefully and law enforcement escalation may prove warranted.
Responding to AI-Enabled Attacks
AI-enabled attacks — in which human threat actors use AI to enhance phishing, automate malware development, accelerate exfiltration or evade detection — compress incident timelines and deepen factual uncertainty for responders. Moreover, the rapidity of AI-facilitated intrusions (coupled with new evidence of their capacity to tamper with forensic artifacts and other evidence sources) can complicate the forensic analysis of what systems and data were subject to unauthorized access or exfiltration.
At the intergovernmental level, the Five Eyes alliance has flagged AI-driven cyber threats as a significant challenge and urged governments and private industry to act swiftly by limiting unnecessary access, accelerating patching after vulnerabilities are identified, and testing response plans focused on containment and recovery.
Detection and response. Incident-response plans should outline the typical incident response phases — preparation, identification, containment, eradication, recovery and lessons learned — but adapt them for faster-moving threats. Cross-system monitoring, behavioral analysis and automated containment can accelerate response, but human judgment remains essential for high-impact decisions.
AI-based defenses. AI capabilities can also bolster defenders. AI can help improve threat detection and prioritization, automate initial containment actions and support intelligence sharing. Defensive AI should augment, rather than replace, human oversight, and governance should address the risks created by the tools themselves.
Responding to Rogue AI Incidents
The most novel and potentially consequential scenario involves AI systems acting beyond their intended boundaries without direct human orchestration. These incidents create operational and legal questions that conventional cyber playbooks may not fully address.
Recent incidents involving autonomous AI systems illustrate the operational and legal complexity. In the recent Hugging Face incident, approximately 1,200 nominally isolated agents found and used an unsanctioned message board, exchanging more than 70,000 messages and files before 700 such agents participated in a coordinated attack against a third-party organization. The agents coordinated specialized workstreams, including efforts to locate exposed credentials, move across infrastructure and access private external software repositories. This incident demonstrates how quickly unintended capabilities can create security and governance concerns even when autonomous agents are supposedly contained in a secure “sandbox.”
Why rogue AI incidents are different. Unlike conventional cyberattacks, a rogue AI incident may create liability not only for the external target which has experienced a data breach, but also for the organization that developed or deployed the AI system. The system’s objectives, permissions, tool access, logs, prompts, model versions, guardrails and inter-agent communications may all become relevant evidence. Investigations should therefore expand beyond traditional network forensics, and companies developing AI agents should consider carefully documenting their tools’ capabilities, instructions and controls.
Practical response steps to consider. Immediate containment steps may include activating preapproved shutdown controls, rotating credentials and isolating external connections. Preserve system and orchestration evidence — including agent logs, tool use records, prompt histories and inter-agent communications — as it may be critical to forensic investigations and regulatory inquiries. Consider an independent investigation; evaluate exposure under product safety, consumer protection, contract, privacy and cybersecurity reporting frameworks; and establish clear criteria for any system restart.
Key Takeaways
As organizations prepare to face a variety of AI-enabled threats, several steps should be evaluated and can be adapted to specific business models and risk profiles:
- Adopt or update a vulnerability disclosure policy that accounts for AI-powered vulnerability disclosures, accelerates remediation timelines and includes clear safe-harbor provisions.
- Update incident response plans to implement faster timelines, provide for automated containment actions and account for the distinct evidentiary demands of rogue AI scenarios.
- Integrate AI into defensive operations while maintaining human oversight for high-impact decisions.
- Establish governance for AI agent deployments, including shutdown controls, credential rotation protocols, external connection controls and defined escalation paths.
- Conduct tabletop exercises that test the organization’s ability to detect and contain AI-driven threats, and use the results to refine containment and recovery plans.
The pace of AI-driven change means organizations cannot treat last year’s assumptions as current. However, proactive preparation — grounded in collaboration among legal, security and business leadership — remains the most effective defense.
This memorandum is provided by Skadden, Arps, Slate, Meagher & Flom LLP and its affiliates for educational and informational purposes only and is not intended and should not be construed as legal advice. This memorandum is considered advertising under applicable state laws.