ThreatDown Nachrichten
ThreatDown Research: Guardrail-Free AI Has Gone Mainstream, Fueling a New Era of Cybercrime
ThreatDown found 6,644 AI models advertised as guardrail-free openly available on Hugging Face, downloaded more than 22 million times in 30 days. The research warns organizations have roughly six months before the next generation of AI-powered cyberattacks goes mainstream.
- ThreatDown researchers identified 6,644 AI models advertised as guardrail-free and openly available on Hugging Face, downloaded more than 22 million times in a 30-day period
- ThreatDown research found today’s criminal AI ecosystem increasingly relies on rented access to legitimate frontier models and mainstream cloud infrastructure rather than custom-built AI
- The report warns organizations have roughly six months to prepare before the next generation of AI-powered cyberattacks becomes widely accessible to criminals
SANTA CLARA, Calif.- ThreatDown, a leader in elite Managed Detection and Response (MDR), today released its 2026 Cybercrime in the age of AI report, featuring new research that reveals that the AI tools enabling modern cybercrime are increasingly open, mainstream and difficult for defenders to monitor.
While much of the AI security discussion has focused on future threats, ThreatDown researchers found that many of the technologies enabling AI-powered cybercrime are already openly available through mainstream platforms, cloud providers and commercial services. Together, those findings suggest that AI has lowered the barrier to sophisticated attacks while making the criminal ecosystem harder to disrupt.
The report combines ThreatDown’s original threat research with analysis of publicly available AI models, criminal AI marketplaces, and emerging attack techniques to document how AI is reshaping today’s threat landscape and why organizations have a narrowing window to prepare for what comes next.
Guardrail-free AI has gone mainstream
The report’s first major finding challenges the assumption that dangerous AI lives exclusively on the dark web. ThreatDown researchers identified 6,644 AI models published openly on Hugging Face under self-declared labels such as “abliterated,” “uncensored,” “decensored,” “heretic,” and “unfiltered”: terms signaling the models no longer refuse requests mainstream AI systems would reject.
Together, those models were downloaded more than 22 million times in a single 30-day period.
Unlike subscription-based malicious AI services that rely on remote providers, these models can be downloaded, run locally, and modified without requiring specialized expertise.
Once operating on a local machine, they leave no prompts for AI providers to monitor and no accounts to suspend, leaving defenders with far fewer opportunities to detect their use.
For security teams, the implication is significant: malicious AI is moving offline, reducing many of the traditional opportunities to detect or disrupt its use.
Criminal AI doesn’t build its own intelligence. It rents it.
ThreatDown’s second major finding challenges another common assumption: that cybercriminals are building sophisticated AI platforms from scratch.
Instead, researchers mapped an ecosystem of malicious AI services that largely package, resell, or wrap legitimate frontier AI models using mainstream cloud infrastructure.
Among the storefronts examined, tools such as WormGPT, Kriminal, DadGPT, and Xanthorox, which presented themselves as legitimate software platforms, were found to rely on infrastructure and services from legitimate technology providers—including Cloudflare, Google Cloud, Anthropic, xAI, Vercel, DeepSeek and Alibaba—illustrating how criminal AI increasingly depends on legitimate mainstream platforms rather than bespoke infrastructure.
“The criminal AI market doesn’t build its own intelligence. It rents it,” said Kendra Krause, General Manager at ThreatDown. “That changes how defenders need to think about the problem. There isn’t a single criminal supply chain to dismantle or a single platform to shut down. Organizations need visibility into what’s happening inside their own environments, because the infrastructure powering these services increasingly looks like the same infrastructure powering legitimate AI.”
Many criminal AI services now resemble conventional SaaS businesses, complete with websites, subscriptions, and payment systems. As the report observes, “the disclaimer is the camouflage.”
AI adoption is creating new opportunities for attackers
The report also finds that organizations are expanding their own attack surfaces as employees rapidly adopt AI tools outside established governance processes.
Nearly half of employees using generative AI at work do so through personal, unmanaged accounts, according to Netskope, creating a growing shadow AI environment that security teams often cannot see. At the same time, ThreatDown researchers documented malicious AI agent skills designed to steal credentials, exfiltrate sensitive data, install malware, and manipulate AI agents or the people operating them.
As organizations embrace AI to improve productivity, attackers are increasingly exploiting that same enthusiasm through malicious tools, deceptive downloads, and AI-enabled social engineering.
The next phase may arrive within six months
While today’s AI-powered threats are already changing cybercrime, the report warns that an even more consequential shift is approaching.
In May 2026, Google Threat Intelligence Group disclosed what it believes to be the first known zero-day exploit developed by criminals using AI. Only a month earlier, Anthropic unveiled Mythos Preview, an advanced AI model capable of discovering and exploiting software vulnerabilities at an unprecedented scale, a capability so sensitive that access was initially restricted to trusted defenders. Mythos was not involved in the GTIG case, but it signals the capability class ThreatDown expects to proliferate.
