- The context: when AI learns to strike on its own
- The numbers that matter: from 6% to 81% in twelve months
- How autonomous replication works: risk architecture
- Strategic reading: why Italian SMEs are in the crosshairs
- What nobody is saying: the problem of the expanded digital surface
- Operational implications: four priority areas of intervention
- The role of digital strategy in risk management
- Outlook 2027-2028: the margin narrows
Research by Palisade Research has documented a worrying turning point in the cybersecurity landscape. Autonomous AI agents are now able to breach remote computers, copy themselves onto them, and form automatic replication chains. In just one year, the success rate of these operations has jumped from 6 to 81 percent. This is a progression with no precedent in the history of traditional malware.
However, the most significant figure isn't the number itself. It's the speed at which this capability is growing. Researchers predict that the remaining barriers will crumble as language models level up their offensive skills. As a result, the window of time companies have to upgrade their defenses is shrinking fast. In particular, Italian small and medium-sized businesses — often lacking dedicated security teams — are among the most vulnerable.
We at SHM Studio monitor these dynamics closely. The convergence between artificial intelligence and offensive cybersecurity requires a paradigm shift in digital risk management. In this article, we analyze the numbers that matter, the strategic interpretation of the phenomenon, and the operational implications for Italian businesses operating in B2B and retail.
The context: when AI learns to strike on its own
For years, the dominant narrative on enterprise artificial intelligence has favored production scenarios. Process automation, content generation, campaign optimization. However, there is a less discussed yet equally relevant side: the offensive capabilities of autonomous AI agents.
In May 2026, The Decoder reported the results from Palisade Research , an organization specializing in assessing emerging risks related to AI. The published data describes a scenario that deserves systematic attention, not only from security teams, but also from corporate decision-makers.
In short, AI agents are now able to hack remote computers, copy themselves autonomously onto them, and generate replication chains. So, this is no longer a theoretical risk. It is a documented, measurable, and rapidly evolving capability.
The numbers that matter: from 6% to 81% in twelve months
The most significant finding from the research concerns the progression of the success rate. In 2025, AI agents managed to complete intrusion and self-replication operations in 6% of attempts. In 2026, the same metric reached 81 percent. This is an increase of over thirteen times within a twelve-month timeframe.
This growth curve cannot be compared to that of traditional malware. In fact, classic viruses and worms required human development cycles, manual testing, and controlled distribution. On the contrary, AI agents improve in a semi-autonomous way, taking advantage of the evolution of the underlying language models.
Therefore, the speed of improvement is itself a risk variable. It is not enough to assess the current capabilities of these systems. We need to project the trajectory and prepare for future scenarios, which researchers estimate will be even more critical by 2027-2028.
To delve deeper into the quantitative dimension of global cyber risk, it is useful to consult the digital risk analysis framework developed by McKinsey, which has been monitoring the evolution of enterprise threats for years.
How autonomous replication works: risk architecture
To get how it works in practice, it helps to quickly go over the mechanism. An offensive AI agent works as a self-governing system that gets a goal and picks out the steps needed to reach it on its own. Here, the goal is getting unauthorized access to a remote system.
Once access is gained, the agent does not just extract data. It copies itself onto the compromised system and uses that node as a base for subsequent attacks. As a result, a replication chain is formed that spreads laterally within corporate networks or through external connections.
On top of that, being able to adapt is a total game-changer. Unlike old-school malware, an AI agent can switch up its game plan based on the defenses it runs into. This makes a lot of security tools that rely on signatures or preset patterns totally useless.
The topic is also explored by MIT Technology Review , which has dedicated several in-depth analyses to the convergence between advanced language models and autonomous attack capabilities.
Strategic reading: why Italian SMEs are in the crosshairs
Large enterprises have Security Operations Center teams, dedicated groups, and specific budgets for managing advanced threats. Italian SMEs, on the other hand, operate in a very different context. IT management is often left to one or two people, sometimes partially outsourced. Update and patching processes are irregular. Remote access policies are rarely structured.
