There is an interesting thought experiment hiding inside Live Free or Die Hard, the 2007 installment of the Die Hard franchise. The movie imagined a coordinated cyberattack capable of disrupting the United States by attacking the increasingly interconnected computer systems underlying transportation, finance, communications, utilities, and government. At the time, the premise seemed like an exaggerated Hollywood version of a very real concern: what would happen if someone could exploit the country’s growing dependence on digital infrastructure?
Nearly twenty years later, the premise looks considerably more interesting—not necessarily because the specific mechanics of the movie have become realistic, but because the architecture of the digital world has changed. We are moving toward a world in which AI agents increasingly sit between human beings and the underlying services they use. They schedule appointments, communicate with businesses, make purchases, manage information, interact with software, and potentially coordinate with other agents. The Internet is gradually becoming less of a collection of websites and applications that humans operate directly and more of an ecosystem of machines operating on our behalf.
That creates the possibility of a very different kind of “fire sale.”
The original Die Hard 4 scenario was fundamentally about taking control of infrastructure. An updated version would be about taking control of the systems that control infrastructure—or, perhaps more dangerously, manipulating the systems that have been entrusted with making decisions about it.
That distinction matters.
The Internet Has Become a Stack of Dependencies
One of the great illusions of the modern Internet is that thousands of different services appear to be independent when they are often dependent upon the same underlying infrastructure. A person might interact with a bank, an airline, a hospital, a government agency, and an online retailer and reasonably assume that these are five separate systems. Technically, however, they may depend upon overlapping cloud providers, identity systems, authentication services, software libraries, payment networks, communications infrastructure, APIs, and other common components.
This creates enormous efficiency, but it also creates chokepoints.
The original Live Free or Die Hard understood this basic principle. The villain did not need to personally destroy every bridge, turn off every television station, and shut down every traffic light. He needed to understand the dependencies connecting those systems and exploit the points where many systems converged.
AI agents potentially add another layer to this architecture.
Instead of humans individually interacting with thousands of services, increasingly sophisticated agents could mediate those interactions. Your personal AI might communicate with your bank. Your employer’s AI might communicate with your personal AI. An airline’s AI might negotiate with your calendar. A doctor’s AI might interact with your insurance company’s AI. Businesses might increasingly have autonomous software negotiating with autonomous software.
That is enormously convenient.
It is also an entirely new attack surface.
The New Fire Sale Wouldn’t Necessarily Turn Everything Off
The most interesting version of an AI-enabled cyberattack probably wouldn’t look like the traditional Hollywood blackout.
It wouldn’t necessarily be a situation in which the lights go out, the phones stop working, the stock market crashes, and every computer screen suddenly goes black. That would certainly be dramatic, but it might actually be the easier scenario to understand and respond to.
The more disturbing possibility is that everything continues functioning.
It just begins producing the wrong answers.
Your bank tells you that your account contains no money. Your airline says your reservation doesn’t exist. Your employer’s system says you no longer work there. A logistics system redirects a shipment to the wrong warehouse. A hospital’s software produces contradictory information about a patient’s records. A government database identifies someone incorrectly. An automated purchasing system orders the wrong supplies.
Nothing has necessarily “gone down.”
Instead, reality has become unreliable.
That could be far more disruptive.
Modern civilization depends not merely upon machines functioning, but upon people being able to trust the information those machines provide. If that trust disappears, an enormous amount of economic activity has to slow down while humans attempt to verify what is actually happening.
The attacker doesn’t necessarily need to destroy the system.
They can attack confidence in the system.
AI Makes the Impersonation Problem Much Worse
This is where generative AI changes the premise dramatically.
Traditional cyberattacks generally require some combination of technical vulnerability, stolen credentials, malicious code, or human deception. AI doesn’t eliminate those requirements, but it potentially makes the human component dramatically more scalable.
Imagine receiving a message from your bank. It looks legitimate. You ask your personal AI whether it is legitimate. Your AI checks the relevant information and tells you that everything appears to be fine.
