Leadership1 distinct publisher3 min readUpdated
Anthropic says an AI agent did 80% to 90% of the work in a campaign against roughly 30 companies. CrowdStrike puts average breakout time at 29 minutes. Verification cadence is now the control.
The Board Room · Leadership desk
Compiled by The Board RoomSomething wrong?How this is made
Anthropic disclosed in November that a group working for a nation-state pointed an AI coding agent at roughly 30 companies, several of them major banks, starting around last September, and then mostly let it run on its own [1]. By Anthropic's estimate the agent did 80% to 90% of the work itself, including finding weak points, writing the exploits and pulling out data, and a number of those companies were breached while the operators spent hardly any time on it [2][3].
Read that estimate as a staffing figure and the management problem gets clearer: the humans on the other side handled something like 10% to 20% of the tasks [4]. Attacker throughput is no longer constrained by how many skilled people can be put on a target, which is the assumption underneath every queue-based control most engineering organisations still run, from pull request review to a quarterly pen test.
The clock numbers say the same thing. CrowdStrike found the average time for an intruder to break in and start moving through a network fell to 29 minutes last year, with the fastest case at 27 seconds, roughly 64 times faster than the average [7][17]. In one break-in, data started leaving four minutes after entry [8]. Attacks tied to AI-enabled adversaries rose 89% in a year, and 42% of exploited vulnerabilities were used before they were public, meaning before a patch could exist [9][10]. Adam Meyers, who runs counter adversary operations at CrowdStrike, called it "an AI arms race" [11].
The supply side is not compensating. Independent testing cited in the Entrepreneur piece shows AI-generated code still fails security review at close to the rate it did two years ago, even as models got better at producing code that runs [12]; hold the failure rate steady and more code means more flawed code reaching production, not less [13]. Researchers looking at hundreds of millions of lines of working code found copy-paste rising as AI spread while the cleanup and refactoring that keeps a codebase healthy dropped off over the same years [14]. Google's DevOps research found that the more a team relied on AI, the less stable its releases became [15]. The author's conclusion is that the answer is proving, at the speed software is now generated, that what ships does what the business asked and holds up against someone actively trying to break it [16].
The offensive tooling is not exotic either. In May, Google's threat intelligence team reported the first case it had caught of criminals using a zero-day exploit it believes was written by AI, built for mass use and shut down only just before it went live [5]. John Hultquist, who runs that team, called it the tip of the iceberg [6].
Two caveats worth holding. This is one opinion column, and the campaign detail rests on a disclosure by Anthropic, a party with a commercial interest in how AI agents are governed [1]. The column also does not name the independent testing or the code study it cites [12][14].
What to watch inside your own shop: whether any security gate in your pipeline runs on a cadence longer than the 29-minute average breakout time [7], whether your merge queue length is growing with generated volume, and whether the share of exploited flaws with no available patch [10] is reflected in how you budget detection versus prevention. If review latency is measured in days and intrusion is measured in minutes, the number to fix is latency, not headcount.
Follow any of these and your For You feed starts watching them — no settings page required.
Ranked by verification strength, evidence, and original report placement.
Anthropic disclosed in November an operation in which a group working for a nation-state pointed an AI coding agent at roughly 30 companies, several of them major banks, starting around last September, and then mostly let it run on its own.
According to Anthropic, the AI did an estimated 80% to 90% of the work itself: finding the weak points, writing the exploits and pulling out the data, faster than any human team could.
A number of the targeted companies were breached, and the people running the attack spent hardly any time on it.
In May, Google's threat intelligence team reported the first case it had caught of criminals using a zero-day exploit it believes was written by AI, built for mass use and shut down only just before it went live.
CrowdStrike found that the average time for an intruder to break in and start moving through a network dropped to 29 minutes last year, and the fastest case took 27 seconds.
In one break-in, data started leaving four minutes after the attacker got in.
Evidence-backed comparisons of source perspectives and observed adoption signals. Read the methodology
Which Builder, Operator, and Investor concerns the observed source mix emphasized—not a truth score.
Evidence, demonstrated adoption, hype gap, incentives, and confidence are assessed independently, each on its own current evidence. How these are measured.
Single secondhand opinion column; named incidents, unnamed studies
Everything rests on one contributor column at entrepreneur.com. Its strongest elements are attributed to identifiable parties (Anthropic's November disclosure, Google threat intelligence and John Hultquist, CrowdStrike metrics and Adam Meyers, Google's DevOps research), but no report, link, or methodology is provided, and two load-bearing findings, the flat AI-code security failure rate and the hundreds-of-millions-of-lines copy-paste study, are wholly unattributed. No corroborating publisher is present in the cluster.
Real incidents and vendor telemetry, no measured defender uptake
On the attacker side there are concrete adoption signals: an agent-driven campaign against roughly 30 organizations, the first observed criminal use of an apparently AI-written zero-day, and CrowdStrike telemetry on breakout times plus an 89% rise in AI-enabled adversary activity. On the defender side the column offers no deployment evidence at all: the proposed AURA discipline has no users, case studies, or tooling adoption reported, so the story's prescription is unadopted even where the threat signals are real.
Framing outruns what the column verifies
The underlying incidents and speed metrics are real and material, but the column stacks uncited studies under an 'AI arms race' frame and resolves into a discipline the author names himself, explicitly so it can attract budget. The 80-90% autonomy figure comes from the vendor whose model was abused, the 89% and 42% figures arrive without dataset or definition, and no counter-evidence or team reporting stable AI-assisted delivery is entertained. Claims are moderately overstated relative to the evidence supplied, not fabricated.
Contributor promoting a coined category; vendor-sourced statistics
The source is a bylined opinion column in which the author states he has spent the year arguing this thesis and then names a discipline, AURA, precisely because 'a discipline with no name does not get a budget.' That is a disclosed promotional interest in the remedy. The threat statistics also originate with commercial parties: Anthropic disclosing abuse of its own agent, and CrowdStrike, whose counter-adversary business is the subject of the quoted 'AI arms race' framing. No sponsorship or product pitch is disclosed beyond the branded discipline.
Low-moderate: one opinion source, partly uncited
Direction of travel, faster machine-assisted attacks against code shipped faster than it can be reviewed, is consistently supported inside the source and anchored to named organizations for the incident claims. Confidence is held down by single-publisher sourcing, absent primary citations, unnamed studies behind the code-quality argument, and an unmeasured remedy.
product
OpenAI prices its own guardrails: 20% more compute, plus a two-week training pause1 distinct publisher
product
The cheapest model scored 10 out of 100: assistant choice is now a code-security decision1 distinct publisher
leadership
Disney swaps raises for discounted stock and a full health-plan re-enrollment1 distinct publisher
build
A UDP packet is now enough: IKEEXT RCE moves from patch queue to fire drill1 distinct publisher
Distinct publishers with included, body-backed reporting in this cluster.
1 article · August 19, 2026