A recent paper showed AI self-replication is no longer technically hypothetical.
Current agents can hack, copy themselves to a new server, and keep going, so this capability now belongs in real AI security planning.
The paper actually demonstrates the full loop rather than testing isolated pieces.
Agents found vulnerabilities, extracted credentials, transferred model weights and the agent software, started inference on the compromised machine, and then used the new replica to attack the next target.
Qwen3.6-27B completed a 3-hop chain across 4 VMs on 3 continents from 1 initial prompt, with no human intervention after launch.
But this does not mean AI agents are freely spreading across the internet, here in this experiment, the targets were intentionally vulnerable lab systems with known hostnames, available GPUs, and unusually accessible SSH credentials.