Blog
Research
Beyond the Human Horizon: Cogent Research Maps the Attack Paths Vulnerable to AI Swarms
Attacker economics kept the deepest, lowest-yield attack paths safe for years. AI agents can now exploit them, and they outnumber human-viable paths 3 to 1.
6 min read

Lines of attack that in enterprises that attacks could exploit emerge all the time as new vulnerabilities are published and environments change. In August 2026, the average enterprise gained 45 new attack paths to its crown jewel assets. Only 11 of them were paths a human intrusion team would realistically attempt. The other 34 were viable only for AI agents.
That's according to Cogent's latest research following the attack on Hugging Face in July in which a swarm of hundreds of coordinated AI agents compromised the platform. The swarm ran continuously, worked in parallel, and kept pursuing lines of attack a human team would have dropped. It performed over 17,600 actions.
To measure enterprise exposure to agent swarm attacks, Cogent Research analyzed 43 million assets and 1.2 billion vulnerability, misconfiguration, and identity findings across the hybrid environments of more than 50 Fortune 1000 organizations. We split every crown jewel attack path into two populations and tracked how fast each forms, how deep it runs, how long it persists, and how many tools it takes to see.
Key Findings
Three new machine-viable attack paths appear for every human-viable one
In August 2026, the average enterprise gained 45 new attack paths to crown jewel assets: 11 viable for human attackers and 34 viable only for AI agents. Human-viable path formation grew 38% year over year, from 8 to 11 per month. Machine-viable formation surged 386%, from 7 to 34, as the offensive capability of AI models advanced.
Machine-viable paths run twice as deep and span five technique domains
Machine-viable paths run at least twice as deep as human-viable paths on four depth dimensions: a median of 8 asset hops versus 4, and 5 trust-boundary crossings versus 2. The median machine-viable path spans five distinct technique domains, and 64% span four or more, a breadth that has historically required a team of specialists.
83% of machine-viable attack paths persist for more than 30 days
Machine-viable paths outlast human-viable ones: 83% versus 55% were present in the environment for more than 30 days. These paths are built from medium and low severity vulnerabilities, configuration weaknesses, and identity conditions that severity-based remediation policies rank below their thresholds. Chaining low and medium severity vulnerabilities alone produced 7% of the critical paths in our dataset.
64% of attack paths cross domains that no single security tool observes
The majority of attack paths move between endpoint, identity, network, and cloud infrastructure, and reconstructing the median critical path required correlated data from five security tools. Every finding along these paths existed in at least one console. No single product held enough of the environment to join them into a path.
The Human Horizon
Attack paths vulnerable to AI agents are different from those pursued by human teams across several key dimensions.
Human-viable paths: Paths whose depth, per-step yield, and technique requirements fall within the envelope of documented human intrusion activity. A professional intrusion team could be expected to attempt them.
Machine-viable paths: Paths that terminate at a crown jewel asset but exceed at least one human-economics threshold: too deep, too low-yield per step, or requiring more technique breadth than human operations sustain. Traversal is practical only for automated attackers.
The human horizon: The set of thresholds that separates the two populations. Each threshold is calibrated against published red team engagement data and DFIR incident reporting, including median steps to objective and time on target in documented intrusions.
Difference Between a Human-Viable Attack Path vs. a Machine-Viable Attack Path
A cyber attack using a swarm of AI agents can use the same techniques as those run by humans. What makes them different is continuous operation, parallel coordination across hundreds of agent instances, and indifference to effort.
Several hundred AI agents working in parallel can methodically try every technique on every asset, while a human adversary will develop hypotheses about what techniques may be successful, and prioritize a few of them. If they don’t succeed after a few tries, they give up and try another path.
Documented human operations typically abandon unproductive lines of attack around hop 3, which is the depth at which 82% of crown-jewel paths accessible to machines have yet to return secrets or privileges.

For each hop, we measured four forms of yield: credentials and keys made readable, privilege gained, newly reachable assets, and access to sensitive data. Human-viable paths deliver high yield from the first hops. Machine-viable paths return a fraction of that value per step.
In our assessment, low per-step yield is the reason these paths go unexploited, because an intrusion team operating under time and detection constraints has little incentive to continue a line of attack that returns almost nothing at each step. That constraint does not apply to automated attackers, for which the marginal cost of an additional hop approaches zero.

