Agentic AI has fundamentally shifted the cybersecurity landscape by making it faster and easier to discover and fix software vulnerabilities. However, veteran security researcher James Kettle sought to explore a deeper question: Can AI develop entirely novel, abstract hacking methods from concept to execution?

The Limits of Autonomy and the Power of Partnership

Presenting his findings at the Black Hat security conference in Las Vegas, Kettle concluded that AI is currently minimally capable of devising new attack paths in a fully autonomous way. However, when paired with human guidance at key moments, AI becomes an extremely powerful partner in conceptualizing and uncovering new strategies that a human alone might never find.

The research, which began in September 2025 using the latest models from Anthropic and OpenAI, resulted in the discovery of a new class of vulnerability dubbed "Shared-Parser Confusion." This occurs when web servers use shared code to process both untrusted requests and trusted responses.

A New Research Methodology

Kettle found that by training models on his own research methodology, he could prevent the systems from attempting to pass off existing research as original. This approach created what he described as a "productive research feedback loop," with the AI generating notable findings roughly every two days—a rate far surpassing human output.

"It couldn’t do that on its own, but I would never have found that on my own for sure," Kettle noted regarding the Shared-Parser Confusion discovery.

While the AI was unable to prove the discovery autonomously, its ability to analyze proven findings and generate viable hypotheses for human evaluation represents, according to Kettle, the most significant long-term impact for both offensive and defensive hacking.