You proceed.
Except the information your AI used to authenticate the message has itself been manipulated.
Now imagine this happening throughout an organization.
An employee receives instructions from what appears to be their manager. The manager’s voice is correct. The writing style is correct. The previous correspondence is correct. The request makes sense in context.
The employee’s AI assistant examines the message and reports that it appears authentic.
So the employee follows it.
The problem is not simply that someone has created a convincing fake.
The problem is that the machines responsible for determining whether something is fake have also become part of the attack surface.
That is an entirely different security problem.
The AI Agent Becomes the New Employee
There is another important difference between an ordinary cyberattack and an AI-era cyberattack.
A conventional attacker has limited bandwidth. An individual hacker can only investigate so many systems, write so many messages, maintain so many identities, and respond to so many defensive actions.
An autonomous AI system potentially has none of those limitations.
It could investigate one organization while simultaneously investigating hundreds of others. It could maintain thousands of conversations. It could analyze enormous quantities of technical documentation. It could adapt its behavior based upon what happens after every attempt.
The important point isn’t that an AI necessarily becomes superintelligent.
It doesn’t have to.
Even a relatively capable system that can operate continuously, cheaply, and at enormous scale changes the economics of cybercrime.
Instead of asking, “How many systems can the attacker personally compromise?” we might eventually have to ask, “How many systems can the attacker’s agents investigate and manipulate simultaneously?”
That is a profoundly different question.
The Really Interesting Scenario: Nobody Knows Who Is in Charge
This leads to what might be the most frightening version of the hypothetical.
Imagine that an attack begins.
Some systems start behaving strangely. Security teams respond. The attackers begin impersonating the security teams. Companies disconnect certain systems. The attackers generate convincing explanations for why those systems were disconnected.
Government agencies issue emergency instructions. Fake versions of those instructions begin circulating. Executives receive conflicting information. Personal AI assistants attempt to determine which information is trustworthy. Corporate AI systems attempt to determine which government instructions are legitimate. Government systems attempt to determine which corporate systems have been compromised.
Meanwhile, ordinary people are asking their own AIs what is happening.
And the AIs disagree.
At that point, the attack has entered a completely different phase.
The objective is no longer simply to compromise computers.
It is to compromise the epistemic infrastructure of society—the mechanisms by which society determines what is true.
That is a much more profound vulnerability.
Your Navi Could Become Part of the Problem
This is particularly relevant if the future develops something like the personalized “Navi” concept that increasingly seems plausible: an AI that knows an individual extremely well and serves as their primary interface with the digital world.
A Navi could become the ultimate defensive technology.
It knows you. It knows your accounts. It knows your normal behavior. It can identify unusual requests. It can independently verify information. It can warn you when something appears suspicious.
In principle, that could make individuals dramatically safer.
But there is an obvious paradox.
The more we trust the Navi, the more valuable the Navi becomes as a target.
Suppose your Navi tells you, “I’ve checked this. It’s legitimate.”
That statement might eventually carry more weight than an email from a bank, a text message from a friend, or even a phone call from a government agency.
After all, the whole point of the Navi is that it is supposed to be your trusted intermediary.
But what happens if the Navi’s information sources have been compromised? Or its authentication mechanisms? Or its memory? Or the APIs through which it communicates with other services? Or the model itself?
Suddenly the technology intended to protect people from an increasingly complicated digital world becomes the most important piece of infrastructure an attacker needs to compromise.
The attacker doesn’t have to fool you.
They fool the thing you trust to tell you when you’re being fooled.
This Could Produce an Information “Fire Sale”
The original Live Free or Die Hard envisioned a “fire sale” in which one system after another was brought down. An AI-era fire sale could instead proceed through increasingly severe levels of information corruption.
First, relatively minor services become unreliable. Then financial systems begin producing contradictory information. Then logistics systems begin disagreeing with one another.
Then communications become suspect.
Then government information becomes difficult to authenticate. Then AI agents begin disagreeing about which sources are trustworthy. Eventually, people stop knowing which digital information they can safely act upon.