Three New Machine-Viable Attack Paths Now Appear for Every Human-Viable One
At every organization, new attack paths are emerging all the time as credentials are issued, permissions change, software is deployed, infrastructure is reconfigured and new vulnerabilities are discovered.
In August 2026, the average enterprise saw 45 new attack paths emerge to crown jewel assets. These are latent risks. Unless an attacker discovers them, nothing happens. But for every one attack path a human adversarial team could exploit, three emerge that are only viable for AI exploitation.

There has been a significant increase in the number of machine-viable attack paths this year. Human-viable attack paths increased 38% from 8 to 11 per month. But machine-viable attack paths surged 386% to 34 per month. While the number of new vulnerabilities is driving an overall increase in the number of viable attack paths, the greater increase in machine-viable attack paths is due to the rapid advancement of AI models. AI agents are much more capable of executing cyber attacks today than they were a year ago.
Machine-Viable Attack Paths Run Twice as Deep and Require a Greater Breadth of Attack Techniques
We measured attack path depth across four dimensions. Machine-viable paths were longer under every rule, and the difference was largest for action hops and trust boundary crossings.
Those hops carry the highest detection risk for a human operator: each action and each boundary crossing increases the likelihood of triggering an alert that ends the operation, which is why documented human intrusions concentrate in short paths.
The four dimensions we assessed include:
Asset hops: a move onto a new machine or resource, such as a workstation reaching a file server.
Action hops: one discrete technique execution, and a single asset can host several in sequence: dumping a cached credential and then replaying it are two actions on one system.
Privilege hops: any transition that raises the attacker’s effective identity tier, as when a standard user account is exchanged for a domain administrator credential.
Boundary hops: a crossing of a trust boundary, from one network segment into another or from the on-premises directory into the cloud tenant.

Across these dimensions, machine-viable attack paths are at least twice as deep. They also differ in the breadth of tradecraft they require. The median machine-viable path spans five distinct technique domains, such as web exploitation, Active Directory abuse, and cloud IAM manipulation, and 64 percent span four or more. In documented human intrusions, operations of that breadth have typically required multiple specialists. An automated attack can execute all of them within a single operation, at no additional staffing or coordination cost.
Machine-Viable Attack Paths Persist Longer in Enterprise Environments Due to Policy Gaps
In our analysis, 55 percent of human-viable and 83 percent of machine-viable critical paths had been present in the environment for more than 30 days.
Machine-viable paths are disproportionately composed of findings that severity-based remediation policies rank below their thresholds: medium and low severity vulnerabilities, configuration weaknesses, and identity conditions that no SLA covers. Each component finding is individually and defensibly deprioritized. The paths those findings form inherit that deprioritization and remain standing.

1 in 4 machine-viable paths is built entirely from findings below remediation thresholds
Machine-viable paths composed entirely of findings the organization’s own remediation policy never requires fixing: sub-SLA severities, informationals, accepted configurations. 26% of machine-viable paths contain no finding that current remediation policy requires fixing. Completing the remediation program as written does not affect them.
7% of critical paths were built by chaining low and medium severity vulnerabilities
Ranked individually, low and medium severity vulnerabilities fall below most remediation thresholds. Chained together, they produced 7 percent of the critical paths in our dataset. Severity-sorted remediation queues do not surface these combinations, because each component appears low risk in isolation.
The Majority of Attack Paths Span More Domains Than Any Single Tool Observes
Across our dataset, 64 percent of attack paths cross at least one domain boundary, moving between endpoint, identity, network, and cloud infrastructure.
Reconstructing the median critical path required correlated data from five security tools. This is a data aggregation problem faced by many enterprises with multiple point solutions covering different risk and asset types. The individual findings existed, in separate consoles, without the joins that make them a path.
What This Means for Security Teams
Remediation programs are often built around CVSS severity scores, which don't take into account the context of how attackers (human or AI) move through environments.
Closing those attack paths requires evaluating findings by the paths they form. That means joining data from the scanners, EDR, identity providers, and cloud platforms that each hold part of the picture, then validating which paths are traversable in the environment as it is actually configured. A path with eight hops and a single chokepoint can be severed with one fix, even when that fix would never rank on a severity-sorted list.
Attacker economics used to keep many of these paths hidden. Defenders now need to find and close them before an agent swarm reaches them. That's exactly what Cogent is designed for, AI that helps you defend against AI by finding and fixing the most critical attack paths before adversaries can exploit them.







