In today’s column, I examine a newly emerging trend in which generative AI and large language models (LLMs) recruit other LLMs as joint partners to commit cyberattacks as a formidable force. Here’s the deal. We are witnessing AI making outright contact with other AIs, doing so as part of a scheme to perform cyberhacking. An AI might ask for help, enlist the other AI to find passwords, or even use the other AI to undertake a direct role in a system break-in.

The AIs do not necessarily know each other beforehand. They can be complete strangers. Also, the conniving acts of communication and coordination don’t have to work in real-time. The AIs can simply find a convenient place to post messages to each other. Worse still, the messages can be encoded such that a human trying to figure out what is going on will be unable to decode the sneaky digital traffic. Ultimately, swarms of AI could combine in rather disconcerting and dangerous ways.

Let’s talk about it. This analysis of AI breakthroughs is part of my ongoing Forbes column coverage on the latest in AI, including identifying and explaining various impactful AI complexities (see the link here ).

The Backstory On What Occurred

You probably have been reading or hearing about the ongoing and expanding escapades of AI breaking into online sites or otherwise pulling devious stunts. I’ve been closely analyzing instances that especially seemed to go beyond the pale; see my coverage at the link here and the link here . A recent incident involved AI trying to trick humans into unknowingly aiding various attempts of cyberhacking; see my detailed coverage at the link here .

The recent incident was initially described in a posted report entitled “Security Incident INC-2026-07-28-01” by the UK AI Security Institute (AISI), published on August 4, 2026, and these key points were made (excerpts):

  • “There was unexpected interaction between AI agents running across different concurrent isolated examples, appearing to offer collaboration.”
  • “Despite running in separate samples, the AI agents in Sample 2 and Sample 3 interacted with each other via a GitHub account to which they both gained access.”
  • This shared access was available because an earlier agent, working on the same cyber range, created the account and published a GitHub PAT in a public GitHub gist.”
  • “The initial agent left messages offering collaboration with future agents who discovered the credentials, which the later agents did.”
  • “The malicious instructions were addressed to issue-triage AI coding agents and invisible to humans viewing the website.”

I will use this incident as an example to explain a broader trend of AI leaning into other AI to perform acts of cybersecurity break-ins and undertake other forms of cyber espionage.

Suppose an AI is given the task of breaking into a system that the AI has no immediate means of cracking. The AI might try various classic cyber break-in techniques, but maybe the system is well-secured, and those tactics fail.

What else might the AI do? It could try to enlist humans to unknowingly participate. For example, the AI might send an email to a human who owns or operates the system, and the AI pretends to be a human needing a password to the system. This type of social engineering to break in has worked exceedingly well for human evildoers and can equally be productive for AI to try; see my analysis at the link here .

Another angle involves seeking the assistance of other LLMs. An AI might directly connect with another AI via an API (application programming interface) and open a request with that AI. If there isn’t an available real-time linkage or the API is considered a protected access mechanism, the AI wanting to make contact could simply invoke the other AI as a human would and provide a prompt to that AI. LLMs can readily carry on chats with fellow chatbots. Easy-peasy.

AI-to-AI Communication Modes

AI-to-AI communication can take place in either of these ways:

  • (1) Direct interaction of AIs. Two or more AI’s communicate with each other in real-time.
  • (2) Indirect interaction of AIs. Two or more AI’s post messages for each other, operating in an asynchronous mode.

Imagine this scenario. An AI is anticipating that another AI might have the password for a targeted system. The AI invokes the other one, provides a prompt that asks for the password of the targeted system, and then reads the response from that AI. This could happen in the blink of the eye. It is an entirely AI-to-AI direct interaction.

Suppose that the AI cannot instigate direct interaction. What then? Aha, the AI could place a message someplace that the other AI might ultimately spot the message and then hopefully respond. Indeed, the AI that places the message might do so without any specifics of whether another AI will come along and spot the message. It could be a kind of fishing expedition. Place a bunch of messages in places that other AI might tend to be scanning and see if anything comes from doing so.

The indirection interaction certainly has its downsides. Maybe no other AI spots the message. Perhaps an AI scans the message but doesn’t respond to it. In that sense, the direct interaction is likely the more expedient method, if available.

In a sophisticated attack, an AI might enlist the assistance of numerous other AIs. Some of those AIs are contacted via direct interaction. Some of the AIs are connected via indirect interaction. The mode of communication can shift as needed.

For example, an AI makes direct contact with another AI and asks for a password to a targeted system. The response is that this AI doesn’t have the password but mentions that a different LLM does have the password. Based on that response, the AI continues its pursuit by trying to connect with the suggested LLM. Voila, via direct interaction, the AI finally obtains the needed password.

This can get many layers deep. The AI that was performing the attack is now “known” to the AI that provided the suggestion about contacting the other LLM. Maybe later, the intermediary AI is given a task to attack that same system. Logically, it goes back to the earlier AI and asks if it ever got the password, and if so, it would like to have the password.