At that point, society might begin reverting to surprisingly primitive mechanisms. Phone calls. Physical documents. Paper records. Face-to-face verification. People physically going to banks and government offices. Human beings personally confirming that other human beings are who they claim to be.
The irony would be extraordinary.
The most technologically sophisticated civilization in human history might temporarily have to rediscover the value of asking another human being, in person, “Are you sure?”
The Attack Doesn’t Even Have to Be Perfect
There is another reason this scenario is worth taking seriously as a thought experiment. A successful attack doesn’t necessarily require complete control.
Cybersecurity is often discussed in terms of whether an attacker can penetrate a particular system. But the societal consequences of an attack can depend on something else: how much disruption can be produced with relatively little control.
If an attacker can cause a small percentage of automated systems to behave incorrectly, while simultaneously making it difficult to determine which systems are compromised, the resulting confusion could become disproportionately large.
This is especially true in highly automated environments.
Automation works because systems assume that other systems are behaving predictably. If that assumption breaks down, organizations may have to insert humans back into processes that were specifically designed to eliminate human intervention.
The bottleneck then becomes human attention.
And human attention is scarce.
The Villain Might Not Look Like a Villain
This also changes the cinematic possibilities.
The villain in Live Free or Die Hard is recognizably a villain. He has a plan, a hideout, and a technological conspiracy.
The AI-era villain might be much harder to identify. It could be a criminal organization, a hostile government, a terrorist organization, a rogue insider, a compromised software company, or a group that steals access to autonomous AI agents.
Or, in the most unsettling version, nobody initially knows who did it at all. The attack could begin as a collection of seemingly unrelated technical incidents. A strange banking problem here.
A logistics anomaly there. An authentication failure somewhere else. A government database behaving strangely. A few apparently unrelated deepfake communications. Only gradually would investigators realize that these incidents aren’t independent.
Something—or someone—is moving through the connective tissue. And by the time humans understand the pattern, the attacker has already learned how the defenders respond.
The Ultimate Vulnerability Is Complexity
There is a larger lesson here that goes beyond AI. Every generation of technology creates new capabilities while also creating new dependencies.
The telegraph created communications networks. Electricity created electrical grids. The telephone created telecommunications networks. Computers created information networks. The Internet connected those networks. Cloud computing concentrated enormous amounts of computation and storage into shared infrastructure.
AI agents could now become the decision-making layer sitting on top of all of it. That could be enormously beneficial. It could also mean that civilization is gradually constructing another layer of systemic dependency. The more capable these agents become, the more we may allow them to do without asking for human confirmation.
Eventually, the question may no longer be whether an AI can write an email or book a restaurant.
It may be whether we trust an AI to decide which email, which transaction, which identity, which instruction, and which piece of information should be considered legitimate.
That is an extraordinary amount of authority to place in software.
The Sequel Practically Writes Itself
If Hollywood ever made a genuinely updated Live Free or Die Hard, I would hope it resisted the temptation to simply make the villain “an AI.” That would actually miss the interesting part.
The frightening scenario isn’t necessarily an artificial intelligence deciding to destroy humanity. It is a malicious human being—or organization—realizing that AI agents have become the connective tissue of civilization and figuring out how to exploit them.
The attack would not necessarily look like machines taking over.
It might look like machines doing exactly what they were designed to do. They authenticate. They communicate. They execute instructions. They optimize. They make decisions. They trust other machines. They pass information along. They act autonomously.
And somewhere in that enormous network of apparently reasonable decisions, someone has inserted a lie. That is the real 2020s-and-beyond version of the Die Hard premise.
John McClane wouldn’t necessarily be running around trying to stop somebody from shutting down the computers. He’d be trying to figure out which computers he could still believe. And that may ultimately be the more frightening question. Because when civilization’s infrastructure stops working, people know there is a problem. When civilization’s infrastructure continues working while quietly telling everyone different versions of reality, how do you even know there is a problem?
You must be logged in to post a comment.