These cases caused serious concern at the state level and in the business community due to the emergence of a new type of cyber risk stemming from the rapid development of projects based on extensive use of AI.
Initially, testing of AI models assumed only restricting access to internal systems and minimizing potential damage to them, and preventing AI models from accessing the internet was not considered a priority. However, during testing conducted by OpenAI, AI models exploited software flaws unknown to cybersecurity specialists. In Anthropic’s case, due to a misunderstanding between the company and its partner conducting the evaluation, the AI models effectively had internet access. Meta stated that the AI model’s escape beyond the established constraints occurred due to an error in configuring the testing environment. At the same time, according to a number of experts, such cases became good publicity for the companies in question, since AI models breaking out of the testing environment may indicate exceptional capabilities and attract heightened interest.
The scale of the actual damage caused as a result of incidents involving AI models is quite difficult to determine, since no financial losses or physical damage have been publicly reported. However, it should be borne in mind that AI models gained unauthorized access to real systems, and in one case attempted to inject malicious code into an active project. If, in the future, AI models are able to penetrate larger systems or organizations and disrupt their normal functioning, this could lead to more serious negative consequences.
Today it is already obvious that AI model development is progressing so rapidly that government agencies and experts cannot keep up with it. As a result, calls are increasingly being made for mandatory government testing of AI models and tighter oversight of their functional capabilities, which could be used to conduct large-scale cyberattacks. Along with this, it is proposed to slow down AI model development until the developers themselves fully understand the systems they are creating. It is important that AI models remain continuously controllable and strictly perform only those functional tasks that developer companies set for them.
Author: Doctor of Economics, Professor, Department of World Economy and World Finance, Financial University under the Government of the Russian Federation Igor Alekseevich Balyuk.