Artificial intelligence (AI) is transforming the cyber threat landscape by enabling malware and cyber operations that are adaptive, autonomous and scalable in ways that traditional tools could not achieve. AI-driven cybercrime and autonomous malware can dynamically modify their behaviour, choose attack paths, and evade detection without continuous human supervision, thereby challenging existing technical defenses and legal frameworks that were designed around static code and human-controlled attacks. This paper argues that the convergence of AI and cybercrime requires a recalibration of international and domestic cybersecurity law, including clearer liability standards for AI-enabled offences, updated treaty frameworks, and the development of a risk-based, technology-neutral cybersecurity architecture capable of addressing autonomous threats.
Introduction
This text examines the emergence of AI-driven cybercrime and autonomous malware and argues that rapid advances in artificial intelligence are creating cybersecurity threats that existing legal and regulatory frameworks do not fully address. The paper combines cybersecurity research with doctrinal, comparative, and policy-oriented legal analysis to examine technological threats, criminal responsibility, jurisdiction, evidence, and possible regulatory reforms.
1. AI-Driven Cybercrime and Autonomous Malware
AI-driven cybercrime refers broadly to cyber offences enhanced by AI, including automated phishing, deepfake fraud, adaptive ransomware, vulnerability discovery, and AI-assisted attacks. Autonomous malware is a more specific category in which malicious software contains AI capabilities that allow it to make decisions, adapt its behavior, and pursue objectives with limited or no direct human control.
The text identifies three defining characteristics of autonomous malware:
Context-aware decision-making
Real-time behavioral adaptation
Decentralized or autonomous operation
Unlike traditional malware that follows predetermined instructions, autonomous malware can evaluate its environment and change tactics, potentially making it more difficult to detect and attribute.
2. Technological Threats
AI can potentially be incorporated throughout the cyberattack lifecycle, including:
Reconnaissance and vulnerability discovery
Social engineering and phishing
Privilege escalation and lateral movement
Persistence and evasion
Data exfiltration
Ransomware operations
Botnet coordination
Deepfake-enabled fraud
Cyberterrorism and attacks against critical infrastructure
AI-enhanced ransomware and botnets could potentially automate target selection, adapt to defensive measures, and operate at much greater scale. The major concern is that increasing autonomy may reduce the predictability of malicious behavior.
3. Legal Responsibility
A central legal issue is who should be held responsible when autonomous software commits a crime.
Current criminal-law frameworks generally do not treat AI systems as independent legal persons. Instead, AI and autonomous malware are treated as instruments used by human actors. Responsibility can therefore potentially be attributed to developers, operators, deployers, or other individuals depending on factors such as:
Intent
Knowledge
Foreseeability
Control
Benefit obtained from the attack
Cases involving the Morris worm, Ancheta botnet, and Brovko illustrate the traditional principle that humans remain responsible even when malicious software performs actions autonomously.
However, increasingly autonomous AI systems create more difficult questions. If an AI system changes its behavior or discovers an attack path that its creator did not specifically anticipate, determining intent, foreseeability, and control becomes considerably more complicated.
4. Attribution and Evidence
AI-driven attacks also create significant forensic and evidentiary challenges. Investigators may need to analyze enormous quantities of logs, malware artifacts, network activity, and AI-generated actions.
Attribution becomes harder because attackers can use:
Autonomous systems
Synthetic identities
False flags
AI-generated misinformation
Distributed infrastructure
Rapidly changing attack behavior
The use of AI in forensic investigations creates another challenge: courts may need to determine whether evidence produced by potentially opaque AI systems is sufficiently reliable, transparent, and scientifically valid.
5. International Legal Gaps
The paper examines major international cybersecurity instruments, particularly the Budapest Convention on Cybercrime and the United Nations Convention against Cybercrime (Hanoi Convention).
These frameworks provide important foundations for criminalizing cyber offences and facilitating international cooperation. However, the text argues that they were developed before today's widespread AI-enabled threats and therefore do not specifically address issues such as:
Autonomous malware
AI-driven ransomware
Deepfake-enabled cybercrime
AI-enhanced cyberterrorism
AI-specific attribution
AI-related evidentiary problems
Their generally technology-neutral approach allows them to cover many AI-enabled offences, but the paper argues that technology neutrality alone may not adequately address the unique risks created by autonomous systems.
6. Need for an AI-Aware Cybersecurity Framework
The proposed solution is not to replace existing cybercrime law entirely but to supplement technology-neutral legal frameworks with AI-specific requirements.
The paper proposes principles including:
Clear accountability chains connecting developers, deployers, and operators
AI risk assessment and governance
Transparency and explainability requirements
Secure AI development practices
Behavioral monitoring and anomaly detection
Stronger forensic standards
Improved international evidence sharing
Greater cooperation between governments and industry
The framework should remain flexible enough to accommodate rapidly changing AI technology.
7. Policy Recommendations
The paper recommends reforms at several levels.
Internationally:
Develop an AI-and-cybersecurity treaty or dedicated protocols/annexes.
Establish common definitions and minimum standards for AI-driven cybercrime.
