When DIG AI appeared on the dark web in late 2025, it looked like a glimpse of cybercrime’s next evolutionary step.
An anonymous AI assistant, accessible through Tor, requiring no account and apparently operating without the safety restrictions normally associated with commercial artificial intelligence platforms. Security researchers found that it could respond to requests involving malware, fraud and other forms of criminal activity that mainstream systems would normally restrict.
At the time, DIG AI seemed to represent a simple but disturbing future: cybercriminals would build their own unrestricted versions of ChatGPT and move them underground.
Less than a year later, that prediction looks only partially correct.
DIG AI has not become irrelevant. In fact, recent threat intelligence still places DIG inside the evolving darknet AI ecosystem. But the wider criminal market has developed in a more complicated direction.
The real threat may no longer be a single “evil chatbot.”
It is the infrastructure forming around criminal use of artificial intelligence.
DIG AI Did Not Simply Disappear
Our original investigation into DIG AI focused on its unusually low barriers to entry.
Unlike subscription-based criminal AI services such as some versions of WormGPT and FraudGPT, DIG AI was promoted as accessible without traditional registration or payment infrastructure.
Resecurity first documented DIG AI in September 2025 and later reported increasing use among cybercriminal communities during the final months of that year. Researchers testing the system found that it was capable of producing content that could support malicious activity, while its operator promoted it through underground marketplaces.
The obvious question was what would happen next.
By 2026, DIG had not vanished from threat intelligence reporting.
An August 2026 report from blockchain intelligence company TRM Labs describes a dedicated onion search platform called DIG that has expanded into uncensored AI chat, GPT-style assistants and image generation.
That development is important.
DIG is no longer interesting merely because it is an unrestricted chatbot.
It illustrates something larger: AI is becoming another service integrated into the infrastructure of the darknet itself.
But “Dark LLMs” Have a Problem
There is an important twist.
The cybercrime industry does not appear to have abandoned mainstream artificial intelligence in favor of specialized criminal models.
Quite the opposite.
Check Point Research’s 2026 AI Security Report argues that dedicated criminal “DarkGPT” services have struggled to match the technical capabilities of leading commercial AI systems.
Some underground users reportedly consider self-hosted or criminal-only models slower, less accurate and more expensive to operate effectively.
DIG AI is specifically mentioned as an example of the inexpensive Tor-hosted services that continue to appear, but Check Point says much of the more serious activity has moved toward other approaches — particularly abusing commercial AI systems or running unrestricted open models.
Trend Micro reached a similar conclusion earlier in 2026.
Its researchers found that criminals frequently rely on jailbreaking legitimate LLMs rather than developing sophisticated foundation models themselves.
And economically, that makes sense.
Training a frontier AI model requires enormous amounts of computing power, data, engineering expertise and money.
Cybercriminals generally do not need to recreate OpenAI, Google or Anthropic.
They need access to intelligence somebody else has already built.
Criminal AI Doesn’t Need to Build the Model
This may be the biggest misconception surrounding systems such as DIG AI.
The important innovation is not necessarily the underlying model.
It is the removal of friction around it.
Cybercriminal services can combine existing models, open-weight systems, stolen credentials, jailbreak techniques, custom prompts and simple interfaces into products designed specifically for underground users.
Rapid7 describes this emerging ecosystem as Criminal AI-as-a-Service.
Many of the services advertised on underground forums are not genuinely new artificial intelligence models at all. Some are wrappers around existing models. Others use fine-tuned open-weight systems, jailbreak configurations or combinations of multiple external services.
Some may even exaggerate their technical capabilities entirely.
But that does not make the ecosystem harmless.
The product being sold is convenience.
A criminal no longer needs to understand how a large language model works. They simply need a service promising to remove restrictions and help automate part of an existing criminal workflow.
This is essentially the same economic transformation that previously reshaped ransomware.
Attackers do not necessarily build everything themselves.
They buy access.
From AI Assistant to AI Operator
The bigger change in 2026 is happening beyond DIG AI.
Check Point Research argues that artificial intelligence has moved from being an assistant inside cyberattacks to becoming an active component of the attack process.
Researchers have documented cases where AI generated commands, processed information and assisted live intrusion workflows with limited human intervention.
AI-generated malware has also become increasingly difficult to distinguish from traditionally developed malicious software.
In one case analyzed by Check Point, a single developer reportedly produced an 88,000-line command-and-control framework in less than a week with extensive AI assistance.
The significance is not that AI suddenly became an autonomous super-hacker.
It is that one human operator can potentially accomplish work that previously required substantially more time, expertise or personnel.
This changes the economics of cybercrime.
The Real Power of Criminal AI Is Scale
Consider phishing.
Writing one convincing phishing message has never been particularly difficult.
Writing thousands of personalized messages, adapting them to different languages, companies, victims and situations is much more expensive.
Generative AI changes that equation.
