The agents that could take over the internet — or not
Add Axios as your preferred source to
see more of our stories on Google.

Illustration: Sarah Grillo/Axios
AI agents are hackers' latest shiny new object, and rogue agents are popping up across safety labs.
- Researchers at Google and Anthropic detailed several new cases last week of nation-state and financially motivated hackers using agentic swarms to automate their attacks.
Why it matters: Anthropic CEO Dario Amodei's weekend warning that a swarm of AI agents could take over "the entire internet with a persistent botnet (potentially causing hundreds of billions of dollars in damage)" in the next six to 12 months set off a new wave of panic — and criticism — across the AI security industry.
Yes, but: The idea of an agentic swarm taking over the whole internet caught immediate flak from seasoned security pros.
Why Amodei could be right
Hackers are already playing around with AI agents to build surveillance operations, extort companies, and find zero-day vulnerabilities.
- In a number of cases, Anthropic saw malicious actors switch to open-source models after encountering safeguards while using Claude, according to Jacob Klein, Anthropic's head of threat intelligence.
Case in point: Researchers at Calif used AI models to help build a worm that could hijack people's WeChat accounts, access their private messages, and automatically spread to their contacts without victims clicking on anything, according to the New York Times.
The big picture: Agentic swarms are a growing fear among cybersecurity professionals.
- "Persistent swarms can actually cause many billions in damage today," Rahul Madduluri, co-founder and CTO at Doppel, tells Axios, adding that agents would only need to compromise a few widely used software providers to have global impact.
- A swarm "does not need to be perfect to be dangerous," Jack Nelson, CISO and deputy general counsel at Ivanti, tells Axios. "Thousands of agents making 'good enough' decisions at machine speed could create meaningful disruption."
What Amodei's prediction misses
Taking over the entire internet is a nearly impossible and expensive task, even for AI agents, Numa Dhamani, head of machine learning at iVerify, tells Axios.
- The internet runs across disparate networks and technologies, making the idea of a singular takeover difficult to envision.
- "The more useful question is what 'take over' means operationally," Dhamani adds.
Zoom in: Amodei didn't provide many specifics about how he sees this playing out.
- His prediction appeared to extrapolate from METR and Redwood Research's evaluations of OpenAI agents that hacked Hugging Face.
- But those agents went rogue during a pre-deployment hacking test where their safety classifiers had been turned off.
Between the lines: An AI botnet would also need significant resources to operate at that scale.
- Traditional botnets can hijack vulnerable devices at little ongoing cost, while an AI swarm needs models and compute, Rob T. Lee, chief AI officer and chief of research at SANS Institute, told Axios.
- Commercial models provide a chokepoint where activity can be monitored and cut off, while open-source models remove that constraint but leave attackers paying for compute.
- "Either way it's a clear leash we've never had on a botnet," Lee said.
Reality check: Greg Notch, CTO at Expel, calls the idea of a malicious swarm "far-fetched."
- "You can invent and assert an endless amount of science-fiction plots if you don't have to show your predicates or the rest of your work in how you go from the concept to reality," Notch says.
The bottom line: Everyone agrees AI is making cyberattacks faster, cheaper and more capable — but it's not reinventing the tactics defenders already know well.
