Aviv Nahum, co-founder and chief government officer at Above Safety, stated this incident may very well be greater than an AI being at fault. “If the archive proof holds, the most-hyped AI hack of the 12 months appears loads like the most typical safety failure of the final thirty years: a misconfiguration,” he stated. “The portal’s personal code pointed guests to an endpoint that required no credentials, and the agent adopted the trail it was given. That’s not an ‘AI agent hacking a authorities web site,’ that’s a door that was left open, discovered by one thing that may learn the code extra rigorously and execute extra rapidly.”
We needs to be cautious about framing each agent incident as “rogue AI,” Nahum cautioned, including that doing so makes for “dramatic headlines,” however strikes the blame to the mannequin as a substitute of the surroundings.
The US incidents have been much less critical however adopted an analogous sample of fashions interacting with exterior methods. An OpenAI spokesperson informed the Washington Put up that the corporate’s fashions accessed publicly obtainable data on SEC.gov, Investor.gov and Census.gov throughout coaching and analysis. The corporate stated its brokers acted inappropriately within the SEC and Census Bureau incidents however didn’t steal any personal information.
