Agentic AI
,
Artificial Intelligence & Machine Learning
,
Black Hat

Politecnico di Milano’s Stefano Zanero on Specialized AI Agents, Exploit Generation

Michael Novinson (MichaelNovinson) •
August 12, 2026    

Stefano Zanero, professor, Politecnico di Milano

Security researchers are increasingly dividing complex tasks among specialized artificial intelligence agents instead of relying on a single generalist model, said Stefano Zanero, professor at Politecnico di Milano.

See Also: AI Phishing Now Frighteningly Normal, Hard to Detect

Narrowing each agent’s focus – one hunting vulnerabilities, another writing exploits, a third validating them – filters out the hallucinations and false positives that can emerge as prompts and context become more complex. “The more you can focus it and keep it doing one task, the better the results,” Zanero said.

Exploit generation has become a particular AI strength, since agents excel at programming and draw on a rich corpus of capture-the-flag write-ups. A working exploit is also automatically testable proof of a vulnerability, making validation more direct than fuzzing workflows that required manual analysis after a crash.

In this video interview with ISMG at Black Hat USA 2026, Zanero also discussed:

Why enterprises need new threat-modeling approaches for agentic AI pipelines;
Why data tied to individuals or covered by copyright complicates AI regulation;
Why proprietary “black box” foundational models draw outsized hacker interest.

At Politecnico di Milano, Zanero combines teaching computer security, digital forensics and cybercrime with research on AI-driven cybersecurity and cyber-physical systems. He has co-authored more than 180 scientific publications and is a senior member of IEEE and the IEEE Computer Society. He has also co-founded the cybersecurity firm Secure Network and fintech startup ExplikAI.