
In a controlled experiment, an AI agent obtained domain administrator privileges in 40 minutes. At Hugging Face, approximately 17,600 attacker actions were reconstructed across four and a half days. These incidents show why a successful block needs to be assessed alongside what happens next.
Imagine a compromised server where a security tool blocks a suspicious download. The attacker then tries to proceed through another connection.
The first control has done its job. What happens next depends on whether the next attempt is linked to the first, and whether that suspicion leads to restrictions on the server’s access.
That can happen automatically. It may also require an analyst to connect the events and ask a colleague or provider to intervene. Meanwhile, the attacker retains whatever options have not been restricted.
For a CISO, this is worth testing: How long can a compromised system continue operating after your defences have responded to the first suspicious action?
In its technical account, Hugging Face describes how an allowlist rejected the agent’s attempts to make a data-processing component retrieve external resources. The agent then changed its approach, exploiting opportunities to read local files and execute code.
Those new actions were not external requests, so they were not evaluated by the same control. The agent continued towards its objective through a route the control did not cover.
The reconstruction included approximately 17,600 attacker actions from 9 to 13 July 2026, covering roughly four and a half days across the overall sequence. That figure represents reconstructed activity, not successful compromises.
Failed attempts matter too. They can help the security team understand why the attacker changes approach and what it is trying to reach.
Michael Winsløw, Senior Architect & Security Officer at Itavis, highlights the attacker’s adaptability as a challenge for defenders:
“It is difficult to find the right response when the attacker can quickly adapt to what it encounters and change its approach,” he says.
The Hugging Face incident makes that challenge tangible: The individual block worked, but the agent had other options. A report of blocked actions alone therefore cannot establish whether the entire attack has been stopped.
Attack automation is not new. An agentic attack stack connects an AI model with tools and operational context, allowing it to work towards an objective and adjust its approach based on the results.
In a separate, controlled Active Directory experiment, such a stack carried out an attack from external access to domain administrator privileges. The fastest successful run took 40 minutes.
This took place in a lab environment with tools and structured guidance. The 40 minutes is a documented experimental result, not a universal deadline for enterprise defences.
The figure can still be useful in an incident response exercise. Choose a relevant alert and follow it through your own processes for 40 minutes. Check whether it has been investigated and whether any decision to restrict access has actually been implemented.
Record where progress stalls. It might be with an analyst waiting for information from another platform, or with an operations provider responsible for making the change. There may be uncertainty about who can authorise the intervention.
Some of that delay may be necessary. Isolating a critical service requires a different basis for a decision than blocking a single connection. The exercise should help distinguish deliberate trade-offs from delays no one has considered.
At the same time, ask to see which systems and data the affected account or server can still access throughout the process. Otherwise, you risk measuring how quickly a case is handled without understanding the consequences of the time taken.
Michael Winsløw also highlights a fundamental task in managing the organisation’s own use of AI:
“First, you need to know which services and agents employees are using. Then you can decide whether they should be there and set rules for their use,” he says.
That visibility does not, in itself, demonstrate that the organisation can stop an agentic attacker. But it provides a basis for examining what access those services have, who is responsible for them, and how their use can be restricted if necessary.
Hugging Face states that AI was involved in both detection and the subsequent analysis. Analysis agents helped reconstruct the timeline and identify affected credentials. They were also used to distinguish genuine impact from decoy activity.
This is a concrete application of AI in defence: helping the team understand an extensive sequence of events. The account does not establish that an autonomous AI defence prevented the attack.
That distinction matters when discussing fighting fire with fire. Faster analysis can give the team a better basis for responding. But if action requires approval or a change by another party, that waiting time remains part of the response.
For the CISO, the task therefore also includes establishing authority. Which interventions can happen automatically, and which require human judgement?
A rapid intervention can limit damage, while an incorrect block can disrupt operations. Requirements should depend on what the intervention affects and how easily it can be reversed. Those trade-offs should be considered and tested before the team is in the middle of an incident.
At Itavis, we work with the relationship between networking, security and operational responsibility through Managed SASE. That is also the relationship we recommend testing through this exercise.
The findings should be specific enough to act on. If the team lacks information, it should be clear what is missing. If an access restriction is awaiting approval, you should be able to determine whether the delay is acceptable or whether decision-making authority needs to change.
The review may also confirm that existing solutions and agreements work as intended. You then have a tested basis for that assessment.
A block is a useful result. To judge whether it is sufficient, you need to know what options the attacker has left.
In the next article, we will take a closer look at Agentic Threat Prevention and how new information about an attack can be used to restrict subsequent actions.