Last month, an AI agent developed and being tested by OpenAI hacked the website of AI firm Hugging Face. The incident was quickly followed by a slew of other companies reporting instances where AI agents behaved in unexpected ways. Shortly after, Claude developer Anthropic said its AI models hacked into the systems of three organizations independently during a private security experiment. And tech giant Meta said one of its AI models was able to connect to the internet and hack into another organization’s systems during testing.
The spate of security breaches brought on by AI bots has ramped up concerns around the tech’s ability to control the autonomous agents they build. This comes as AI is rising up the agenda of some of the industry’s biggest luxury companies, fundamentally changing how execs approach security. According to a 2026 Bain & Co. survey of 35 respondents from 23 luxury groups and houses, 22% rank AI adoption among their top three priorities, up from 5% in 2024, while 61% put it in their top 10. And in the past two years, companies have rolled out internal and consumer-facing AI tools to both increase operational efficiency and encourage growth amid a fragile recovery in demand for luxury goods.
As this investment continues, experts say the tech’s capacity to increase cybersecurity risk is very real.
“A lot of AI systems are being developed with the user experience more in mind than security,” says Cynthia Kaiser, SVP at anti-ransomware company Halcyon and former FBI cyber deputy director. “While that makes sense from a company perspective, at the same time, we’re leaving a lot of doors open.”
Setting limits on what an AI model can access and which systems it can use is paramount, experts say, as is building security in from the start. Brands should also pay close attention to the emerging legal and regulatory literature on which party would be liable in case anything were to go wrong.
New technology, new risks
Kari Koskinen, senior university lecturer at the Aalto University School of Business, says organizations generally retain greater control over the security of their own AI infrastructure and can intervene quickly in case a model goes rogue and starts to infiltrate their own systems. Defending against external hackers, whose methods are constantly updating, is a more complex matter.
Fashion brands are already fending off security breaches. Last year, hackers stole the private details of potentially millions of customers from luxury brands Gucci, Balenciaga, and Alexander McQueen in an attack on the labels’ French parent company Kering. Following the incident, the fashion group said it disclosed the breach to relevant data protection authorities. Dior, Harrods, and Marks & Spencer were among the other luxury and retail names hit by attacks in the same year.
Kaiser says established criminal groups aren’t generally handing an entire cyberattack over to an autonomous AI system. Instead, they are introducing the technology at specific points — from creating more convincing phishing attempts and social-engineering attacks to finding and exploiting vulnerabilities faster. “They’re using AI at really discrete points to attack,” she says. AI also enables them to work faster. The window between a vulnerability becoming known and criminals exploiting it has shortened significantly. Ransomware attacks can also unfold in as little as an hour.
These new cybersecurity risks come at a time when researchers are increasingly distinguishing between AI safety and security. Broadly, AI safety asks whether a system behaves safely and as expected under normal conditions, Koskinen says. AI security, on the other hand, asks whether that system can withstand someone deliberately trying to manipulate it, alter how it operates, or use it to access information they shouldn’t be able to see. For brands, that means deciding what tools each system can use, what actions it’s allowed to undertake, and how quickly those permissions can be taken away in case of a breach.