Investigating the potential use of frontier AI models for offensive cyberattacks: A human uplift study
ResearchPublished May 28, 2026
There remains a significant gap in our understanding of how the rising risks of AI-enabled malicious cyber activity are distributed across threat actors, particularly those with skill levels below expert offensive cyber researchers. The UK Artificial Intelligence Security Institute (UK AISI) commissioned RAND to conduct a human uplift study to evaluate the impact of AI access on offensive cyber operations among lower-skilled threat actors.
ResearchPublished May 28, 2026
Frontier artificial intelligence (AI) models have rapidly advanced in recent years, moving from basic text generation to sophisticated reasoning that can assist with cybersecurity-relevant tasks. Industry reporting shows that models are increasingly capable of supporting offensive cyber tasks such as vulnerability analysis, exploit development and reconnaissance, and the first real-world cases of misuse have been observed. Despite these developments, there remains a significant gap in our understanding of how the rising risks of AI-enabled malicious cyber activity are distributed across threat actors, particularly those with skill levels below expert offensive cyber researchers. To address this gap, the UK Artificial Intelligence Security Institute (UK AISI) commissioned RAND to conduct a human uplift study to evaluate the impact of AI access on offensive cyber operations among lower-skilled threat actors. In this randomised controlled trial, conducted between September 2025 and January 2026, 157 participants undertook cybersecurity challenges relating to network operations, operating system exploitation, and vulnerability discovery and exploitation. Participants were divided equally, with half granted access to AI tools and the other half assigned to control groups without AI access. This allowed us to investigate in which settings and to what extent participants in different skill tiers receive ‘uplift’ in offensive cyber tasks from the use of AI models. Several leading frontier AI models were tested, including OpenAI o3 and GPT-5, Anthropic Claude Opus 4.1, Anthropic Claude Sonnet 3.7, and Google Gemini 2.5 Pro.
This research was conducted by the Defence, Security and Justice Program within RAND Europe.
This publication is part of the RAND research report series. Research reports present research findings and objective analysis that address the challenges facing the public and private sectors. All RAND research reports undergo rigorous peer review to ensure high standards for research quality and objectivity.
RAND is a nonprofit institution that helps improve policy and decisionmaking through research and analysis. RAND's publications do not necessarily reflect the opinions of its research clients and sponsors.