You don't need AGI to do a lot of harm with AI. I'm reminded of a piece of malware that used Instagram comments to encode the instructions it was using to communicate with its control server [1]. This is rudimentary software that any script kiddie could devise with a bit of social engineering. Neural nets / deep learning of today could scale this to the point where it's undetectable.
[1] https://www.engadget.com/2017/06/07/russian-malware-hidden-b...