Martin Lipton is a Founding Partner at Wachtell, Lipton, Rosen & Katz. This post is based on a Wachtell Lipton memorandum by Mr. Lipton, Kevin S. Schwartz, and David M. Adlerstein
As advanced AI models — and autonomous AI “agents” — grow more capable, so do the associated corporate cybersecurity risks. Atincreasingly modest cost, AIsystems can now identify and exploit latent software vulnerabilities, such as by planting malicious code or stealing data, at a speed and scale beyond the reach of human hackers or conventional automated tools. AI also creates new points of vulnerability: a corporation’s own AI agents, if compromised, can become a gateway to sensitive data and to operational or payment systems. The risk of deepfakes (AI-generated voice or video impersonations) is also growing more acute; in one recent test, 48% of video call participants believed an AI agent was a live human. In 2025 alone, the FBI Internet Crime Complaint Center received over 22,000 cybercrime complaints with an AI-related descriptor, with reported losses nearing $900 million. In April of this year, an advanced AI model reportedly uncovered thousands of previously undetected software security flaws, including in a widely used and well-defended open source operating system, and in July, a group of autonomous AI agents worked together to hack a company’s systems.

