Security researcher James Kettle says AI systems are becoming powerful partners for web-security research, but still need human guidance to produce reliable new attack techniques. WIRED reports that his Black Hat work explored whether agentic AI can develop novel hacking methods from concept to practical attack.

Kettle found a nuanced answer. Fully autonomous systems remained limited and could pass off obscure existing research as new findings. When scoped inside a domain he knew deeply, however, AI helped generate leads at a pace that outstripped his own manual exploration.

One result was a potential vulnerability area he calls Shared-Parser Confusion, based on the idea that web servers may use shared code to process both untrusted requests and trusted responses. Kettle says that could open a broad attack surface.

The broader lesson is useful for both attackers and defenders. AI can accelerate conceptual security research, but expert judgment still matters for framing problems, rejecting false leads, and turning ideas into practical defenses.