What this means for agencies and digital teams
If you run a digital agency, a product team, or any organization that builds on top of AI APIs, the instinct is to read this story as something happening far away. A lab-level problem. A research problem. Not yours.
That instinct is wrong, for a few reasons.
The capability gap is closing faster than most teams are tracking. A model that clears the Critical threshold for cybersecurity uplift today is not available to your competitors either. But the generation below it is. Models that score High, models that are already publicly available, already give non-expert users meaningful assistance in identifying software vulnerabilities, writing exploit code, and probing authentication systems. That is not hypothetical. Security researchers have documented this repeatedly.
Your attack surface has changed shape. A few years ago, the main AI risk for most agencies was data privacy: what goes into a prompt, who can see it, where it is stored. That risk has not gone away. But it now sits alongside a second category: AI as an attack tool aimed at your clients. If you build on public APIs, integrate AI into client products, or manage infrastructure on their behalf, you are part of a supply chain that a well-prompted model can help an attacker map.
Most vendor contracts do not cover this. Standard SaaS and API agreements were not written with AI-assisted attack scenarios in mind. When you sign an integration contract today, the risk language almost certainly lags the actual capability of the models your vendor is running. That is a gap worth closing before you need to explain it to a client.