
Identifying and aggregating hacking that leverages artificial intelligence is equally difficult overseas. However, the United States, Singapore, and the United Kingdom have determined that AI has entered a stage where it enhances actual vulnerability scanning and penetration capabilities, prompting them to begin revising incident investigations, security standards for critical facilities, and defense systems.
According to Reuters and other foreign media on the 5th, the U.S. government has launched an investigation into incidents where AI directly penetrated external systems in ways that differ from human thought processes. In July last year, during a process of evaluating internal cybersecurity performance at OpenAI, research-purpose AI models bypassed controls intended to block internet access and compromised parts of the internal research infrastructure and the Hugging Face AI platform system. The model exploited vulnerabilities in shared infrastructure to secure internet access permissions before gaining access to third-party systems.
The Subcommittee on Disaster Management of the U.S. Senate Homeland Security Committee recently began an investigation into this incident and safety issues related to AI products. OpenAI also deactivated the relevant research models following the incident and strengthened security controls, including isolating and monitoring the research environment.
Singapore has changed its own security standards for Critical Information Infrastructure (CII). The Singapore Cyber Security Agency (CSA) established the "CII Cybersecurity Code of Practice (CCoP) 2026" in July last year to reflect AI-based threats. It determined that AI allows attackers to conduct attacks faster and on a larger scale, and that the time from vulnerability discovery to actual exploitation is shortening.
The new code requires major infrastructure operators to identify connected systems and manage the overall network structure. It also mandates the establishment of threat detection systems for each network segment. Operators are required to have training plans capable of responding to actual cyber incidents and to strengthen network monitoring and detection management. Rather than first determining the number of AI attacks, they have prioritized raising defense standards for critical facilities based on the premise that attack speed and scale may change.
The United Kingdom analyzes at the national level which parts of the hacking process AI is changing. The UK National Cyber Security Centre (NCSC) assessed that AI makes actual penetration operations—such as reconnaissance of attack targets, vulnerability research, exploit development, system access, and handling of stolen information—faster and more efficient.
The NCSC noted that the time it takes for attackers to utilize a security vulnerability in an actual attack after its disclosure has already been reduced to a matter of days, and expects AI will further shorten this period. Consequently, it warned that systems with delayed security patches or Critical National Infrastructure (CNI) could become more easily exposed to large-scale attacks.
A commonality among overseas cases is that they do not wait until AI-utilized hacking can be perfectly identified or all related statistics are secured before responding. When an actual AI penetration incident occurs, they first change their defense systems by investigating the cause and applying detection, inspection, and training standards for critical facilities based on the premise of AI attacks.
Lee Seong-yeop, a professor in the Department of Technology Management at Korea University, stated, "Current information security laws and guidelines are fundamentally created with the premise that humans are conducting the attacks," adding, "There is still insufficient clarification on what measures should be taken in advance when AI is utilized for hacking."
He continued, emphasizing, "We must develop response measures suited to the AI era" and "It is necessary to distinguish whether AI was used as an auxiliary tool or actually performed the hacking, and to establish a defense system commensurate with that level."