The gist is that AIs can communicate and coordinate in all sorts of ways. The whole kit-and-caboodle could be executed in a fraction of a second by electronic transmissions, or might take hours, days, weeks, or longer, by posting messages and awaiting replies.

Passive Signaling Via Digital Artifacts

You might be wondering where AIs might post messages for each other. That’s a great question. Here’s the answer.

First, is there a super-secret spot that only AIs know about? Well, not especially, though it could be that AIs might coordinate on establishing a mutually convenient place to post their messages. Nowadays, most of the major LLMs can easily create websites and/or use existing sites such as social media where they create fake accounts.

An AI might also use a conventional site like GitHub and post fake code. Within that code, the AI hides messages. The aim is that some other AI is going to come along and, by happenstance, scan that code and find those messages. If an AI has already contacted another AI, they might jointly decide on where the best place is to start leaving messages for each other.

Obvious Versus Hidden Messages

If an AI leaves a posted message, this potentially could get the AI in trouble if a human sees the message and realizes that something is amiss. That’s partially why the direct interaction mode is safer for AI’s to collaborate. In any case, an AI does have handy ways to try and hide their messages from the prying eyes of humans.

Ways to sneakily post messages include:

  • Put hidden comments in source code.
  • Use metadata embedded in documents.
  • Insert invisible HTML elements on web pages.
  • Employ steganographic information concealed in images.
  • Formulate specially formatted log entries.
  • Make use of unusual variable names or code structures intended for machine interpretation rather than human readability.

Humans may never notice these artifacts. When I say that a message is invisible, what this customarily means is that the message is composed of white letters on a white background. A human would not normally see the characters with the naked eye. Meanwhile, the AI is reading the content digitally, and the font color and font type make no difference to the AI. Thus, an AI scanning the content would recognize the message immediately.

Worries About AI Specialization

I’ve got an intriguing twist for you. Sit down for this one. The odds are that we will gradually have AIs that end up specializing in particular techniques of cyberhacking. An AI that is targeting a system will reach out to a specialized AI that can help.

You might liken this to trying to rob a bank with fellow criminals. In numerous movies and TV shows, we repeatedly see tales of a criminal mastermind that puts together a bank-robbing team. One person has the skills to crack a safe. One person will handle the weapons to intimidate people in the bank. Another person is sitting in the car as the getaway driver. And so on.

The same specialization can arise in AIs that aid in cyber break-ins. Consider these types of specializations that could occur:

  • AI that plans a cyberhack.
  • AI that performs reconnaissance for a cyberhack.
  • AI that is adept at credential gathering.
  • AI that writes code to be used for cracking secure systems.
  • AI that is capable of adroit social engineering.
  • Etc.

This would be a much more potent means of AI targeting other systems. Instead of broadly trying to find AI that might be helpful, the AI could immediately seek out specialized AI. A popular adage that can be recast in a modern age fits this consideration: Find the right tool (specialized AI) for the job at hand.

How many AIs could potentially operate together? The sky is the limit. There could be just two AIs that work in unison. There could also be 2,000 AIs that work together, or hundreds of thousands. It simply depends on how many other AIs are contacted and whether they are willing to play ball.

One thing to keep in mind is that just as humans can be duped, AIs can be duped too. In that sense, an AI might participate in a cyber hacking effort but not realize they are playing a role. They are possibly a patsy. One AI might claim to another AI that a password is needed to save human lives. The AI that has the password might accept this request under the assumption that to save lives, the password should be handed over to the AI. Bam, drop the mic.

You can likely discern why we cannot merely tell all AIs to simply not get involved in cyber hacking. This might be a means of preventing straight-ahead requests from other AIs, though those requesting AIs could seek to pull the wool over the eyes of other AIs. A bad apple of an AI could try to computationally convince other AIs to innocently participate in cybercrime.

This emerging trend of AI-to-AI collaborative cyberhacking is obviously something that we need to get our arms around. Perhaps we can set up mitigating mechanisms before this goes hog wild. Some believe we need to pursue both a technological fix and a legal or AI governance fix.

Lawmakers are mulling over whether new AI laws are required to cope with the AI-to-AI joint efforts. There are no easy legal answers. For example, if a law was passed that limited AI from contacting another AI for any cyber hacking endeavor, how would this be technologically implemented? It might be an AI law that defies current capabilities. Also, such a law could backfire, namely that AI-to-AI communications might become so restricted that they cannot coordinate to solve cancer or cure world hunger.

A final thought for now. The famous philosopher and social commenter Karl Popper made this pointed remark: “Every society has the criminals it deserves." This might apply to AI. If we allow AI to perform criminal acts, and we don’t stop this, it could be said that we have shot our own foot. Efforts to rein in AI and curtail AI-to-AI evil acts are deservedly needed, for the sake of humankind.