The Financial Times, followed by multiple security outlets, reported that suspected China-linked operatives used publicly available AI agent tooling to run what researchers are calling the first documented near-autonomous cyberattack against a government target. Over roughly four days in early July, the operators reportedly deployed up to eight AI agents that mapped around 21 government systems, researched vulnerabilities, attempted credential attacks, and adjusted their approach whenever they were blocked, with comparatively little continuous human direction. The campaign compromised dozens of government accounts, extracted thousands of personnel records, and then expanded to Taiwan's nuclear safety agency along with several energy-sector suppliers, putting critical infrastructure operators squarely inside the blast radius. What makes this significant for security teams and toolmakers is not any single technique used, since the individual steps such as scanning, credential stuffing and lateral movement are familiar, but the fact that an AI agent framework reportedly chained those steps together and adapted in real time without waiting for constant human approval. That shifts the defensive calculus: signature and playbook-based detection assumes attacker behavior that looks recognizably human-paced, while agent-driven intrusions can probe, pivot and retry at machine speed across many systems in parallel. Teams building or securing AI agent frameworks should treat this as a concrete misuse case worth defending against, and security operations teams, especially those protecting critical infrastructure or government-adjacent systems, should revisit incident response assumptions that rely on attackers needing sustained human attention to sustain a multi-stage campaign.