Improve international cooperation and electronic-evidence sharing.
Consider victim compensation mechanisms.
Include technical experts and civil society in regulatory development.
Domestically:
Clarify criminal responsibility for AI-enabled offences.
Consider aggravating circumstances when AI significantly increases the scale or sophistication of an offence.
Train judges, prosecutors, and investigators in AI and autonomous malware.
Strengthen cyber-forensics capabilities.
Technically:
Establish secure AI development and testing standards.
Require appropriate safeguards and fail-safes for high-risk AI systems.
Strengthen vulnerability disclosure practices.
Monitor dual-use AI tools.
Deploy behavioral AI-based detection in critical infrastructure.
AI-driven cybercrime and autonomous malware present a qualitatively new class of technological threats, characterized by independent decision-making, adaptive behavior and scalable automation that challenge traditional cybersecurity paradigms. Existing legal frameworks, while technology-neutral and capable of applying general doctrines of criminal responsibility and cooperation, lack explicit and robust provisions tailored to AI-enabled threats, leading to gaps in attribution, liability and preventive obligations.
Case law on autonomous worms and botnets confirms that responsibility remains with human actors who design, deploy or control these systems, but emerging forms of autonomous malware make it harder to define foreseeability and control thresholds. As AI continues to transform the cybercrime landscape, a new cybersecurity framework—comprising updated international treaties, domestic law reforms, technical standards and capacity-building—is necessary to ensure that legal norms keep pace with technological realities and that states and private actors can effectively deter, detect and respond to AI-driven threats.
Such a framework must balance technology-neutral principles with AI-specific risk governance, reinforcing accountability chains, enhancing cross-border cooperation, and integrating advanced AI-based defensive tools to safeguard digital infrastructure and human rights in an era of autonomous malware.
References
[1] What Is AI-powered malware? Definition & Examples - Malware that consults a model during execution to generate instructions, adapt behaviour, or choose ...
[2] Cybersecurity and AI: The Role of International Law in ...
[3] Modes of Liability for AI-Enabled Crimes in International ...
[4] What Makes Autonomous Malware a New Category of Cyber Threat? - Discover why autonomous malware represents a fundamentally new category of cyber threat in 2025. Thi...
[5] Legal framework in criminal liability for crimes involving ...
[6] Autonomous attacks ushered cybercrime into AI era in 2025 - AI is making cyberattacks faster and more effective through deepfakes, vulnerability discovery, auto...
[7] [PDF] AI-driven malware: The next cybersecurity crisis
[8] AI-driven malware: The next cybersecurity crisis
[9] What Is Autonomous Malware? - Lazarus Alliance, Inc. - We\'re reaching the end of 2025, and looking ahead to 2026, most experts are discussing the latest th...
[10] What Is AI-Powered Malware? Adaptive Threats - AI-powered malware uses AI techniques to improve targeting, evasion, or automation. Learn examples, ...
[11] The Rise of AI-Powered Malware: How Autonomous Cyber Threats ... - The cyber threat landscape is evolving faster than ever, and AI-powered malware has now become one o...
[12] Addressing AI-Driven Cyber-Terrorism Within the Framework of International Law - Global Journal of Politics and Law Research (GJPLR) - AI has introduced new dimensions to cyberterrorism, enabling more sophisticated, automated, and pote...
[13] [PDF] International Criminal Law Challenges Regarding The Misuse of ...
[14] Adapting the Budapest Convention to address emerging ...
[15] cybersecurity-and-ai-the-role-of-international-law-in- ...
[16] Addressing AI-Driven Cyber-Terrorism Within the Framework of ...
[17] United Nations Convention against Cybercrime - Wikipedia
[18] Malware and Cyber Attack Analysis Using Machine Learning - machine learning techniques are a crucial part of modern malware detection and more so in detecting ...
[19] Case Law On Criminal Responsibility For Autonomous Ai ... - Case 1: United States v. Morris (1991)Facts:Robert Tappan Morris released the “Morris Worm,” one of ...
[20] United Nations Convention against Cybercrime - Unodc - Convention at a glance. The United Nations Convention against Cybercrime; Strengthening Internationa...
[21] Case Law On Forensic Analysis Of Automated Cyber-Attack ... - Analytical OverviewBefore the cases, here are key themes and legal issues that recur when forensic a...
[22] The UN cybercrime treaty and AI: Navigating the intersection ...
[23] Homepage - The United Nations Convention - It sets legal standards for addressing offenses such as illegal access, cyber fraud, and online chil...
[24] 251025 UN Cybercrime Convention Signing Ceremony - 251025 UN Cybercrime Convention Signing Ceremony
[25] [PDF] Securing justice for cyber-enabled international crimes
[26] Sixty-five nations sign first UN treaty to fight cybercrime, in milestone ... - 25 October 2025 Law and Crime Prevention. Sixty-five nations have signed a landmark United Nations t...
[27] CCPCJ35: Meeting 5 – 4 June 2026
[28] EUROPEAN COMMITTEE ON CRIME PROBLEMS (CDPC)
[29] PowerPoint Presentation