Security researcher James Kettle has demonstrated that the most effective AI-powered hacking techniques still require human guidance, challenging assumptions about fully autonomous cyberattacks. His experiment pushed artificial intelligence to its limits in offensive security and revealed a critical truth: the most dangerous AI hacking techniques still have humans in the loop.

What You Need to Know

AI models can automate parts of the hacking process, but they lack the strategic intuition and contextual judgment of experienced security professionals. The most effective attack scenarios emerged when AI handled repetitive tasks while humans made high-level decisions. This finding has immediate implications for both offensive and defensive cybersecurity teams.

How the Experiment Worked

Kettle, a well-known vulnerability researcher, designed a series of hacking challenges for AI systems. He used large language models to generate exploit code, identify weaknesses and suggest attack paths. The AI performed well on routine tasks such as scanning for known vulnerabilities and crafting basic payloads. But when faced with novel or complex environments, the models stalled or produced irrelevant results.

Loop Security, a research firm that tracks AI security developments, documented the outcomes. The firm reported that the AI's success rate improved dramatically when a human expert intervened to refine prompts, reinterpret error messages and adjust strategies. The combination of machine speed and human reasoning produced attacks that neither could achieve alone.

The Role of Human Expertise

Kettle's findings underscore a persistent limitation of current AI systems: they lack genuine understanding of the systems they attack. A model might generate a SQL injection payload, but it cannot grasp the business logic behind a web application or anticipate how a defender might respond. Human hackers fill that gap by providing context, creativity and intuition.

  • AI strengths: Speed, scalability and pattern recognition for known vulnerabilities.
  • Human strengths: Strategic thinking, adaptability and understanding of organizational defenses.
  • Combined impact: Efficient, targeted attacks that are harder to detect and defend against.

This human-in-the-loop model is not new, but Kettle's work quantifies its advantage. The most dangerous AI hacking techniques still have humans steering the process, making them more flexible and dangerous than fully automated alternatives.

Why This Matters

For cybersecurity defenders, the message is clear: AI-powered attacks are evolving, but they are not yet a threat that can be countered solely by automated defenses. Organizations must invest in human expertise as much as they invest in AI tools. Security teams that rely only on AI detection will miss the nuanced, adaptive attacks that human-machine teams can launch.

On the offensive side, red teams and penetration testers can use this research to improve their own methods. By integrating AI into their workflows, they can accelerate routine tasks and focus human effort on the most difficult problems. The result is a more effective testing process that better simulates real-world threats.

Loop Security warns that the gap between AI-only and human-AI attacks will shrink as models improve. But for now, the human element remains the critical factor that makes AI hacking techniques truly dangerous.

What This Means for the Industry

Kettle's experiment highlights a broader trend: AI is becoming a powerful tool in cybersecurity, but it is not replacing human judgment anytime soon. Security teams should prepare for a future where adversaries use AI as a force multiplier, not a replacement. The same principle applies to defense: AI can augment analysts, but it cannot replace the experience and intuition that come from years of hands-on work.