Two North Korean hacking groups reportedly running their own large language models should put to rest any lingering assumption that generative AI's darker applications are hypothetical. According to recent reports, Kimsuky — a group tied to North Korea's Reconnaissance General Bureau — has set up a locally hosted LLM to automate parts of its campaign against South Korean targets, while a separate report describes a broader North Korean effort to build tools that analyze stolen data and scale up attacks. This isn't some exotic zero-day exploit; it's the same efficiency logic every enterprise is chasing, just pointed at espionage instead of customer service. The barrier to running a capable model locally has dropped enough that a sanctioned state actor with limited compute access can still stand one up. That should worry anyone who thought export controls and isolation would meaningfully slow this down.
What makes this sting a bit more is the same week China released DeepSeek R1 as a free, open web app that early comparisons suggest can match or beat OpenAI's top model on certain tasks. I've said before that DeepSeek's cost efficiency was the real story, not just its benchmark scores — and that story keeps compounding. When frontier-adjacent capability is free and downloadable, it doesn't stay contained to legitimate research labs. The same openness that let Chinese researchers release a genuinely admirable rare-disease DNA screening tool for equitable global access is the openness that lets a hacking group fine-tune something similar for reconnaissance. Dual-use isn't a new concept in AI, but the timeline between "impressive open release" and "adapted for attacks" keeps shrinking, and I don't think most policy conversations have caught up to that speed yet.
Meanwhile the enterprise side of AI is having its own accountability reckoning, just for less dramatic reasons. Salesforce reports that the average number of AI agents deployed by companies has nearly tripled in just 14 months — genuine, fast adoption beyond pilot purgatory. But scaling agents this quickly raises the uncomfortable question I keep coming back to: who's actually supervising them? Agents now hold company credentials, touch internal systems, and make decisions with real consequences, yet ownership and access control frameworks are lagging badly behind deployment speed. It's the same pattern as the security world, just with less malicious intent and more organizational sloppiness. A misconfigured agent with broad permissions can do plenty of damage without anyone hacking it at all.
By the way, Meta's entry into coding agents with Muse Code is a useful reminder that not every AI story needs a dramatic angle — it underperforms Claude Opus 5 but costs far less to run, which is exactly the trade-off most teams building with AI actually care about. Capability headlines get the attention, but cost curves and access controls are what determine how this technology actually gets used, for better or worse. The question worth sitting with isn't whether AI agents will keep multiplying — they clearly will, on both sides of the law — it's whether the governance structures around them can grow up fast enough to matter.