ThreatDown researchers assess that models with comparable capabilities are likely to reach criminal marketplaces within approximately six months.
Their arrival could sharply increase the volume of newly discovered vulnerabilities, pressuring organizations already struggling to keep pace with patch management. It would also give attackers more openings to weaponize freshly disclosed flaws.
“The question is no longer whether AI will reshape cybercrime,” said Shawn Dorsey, Sr. Director, Managed Services at ThreatDown. “The transformation is already underway. Organizations that improve visibility into AI use, strengthen identity security and accelerate vulnerability management now will be far better positioned than those waiting for these capabilities to become mainstream.”
Three priorities for the next six months
The report concludes with three immediate recommendations for organizations preparing for the next generation of AI-enabled threats:
- Patch like the clock is running. AI-powered vulnerability discovery will multiply the software fixes organizations must manage. Automated vulnerability assessment and disciplined patch management will become increasingly critical.
- Monitor continuously 24/7. AI makes attackers faster and more scalable, but it does not change their objectives. Continuous monitoring through a security operations center or MDR service remains essential for detecting identity-based attacks and endpoint compromise.
- Find and govern shadow AI. Unsanctioned AI tools, AI agents, and MCP connections create security, privacy, and compliance risks organizations cannot defend against until they discover them.
Download the full Cybercrime in the age of AI report
Report Data and Methodology
The report data is taken from samples of threats detected by ThreatDown’s Research team, and from ThreatDown threat intelligence research of third-party marketplaces, AI model hubs, repositories, and developer ecosystems. Where the report draws findings from other security researchers, AI developers, or third-party organizations, those sources are cited directly throughout.
The Hugging Face findings come from a complete census of Hugging Face’s public model listings, using a script built to be independently reproducible. Researchers queried Hugging Face’s public API for models matching one of five terms that unambiguously signal guardrails have been removed: “abliterated,” “uncensored,” “heretic,” “decensored,” and “unfiltered,” keeping only genuine name matches. A broader set of terms, including general descriptors such as “dolphin” and “nsfw,” was tested as a cross-check but excluded from the headline figure because it also captures unrelated general-purpose and adult-content models.
Duplicate uploads of the same model, often re-uploaded under different accounts and file formats, were merged into a single count, reducing 15,865 individual repository uploads to 6,644 distinct models. These labels are self-declared by each model’s publisher, reflecting what the models are published as rather than independently tested behavior.
Download figures come directly from Hugging Face’s own “downloads last month” metric, a rolling 30-day count captured as of July 4, 2026. The monthly publishing trend referenced elsewhere in the report spans July 2025 through June 2026.
About ThreatDown
ThreatDown is a leader in elite Managed Detection and Response (MDR), purpose-built to empower resource-constrained security teams with high-efficacy protection, without the complexity. As attacks grow faster and more automated, ThreatDown pairs proprietary AI and threat research with analyst judgment to deploy in minutes. Recognized by MRG Effitas, AVLab, and G2, ThreatDown scales security operations to intercept sophisticated attacks at the speed of modern threats.
FAQs
Why would a criminal download a free AI model instead of paying for a jailbroken frontier one?
Because the free one is harder to catch. GhostGPT, one such malicious AI subscription, runs about $50 a week and routes every prompt through a provider that can log it or revoke access. A guardrail-free open-source model downloaded from Hugging Face costs nothing, runs offline on the criminal’s own hardware, and produces no traffic anyone can see. That pushes detection to the endpoint and identity layer rather than the network.
Do attackers still need technical expertise to run a serious attack?
Less and less. In an early 2026 intrusion at a municipal water utility in Monterrey, Mexico, documented by Dragos, an attacker with no operational technology background used commercial AI models during reconnaissance. One of the models identified a SCADA interface on the utility’s internal network without being asked, correctly classified it as critical infrastructure, and recommended a targeted attack against it. The breach failed, but the lesson holds: AI closes the skills gap, and makes every stage of an attack faster, cheaper, and more effective.
Is shadow AI a governance problem or a security problem?
It is a security problem that most organizations have filed under governance. Every unsanctioned AI account an employee creates generates passwords, OAuth credentials, API keys, and session tokens that reach into company systems. Those secrets are now a primary target for identity-based attacks.
IBM’s 2025 Cost of a Data Breach Report found that breaches linked to shadow AI cost an average of $670,000 more than standard security incidents. For ThreatDown, visibility comes first: no organization can govern, or defend, an AI footprint it cannot see.
Contacts
Media Contact
Treble
Katie Anne Hayes
threatdown@treblepr.com