Google’s Threat Intelligence Group reports that adversaries have evolved from basic AI prompting to deploying autonomous agentic AI systems for cyberattacks. Threat actors used multi-agent frameworks to plan, build, and execute a mass credential-harvesting campaign in under six hours with minimal human intervention. State-sponsored groups, cybercriminals, and information operations actors are integrating AI across the full attack lifecycle, from reconnaissance to post-exploitation, while also hijacking enterprise cloud infrastructure to sustain unauthorized AI workloads.