What happens when malware no longer has to wait for a human attacker to tell it what to do next?

That question is becoming much less theoretical. On September 22, 2026, Cisco Talos published research on CLOSEDQUORUM, which Talos describes as the first publicly documented Windows implant to delegate tactical command-and-control decisions to a panel of large language models. Instead of waiting for continuous instructions from an attacker, the malware can ask AI models what action to take next and execute the selected decision.

For business leaders, the important issue is not whether this specific malware is attacking companies today. Talos says it has not confirmed CLOSEDQUORUM deployment in the wild, and the public build it analyzed contained placeholder API keys. The bigger issue is what the architecture demonstrates: attackers can increasingly automate decisions that previously required a person.

Key Takeaway: AI is beginning to remove human decision-making delays from parts of the cyberattack process. That makes response time more important, but it also strengthens the case for security controls that restrict what an attack can do before defenders have identified exactly what it is.

So what exactly did Cisco Talos find?

CLOSEDQUORUM is a Windows malware research finding that uses multiple commercial AI models as part of its command-and-control decision process. Talos found that the implant can query up to four LLM providers, tally their recommendations, select an action and execute it without requiring continuous commands from a human operator.

The capabilities Talos documented include familiar attacker objectives such as harvesting credentials, accessing LSASS, stealing browser data, creating persistence and targeting cryptocurrency wallets.

That distinction matters. The AI decision-making architecture is new, but many of the actions the malware ultimately wants Windows to perform are not.

Is CLOSEDQUORUM actually attacking businesses today?

There is currently no confirmation that CLOSEDQUORUM has been deployed in the wild. Talos says the publicly observed distribution binary was effectively an inert template because its LLM credentials and webhook values were placeholders.

That should prevent this research from being turned into another exaggerated “AI malware is taking over” headline. At the same time, dismissing it because this particular sample has not been observed in active attacks would miss the larger development.

Google Threat Intelligence Group reported in September that adversaries are moving from basic AI prompting toward agentic workflows and AI-enabled automation. In one Q2 2026 case, Google observed threat actors compromise a cloud resource and then plan, build and execute an agent-enabled mass credential-harvesting campaign in under six hours.

This is not evidence that every cyberattack is becoming autonomous. It is evidence that the human attacker is no longer necessarily the speed limit.

Why does removing the human from the loop matter?

Automation can compress the time defenders have to recognize an attack, investigate it and respond. A human operator needs time to review results, decide what to do next and issue another command. An AI-driven workflow can potentially make some of those decisions much faster.

Google describes this shift as reducing “human-in-the-loop latency” and enabling machine-speed decision-making. That creates an uncomfortable question for organizations whose endpoint strategy depends heavily on detecting suspicious behavior and then responding quickly enough to prevent damage.

Detect and Respond remains important. Organizations still need visibility, investigation, threat hunting and incident response. But response becomes a more difficult last line of defense when the attacker can move through portions of the attack chain at automated speed.

Does faster AI malware change the business risk?

It can increase the pressure on security teams because the consequences of delayed containment are operational, not merely technical. Credential theft, persistence, lateral movement and ransomware can ultimately lead to downtime, lost productivity, recovery expense, regulatory exposure and disruption to customers.

The 2026 Verizon Data Breach Investigations Report found that ransomware was involved in 48% of breaches. Verizon also reported that vulnerability exploitation became the leading initial access vector, accounting for 31% of breaches.

Those numbers matter because AI does not need to invent an entirely new attack model to increase risk. It can accelerate activities attackers already perform.

Could EDR detect an autonomous AI attack?

Potentially, yes. Autonomous does not mean invisible. Talos specifically recommends focusing detection on behavioral combinations such as unexpected AI-provider traffic alongside LSASS access, process injection, persistence creation or other suspicious activity.

But detection creates a second question: what happens between the suspicious action, the detection, the analysis and the response?

That gap has always mattered. Machine-speed attack decisions make it matter more.

This is why the security discussion should not become “EDR versus prevention.” Organizations need detection and response capabilities, but they should also ask how much execution freedom an attacker should have while those systems are deciding whether something is malicious.

Can an attack be stopped without identifying it first?

In many situations, damaging endpoint behavior can be restricted without first knowing the attack’s name, signature or exact malware variant. This is where Isolation and Containment changes the security model.

Consider CLOSEDQUORUM. Its AI models may decide which action to perform, but the malware still needs the endpoint to permit actions such as accessing protected resources, manipulating processes, harvesting credentials, creating persistence or changing files.

Changing the attack does not necessarily change the endpoint actions the attacker ultimately needs in order to succeed.

That is the opportunity. Instead of trying to predict every possible AI-generated attack, organizations can reduce the usable Windows attack surface and restrict unauthorized behavior before it becomes damaging.

What if you did not have to detect the attack in order to stop it?

AppGuard is a proven endpoint protection solution with more than a decade of production history focused on prevention through Isolation and Containment. It restricts unauthorized endpoint behavior without requiring the attack to first be identified as malicious. It does not replace EDR, and no endpoint technology stops every threat. The value is adding another control layer when detection is late, incomplete or bypassed.

The attack may be new. The actions it needs to perform on a Windows endpoint often are not.

What Should Businesses Do Next?

Assume attackers will continue using AI to reduce the time and effort required to execute attacks, and design security accordingly.

  • Do not rely exclusively on detection and response as the endpoint security strategy.
  • Reduce unnecessary endpoint execution freedom and attack surface.
  • Restrict how applications can access memory, files and sensitive system resources.
  • Review privileged access, browser credentials and third-party administrative tools.
  • Segment critical systems to reduce lateral movement and blast radius.
  • Test whether ransomware can still encrypt important endpoint and network-accessible data when other security layers fail.
  • Maintain tested backups and an incident-response plan.
  • Evaluate Isolation and Containment as an additional prevention layer where appropriate.

The bigger lesson from CLOSEDQUORUM

CLOSEDQUORUM is not evidence that autonomous AI malware has suddenly made traditional cybersecurity obsolete. It is evidence that the economics and speed of attacking are continuing to change.

Security teams should continue improving detection. But they should also reduce how much depends on detecting the right signal quickly enough.

Unknown does not automatically mean unstoppable.

The objective is not to predict every attack. It is to restrict the actions an attacker needs in order to succeed.

For a related look at this problem, read AI Attacks Move at Machine Speed: Can Detect & Respond Keep Up?

Tony Chiappetta
Post by Tony Chiappetta
October 3, 2026