Prof. Dr. Ricardo Usbeck on AI-Driven Cyberattacks
An Analysis
2026-07-30 The second half of July was all about AI: News reports highlighted a hacker attack carried out autonomously by an AI model, and Leuphana announced the establishment of a “Leuphana AI Campus.” While not necessarily consecutive, the two events are certainly correlated, as the cyberattack once again underscores the need for a thoughtful, critical, and competent approach to artificial intelligence – precisely what Leuphana aims to achieve through comprehensive AI literacy education.
We asked Ricardo Usbeck, professor of artificial intelligence and its explainability and co-developer of the “Leuphana AI Campus,” for his assessment.
How do you assess the AI-driven cyberattack currently making headlines, which OpenAI itself has described as an “unprecedented cyber incident”?
Ricardo Usbeck: This cyber incident highlights the capabilities of new, large AI models. It heralds a new era for cybersecurity, but one that should be approached with caution. For one thing, these large language models are not (yet) freely accessible, consume enormous resources, and, under normal operating conditions, have “guard rails” in place to prevent such vulnerabilities from being exploited. For another, from a scientific perspective, the technical report is, at the very least, incomplete. While I believe the incident is real, we should refrain from doomsday predictions and instead seek solutions for the future.
In your opinion, what steps would need to be taken to regulate such powerful AI software?
The regulation of such AI models must take place at the supranational level. This would require either a moratorium on releases to allow time for deliberation, or at the very least, immediate action at the international level. I consider it more likely that so-called “open weight” models (open-source models that anyone can use) will rapidly enter the market and, due to their open nature, cannot be regulated. This would then result in everyone having access to the same cybersecurity tools (in terms of both attack and defense). As a result, the competition would no longer be between models, but between the hardware and the people who use it.
So, should we expect more incidents like this in the future?
Yes! The capabilities of such models have now been proven. Chinese open-weight models like Kimi K3 are poised to develop similar capabilities. That’s why the only solution is to build a high level of AI literacy and learn how to work with such AI models ourselves.
Thank you very much for your assessment of the incident.