At the Black Hat security conference in Las Vegas, James Kettle presented findings on agentic AI's role in cybersecurity. His research highlights both the growing capabilities and current limitations of AI in developing new hacking methods. Kettle found that while AI is minimally capable, it requires human guidance to create fully autonomous attack paths. AI is a powerful tool when paired with human insight, helping to conceptualize and uncover new hacking strategies. Source: wired

Kettle, a longtime web security researcher, discovered a new vulnerability called Shared-Parser Confusion. This finding emerged from months of experiments using Anthropic’s and OpenAI’s models in September 2025. He aimed to explore AI’s theoretical security research capabilities but faced challenges as systems returned findings on obscure topics. To address this, Kettle narrowed his tests to his area of expertise, ensuring he had full control over the material and could verify AI outputs. Source: wired

Kettle’s experiments evolved as more powerful models debuted, leading to a productive research feedback loop. AI systems began generating findings at a rate far surpassing his own, creating a sense of urgency and FOMO about not exploring all leads. He emphasized the importance of pushing AI to its limits to understand where it fails and where human input is essential. Kettle noted that while AI couldn’t prove the Shared-Parser Confusion finding alone, it helped generate the hypothesis, which he confirmed. Source: wired