The same applies to social engineering, fake identities, synthetic photographs, voice cloning, fraudulent customer-support interactions and scam conversations.
The underlying crimes are often old.
The industrial scale is new.
TRM Labs’ 2026 AI-in-Crime Adoption Index gives some indication of how quickly the transition is happening.
TRM estimates overall AI adoption across the crypto-crime categories it studies at 54 out of 100 in 2026, compared with roughly 28 in 2024.
Scams are already classified at the report’s “Mature” level of AI adoption.
Perhaps more strikingly, TRM says the proportion of scam reports containing an identifiable AI component has increased roughly thirteen-fold since 2022.
Reported losses linked to deepfake scams during 2026 had already exceeded the total recorded during all of 2025 by 263% when the report was released in August.
Those numbers tell us something important about DIG AI.
The greatest danger may not be hackers asking an uncensored chatbot to write malware.
It may be thousands of ordinary scammers using increasingly automated AI infrastructure to manipulate thousands of victims simultaneously.
Dark AI Is Becoming an Economy
Cybercrime has always copied legitimate technology businesses.
Malware became Malware-as-a-Service.
Ransomware became Ransomware-as-a-Service.
Phishing became Phishing-as-a-Service.
Infrastructure, stolen credentials, proxy networks, cryptocurrency laundering and bulletproof hosting all became commodities that criminals could buy rather than build.
Artificial intelligence is following exactly the same path.
The emerging criminal AI economy includes underground chatbots, access brokers, deepfake services, automated phishing platforms, stolen AI accounts, jailbreak services and customized models.
Some are technically sophisticated.
Many are not.
Some are almost certainly scams targeting criminals themselves.
But the direction of travel is clear.
AI capability is becoming purchasable infrastructure.
And once capability becomes a service, the barrier to entry falls dramatically.
DIG AI Still Matters — Just for a Different Reason
This does not mean the concerns surrounding DIG AI were exaggerated.
They were simply focused on the first visible manifestation of a much larger phenomenon.
DIG AI showed what happens when the safety layer surrounding generative AI is deliberately removed and the resulting interface is placed inside an anonymous criminal ecosystem.
But the industry that followed does not require one dominant criminal AI platform.
There may never be a “ChatGPT of cybercrime.”
Instead there could be hundreds of smaller tools, temporary services, Telegram bots, open models, commercial API wrappers and stolen accounts constantly appearing and disappearing.
From a law-enforcement perspective, that may actually be more difficult to combat.
A centralized service can potentially be investigated, infiltrated or disrupted.
A decentralized ecosystem built from interchangeable models and disposable infrastructure is far harder to eliminate.
Destroy one interface and another can appear days later.
The Most Dangerous AI May Look Completely Normal
There is another uncomfortable conclusion emerging from 2026 threat research.
The most capable AI used by criminals may not live on the dark web at all.
It may be the same AI used every day by developers, students, companies and researchers.
Check Point and Trend Micro both point toward continuing abuse of commercial and openly available AI systems.
That fundamentally changes the defensive problem.
Security companies cannot simply maintain a blacklist of criminal AI platforms.
The underlying technology is general-purpose.
The difference between productive and malicious use increasingly depends on the user, the surrounding automation and the broader workflow.
That means cybersecurity teams need to watch behavior rather than brands.
Blocking something called “WormGPT” or “DIG AI” does very little if the attacker can reproduce much of the same workflow using another model tomorrow.
What Comes After DIG AI?
The next stage will probably involve more automation.
AI agents can already interact with software, process information and execute multi-step workflows.
The same architecture that allows legitimate businesses to automate repetitive work can also reduce the human effort required for malicious operations.
That does not mean autonomous AI hackers will suddenly replace cybercriminals.
Human expertise still matters enormously.
But a skilled attacker assisted by increasingly capable AI agents can potentially operate faster, investigate more targets and automate more of the attack chain.
That is the evolution defenders should be watching.
DIG AI represented the first wave: unrestricted AI packaged for the underground.
Criminal AI-as-a-Service represents the second: AI capability transformed into a commodity.
Agentic cybercrime could become the third.
DIG AI Was the Warning, Not the Destination
When DIG AI emerged in 2025, the disturbing part was how easy it made access to unrestricted generative AI.
In 2026, the picture is broader.
Dedicated dark-web AI models have not replaced mainstream systems.
Some have proved technically mediocre. Others are little more than rebranded interfaces or marketing operations.
Yet AI-enabled crime has continued to accelerate.
That apparent contradiction reveals what actually matters.
Cybercriminals do not need the world’s most sophisticated underground AI.
They need artificial intelligence that is cheap enough, capable enough and easy enough to integrate into criminal operations.
DIG AI helped demonstrate that demand existed.
The ecosystem forming around it shows where that demand is heading.
And the future of criminal AI may therefore look much less like a mysterious supercomputer hidden somewhere on the dark web.
It may look disturbingly similar to the legitimate AI economy growing everywhere else.

