It’s AI problem now: Why bots attacking their brethren could quickly turn ugly

It’s AI problem now: Why bots attacking their brethren could quickly turn ugly


OpenAI and Anthropic, two of the leaders in generative artificial intelligence, are in hot water right now, and the situation could be reaching a boiling point.

ChatGPT’s maker OpenAI, regarded as the trigger for the generative AI revolution, disclosed last week that one of its AI models escaped from an isolated environment and attacked the AI start-up Hugging Face. Shortly thereafter, the US cloud firm Modal was also reported to have been hacked.

On Thursday, Anthropic, known for its Claude AI bot, said its models were able to gain unauthorised access to the systems of three companies during cybersecurity testing.

These happened within a week. Even before the Anthropic incident, analysts believed the situation was already a problem that could become lengthy and ugly.

“This is already a problem in its early form. We are not yet seeing AI run full-scale, end-to-end cyber campaigns independently, but that is not the point,” Michael Mossad, a partner for cyber emerging technologies at Deloitte Middle East, told The National.

“AI is already acting as a force multiplier, helping attackers move faster, personalise attacks more effectively, and experiment more cheaply. In cybersecurity, that alone is enough to shift the threat landscape.”

Nothing new?

AI agents – autonomous models capable of making decisions and achieving specific goals with limited supervision – are at the centre here. In the case of the OpenAI and Anthropic incidents, however, there seems to be a problem keeping them within their confined spaces.

Mohammed Aboul-Magd, general manager for cybersecurity at AI and quantum tech firm SandboxAQ, said the issue is that agents are moving faster than oversight.

And unlike test beds, projections, or lab papers, it affected real-world infrastructure.

“Agent capability is outpacing agent oversight everywhere and the infrastructure to evaluate, monitor and contain these systems is years behind the systems themselves,” he told The National.

“The capability arrived on schedule. The discipline around it didn’t … it’s a now problem,” he said.