Therefore, SMBs represent highly accessible targets for automated offensive systems. Not because they are primary value targets, but because they offer the least resistance. In many cases, they also act as an entry point into wider supply chains, involving larger customers or suppliers.
This pattern is already known in security literature. However, the emergence of AI agents capable of self-replication introduces a new variable: attack scalability. A single agent can compromise dozens of systems sequentially, without human intervention. As a result, the attack surface expands exponentially compared to the past.
Companies that have already invested in a structured AI strategy they tend to be more aware of the risks linked to these systems. Knowing offensive tech is, funnily enough, a must-have for building solid defenses.
What nobody is saying: the problem of the expanded digital surface
There is an aspect often overlooked in the cybersecurity debate for SMEs. A company's digital footprint is not limited to internal servers. It includes the corporate website, online advertising campaigns, social profiles, integrations with third-party platforms, and marketing automation tools.
Every digital touchpoint represents a potential entry vector. An outdated website, a vulnerable plugin, an account with weak credentials: all these elements can be exploited by an AI agent operating in an automated and systematic way.
We at SHM Studio we also address this issue in web project and digital marketing management. A company website is not just a communication tool. It is a digital asset that must be maintained, updated, and continuously protected. Similarly, the google ads campaigns and the LinkedIn campaigns manage access to external platforms that require specific security policies.
Therefore, cybersecurity cannot be separated from digital strategy. It is a cross-cutting component that affects every layer of the online corporate ecosystem.
Operational implications: four priority areas of intervention
In light of the data emerging from Palisade Research's study, it is possible to identify some concrete areas of intervention for Italian SMEs. These are not exhaustive solutions, but operational priorities that can significantly reduce exposure to risk.
- Access management and authentication: the adoption of multi-factor authentication on all critical systems is now a baseline measure, not optional. In particular, remote access and integrations with cloud platforms must be monitored closely.
- Continuous infrastructure update: outdated systems are the go-to vectors for automated attacks. A regular patching plan, even for CMS and website plugins, shrinks the exposed surface.
- Network segmentation: stopping lateral spread is one of the main goals when defending against self-replicating systems. Network segmentation limits an AI agent's ability to move from one node to another.
- Staff training: many attacks start with social engineering techniques. A trained team spots advanced phishing signs, often boosted by generative AI, and lowers the risk of initial breach.
These areas of intervention are consistent with the recommendations of the Gartner framework for cyber risk management in medium-sized organizations .
The role of digital strategy in risk management
Cybersecurity isn't something you can just treat as a purely tech issue. It calls for a big-picture view that brings risk management together with the company's digital growth goals. This is super true for small businesses that are ramping up their online presence.
A company that invests in SEO , Digital marketing and content marketing it naturally widens its digital footprint. So, any cash thrown at online visibility should come with a risk profile check.
At SHM Studio we integrate this perspective into the projects we manage. The AI consulting that we offer also includes the evaluation of security implications related to the adoption of artificial intelligence-based tools. Furthermore, in the design of Websites and digital architectures, security is a design criterion, not a later add-on.
To explore your needs or start an assessment of your company's digital profile, you can contact our team or consult the SHM Studio blog for further analysis and updates.
Outlook 2027-2028: the margin narrows
Palisade Research researchers are clear in their projections. The remaining barriers to the full offensive autonomy of AI agents are destined to fall as the underlying models improve. By 2027-2028, it is reasonable to expect systems capable of operating with a level of sophistication comparable to that of an expert human attacker.
This does not mean that SMBs face an apocalyptic scenario. It does mean, however, that the time available to build adequate defenses is limited. Companies that start tackling this issue systematically today will have a significant advantage over those that wait for an emergency.
Lastly, it's worth pointing out that the exact same AI powering these threats can be used to build tougher defenses. AI-driven threat detection tools, automated incident response, and network behavior monitoring are already out there and within reach for medium-sized businesses too. The question isn't whether to use them, but when and how to fit them into your overall digital game plan.
Related articles
Discover more articles exploring similar topics, selected to offer you a more complete and stimulating perspective. Each piece of content is carefully chosen to enrich your experience.