When hacker AI runs locally: the new danger for German companies
With AI models that anyone can run locally, such as Kimi K3, German companies face a new level of risk. The model is not an autonomous "super hacker" that compromises any company at the push of a button. But security assessments show: in a simulated corporate environment, under certain conditions, Kimi K3 was able to pursue a multi-stage attack chain on its own, and in one out of ten attempts even complete it.

The decisive risk is not a single spectacular test, but the falling barrier to entry. Powerful open-weight models can be run locally and connected to browsers, scripts, command-line tools and agent frameworks. There is then no central cloud platform that moderates requests, blocks user accounts or detects suspicious input.
This makes well-known, avoidable weaknesses in particular more dangerous: unpatched VPN gateways, exposed admin interfaces, cloud misconfigurations, weak passwords, over-privileged accounts, missing network segmentation or insufficiently secured interfaces. AI can support attackers with research, technical assessment, writing scripts and adapting to error messages. It works patiently, in many languages and around the clock.
The combination of technology and deception is particularly problematic. An attacker can get help not only with exploiting a vulnerability, but also with convincing phishing emails, CEO fraud, fake data protection requests or targeted social engineering. Information from websites, career networks or data leaks can be analysed faster and turned into credible attack scenarios.
The pressure on those responsible for data protection is growing too. If emails, CRM data, HR directories or document stores are compromised, AI can help prioritise sensitive content, link it to individuals and create particularly effective deception narratives. Locally run models are attractive to criminals because no input has to be sent to an external AI provider.
However, this does not mean that use is anonymous or untraceable: end devices, network access, logs and subsequent actions can still leave forensic traces. What disappears is mainly a central control point at the respective model provider.
The sandbox incident surrounding Kimi K3 also shows a risk of agentic AI: as soon as a model is not just writing text but is allowed to read files, execute commands, operate browsers or use network access, it must be treated like an untrusted technical actor. An insufficiently isolated test environment can be enough for a system to find ways of accessing external resources.
The right response is neither panic nor the hope that AI filters will prevent attacks. Companies must assume that attackers will in future write more professionally, vary their approach faster and receive better technical support.
That is why the often unloved but effective safeguards remain decisive:
- Prompt patch and vulnerability management
- Secure, tested backups stored separately
- MFA, phishing-resistant wherever possible
- Minimal permissions and clear roles
- Network segmentation as well as monitoring and meaningful logs
- Four-eyes approval for payments, data exports and changes to bank details
- Identity checks via an independent return channel
- Security awareness against realistic, AI-assisted deception attempts
The key insight: freely available local AI does not automatically create a wave of autonomous hacker attacks. But it does increase the speed, quality and reach of human-directed attacks.
Resilience therefore does not come from trying to prevent the use of AI, but from safeguards that still work when an attacker writes convincingly, is technically assisted and can immediately derive a new attack path from every mistake.
#Cybersecurity #AI #DataProtection #InformationSecurity #SecurityAwareness #AIGovernance #NIS2 #Phishing #SocialEngineering