Both Altman and Amodei loudly farted in a quiet party room, full of people. “I feel it viscerally” – said Altman. ”Let’s lock the room, since some people could fart here and badly spoil the air. What we have here now is bad already.”
“It was cybersecurity's "Jurassic Park" moment.
Starting in April, AI models from OpenAI and Anthropic that had been built to hack had left their corporate test-beds and broke into unsuspecting corporations in an unprecedented series of cyberattacks.
The models were state-of-the art autonomous hacking machines, and neither company had noticed their escape until last month, when OpenAI disclosed a July hack of the AI company Hugging Face. After checking its logs, Anthropic said on Thursday that it had found three hacks.
The twin disclosures caused consternation among lawmakers, with some citing them to argue for new regulation or testing regimes. They also marked an eye-opening moment for some employees of the labs responsible.
"This is the first security incident that I have felt very viscerally. I have been a little surprised that more people don't feel it so viscerally," OpenAI CEO Sam Altman said on a podcast, referring to his company's hacking as "an extremely sci-fi cyber incident."
To cybersecurity experts, it shows increasing capabilities and a rising reason to worry. To AI safety experts, it vindicates what they have been warning about all along: that AI systems would cause real-world harms and evade attempts to control them.
"It is a bit vindicating to see this happen in the wild," said Jeffrey Ladish, executive director of Palisade Research, a nonprofit AI lab that studies AI capabilities to better understand risks. Ladish previously helped build Anthropic's information-security program.
Ladish said he often argues with people online who say he just believes in science fiction. "I hope our predictions stop coming true," he said.
In one sign that the White House is increasing oversight of AI, the administration has completed a framework dictating which models will be subject to federal government review before they are released publicly, a White House official said.
Discussions with companies about how to proceed with the voluntary testing are continuing, the official said.
After years of clumsy performance, AI models had a breakthrough moment last fall, when they became noticeably better at finding bugs and passing hacking-benchmarking tests. But there wasn't much real-world data on their abilities.
Now that has changed.
"These incidents will probably, in retrospect, be seen as inflection points in the ways that attackers operate," said Joshua Saxe, the chief technology officer with the AI security company Abundant Security. "It's a really dangerous situation; these incidents really show that."
OpenAI has committed to conducting a full review sharing a technical report about the hack. News Corp, owner of The Wall Street Journal, has a content-licensing partnership with OpenAI.
Last December, researchers at Stanford University used state-of-the art AI technology to show models achieving close-to-human levels of hacking on a real-world network.
The research received pushback from professional hackers known as penetration testers -- people who are hired by corporations to break into their own networks to help them understand their vulnerabilities
"At the time our results were disputed," said Donovan Jasper, one of the researchers involved in the project. "People said they could do better."
Jasper sees Anthropic's and OpenAI's revelations as affirmation of his team's earlier research. "AI is getting really good at this stuff," he said.
The Stanford researchers' biggest concern during their tests was that their hacking models might somehow do something they weren't intended to do. "The entire time it was operating, there was at least one human observing it," he said.
Hugging Face was unprepared for the agentic attack by OpenAI's models. The company tried to use Claude to analyze the vast amount of data the OpenAI agents had generated, but the Anthropic model refused to perform the analysis, citing safety reasons.
Hugging Face was able to use Chinese open-weight models, which can be run on systems controlled by the users, to do its analysis.
But many companies don't even have the correct tools to analyze AI-generated attacks, said Ryan McGeehan, owner of R10N Security, a cybersecurity consulting firm. "Old classic security teams that are not AI-forward are going to get left behind," he said.
Agentic-AI hackers aren't like humans, McGeehan said. "They go deeper, they go wider, they're more intricate, and they're more dense," he said.
The hacks are increasing pressure on the Trump administration to take more steps to address the security risks posed by AI.
President Trump is attempting a balancing act to mitigate risks presented by powerful AI models while allowing the industry to compete against rapidly improving Chinese companies. "We have to be careful in both ways. We don't want to restrict them when all of a sudden we come in second to China," he said in the Oval Office this week.
The administration has completed a framework dictating which models will be subject to federal government review before they are released publicly, a White House official said. Discussions with companies about how to proceed with the voluntary testing are continuing, the official said.” [1]
In these hacking incidents all of a sudden you come in second to China. Now what?
1. Rogue AI Hacks Mark New Cyber Threat. McMillan, Robert; Wells, Georgia; Ramkumar, Amrith. Wall Street Journal, Eastern edition; New York, N.Y.. 04 Aug 2026: B1.
Komentarų nėra:
Rašyti komentarą