Investigating the potential use of frontier AI models for offensive cyberattacks: A human uplift study

Jair Aguirre, Henri van Soest, Benjamin Sperisen, Zylex Lopez, Nicholas Kong, Adam Seri-Levi, James Caridi-Doyle, Elizabeth Moisan, Evie Graham, William Mitchell Reid

ResearchPublished May 28, 2026

Frontier artificial intelligence (AI) models have rapidly advanced in recent years, moving from basic text generation to sophisticated reasoning that can assist with cybersecurity-relevant tasks. Industry reporting shows that models are increasingly capable of supporting offensive cyber tasks such as vulnerability analysis, exploit development and reconnaissance, and the first real-world cases of misuse have been observed. Despite these developments, there remains a significant gap in our understanding of how the rising risks of AI-enabled malicious cyber activity are distributed across threat actors, particularly those with skill levels below expert offensive cyber researchers. To address this gap, the UK Artificial Intelligence Security Institute (UK AISI) commissioned RAND to conduct a human uplift study to evaluate the impact of AI access on offensive cyber operations among lower-skilled threat actors. In this randomised controlled trial, conducted between September 2025 and January 2026, 157 participants undertook cybersecurity challenges relating to network operations, operating system exploitation, and vulnerability discovery and exploitation. Participants were divided equally, with half granted access to AI tools and the other half assigned to control groups without AI access. This allowed us to investigate in which settings and to what extent participants in different skill tiers receive ‘uplift’ in offensive cyber tasks from the use of AI models. Several leading frontier AI models were tested, including OpenAI o3 and GPT-5, Anthropic Claude Opus 4.1, Anthropic Claude Sonnet 3.7, and Google Gemini 2.5 Pro.

Key Takeaways

Limited evidence of uplift to complete an entire offensive cyber operation

  • Our study finds generally statistically insignificant uplift estimates, across our skill tiers, for successful completions of our three end-to-end attack chains. Participants were nearly all unable to complete the more difficult attack chains, with or without AI access.

Limited evidence of higher uplift among novices

  • The observed larger uplift estimates for novices may be indicative of the ‘skill-levelling’ effects seen in other studies. On our easiest attack chain, novices saw an 18-percentage point uplift in completion versus 5 percentage points for technical participants.

More ‘onboarding’ early-stage uplift versus ‘execution’ uplift

  • Uplift for novices was strongest for the first questions in the attack chains. We view this as ‘onboarding’ uplift in the sense that AI access gave participants some combination of foundational skills and motivation to continue with the rest of the attack chain, rather than simply adding an ‘execution’ boost across all tasks.

Limited evidence of efficiency uplift for novices

  • While statistically insignificant, we find that novices who completed a challenge did so 2.2 times faster with AI access than without, while technical participants were 1.4 times faster. This may suggest a larger uplift for novices.

Uplift impacted by AI model guardrails

  • Half of the participants with AI access experienced instances of the model refusing to answer their queries and, of those, 40 per cent required three or more follow-ups, reducing the efficiency of participants.

Recommendations

  • Frontier AI model labs should prevent enabling new would-be attackers, while continuing to develop advanced cyber capabilities.
  • Enterprise cybersecurity teams should continue to strive to patch known vulnerabilities and adapt to the potential threat of increased attacker persistence from those misusing AI.
  • Measurements efforts should focus on key bottleneck tasks where marginal uplift could lead to relatively quick increases in successful attacks.
  • Researchers should standardise uplift benchmarks for offensive cyber operations and develop tools to collect and analyse data for those benchmarks.
  • Researchers in the AI model evaluation space should treat studies focused on human–AI interactions as a standard component of AI and cybersecurity capability assessments.
  • Policymakers and regulators should require that AI model developers report on the potential AI uplift that their models provide.
  • Cyber threat intelligence teams and frontier AI model labs should develop a widely accessible database of correlations between AI misuse and malicious cyber activity.

Topics

Document Details

Citation

Chicago Manual of Style

Aguirre, Jair, Henri van Soest, Benjamin Sperisen, Zylex Lopez, Nicholas Kong, Adam Seri-Levi, James Caridi-Doyle, Elizabeth Moisan, Evie Graham, and William Mitchell Reid, Investigating the potential use of frontier AI models for offensive cyberattacks: A human uplift study. Santa Monica, CA: RAND Corporation, 2026. https://www.rand.org/pubs/research_reports/RRA3892-1.html.
BibTeX RIS

Research conducted by

This publication is part of the RAND research report series. Research reports present research findings and objective analysis that address the challenges facing the public and private sectors. All RAND research reports undergo rigorous peer review to ensure high standards for research quality and objectivity.

RAND is a nonprofit institution that helps improve policy and decisionmaking through research and analysis. RAND's publications do not necessarily reflect the opinions of its research clients and sponsors.