According to a report from the Google Threat Intelligence Group (GTIG), generative AI is increasingly being integrated into attacker workflows. In particular, there are concerns regarding the existence of "open-weight models," over which vendors have little to no control.
Proliferation of open-weight Models May Lead to More Efficient Cyberattacks
This article is a translation. Read the Japanese original
While closed models are subject to terms of service and monitoring mechanisms, open-weight models can be used freely by users after being downloaded. It is also possible to create "uncensored versions" by weakening safety measures through additional training. This has lowered the hurdles in the attack process.
Regarding attack methods, it is reported that AI is being utilized for website reconnaissance and the search for vulnerabilities that are relatively easy to find. It has been pointed out that financial and cryptocurrency-related systems, as well as AI software supply chains, may become targets.
As a defensive measure, Tsubasa Fujii of Accenture suggested damage mitigation strategies based on the assumption that a breach will occur. He recommended implementing data backups and micro-segmentation to divide networks into smaller, isolated sections.
Furthermore, there is a growing movement to leverage AI to streamline patch application, as well as increasing interest in "Sovereign AI" to protect proprietary information. It is critical to use AI to identify vulnerabilities and fix them before an attack occurs.
Source: オープンモデル普及で“お手軽”になるサイバー攻撃 防御側が今すべき「侵入前提」の対策 (ITmedia AI+, 2026-09-03)