From Jailbreaks to Agentic Attacks: The Evolution of AI Abuse

AI abuse is evolving beyond copy-and-paste jailbreak prompts. New Bitsight Threat Intelligence research shows how threat actors and cybercrime-adjacent users are experimenting with prompt injection, obfuscation, multi-model workflows, AI coding agents, and access to tools that can turn unsafe model behavior into real-world security risk.

This report traces that evolution from early jailbreak communities and underground markets to MCP abuse, agentic execution, and AI-assisted cyber operations.

Key takeaways

  • AI abuse is moving from prompt manipulation toward agentic execution
  • Jailbreaks are becoming repeatable workflows built around obfuscation, model routing, testing, and retry logic
  • Prompt injection can create greater risk when AI agents can access files, run commands, or call enterprise tools
  • MCP-connected tools expand the potential impact of indirect prompt injection and unsafe agent behavior
  • Threat actors are increasingly interested in AI capabilities, including private prompts, uncensored models, API access, coding agents, and stolen AI assets

Download the report to explore how AI abuse is evolving and what security teams should monitor as AI systems become more connected, autonomous, and operational.

Threat actors are learning where AI systems have power. In agentic environments, what the model can do may matter more than what the model can say.

-Emma Stevens, Senior Threat Intel Advisor, Bitsight