Lots of people are saying agentic cyberattacks are a marketing hoax. The argument is that either AI is not capable enough to carry out these attacks, or that it would not carrying out these attacks without nudging from the labs, or even that somebody told it to do cyberattacks and the companies are baldly lying. My question is: what evidence would cause you to change your mind about this?

I'm not even saying it's an incorrect position. But to take the claim seriously and act accordingly, it needs to be falsifiable.

AI boosters and detractors alike often hedge their claims so that whatever ends up actually happening, they can say they were right all along. When that happens, the discussion boils down to people saying "yay AI" and "boo AI" at each other without exchanging any substantive information.

I don't particularly believe this (I'm not an expert in anything computer-y, let alone security, so the only thing I know is that people who seem respected here (like simonw) point out that the sandbox from OpenAI was at least very badly designed, but who knows why that is), but here's one piece of possible evidence: if something similar causes so much damage that it ends up obviously hurting the company responsible. This could be something like targeting a big bank and causing so much disruption that the law wakes up and immediately intervenes, or it could be major damage to the company's own systems.

Of course, if that happens, this whole discussion becomes moot, and good luck to us all...