Recently CNN reported the following:
AI isn’t the biggest cybersecurity problem. People are
(1/2)
BUSINESS TECH
CNN - By Lisa Eadicicco
AUG 9, 2026
Cases of AI escaping the lab, infiltrating other companies
and trying to deceive people have all made headlines in recent weeks. And in
one case, AI models even worked together to break free from their test
environments.
Does this mean the machines are taking over? Not quite.
AI isn’t the mastermind behind today’s most widespread cyber threats; it’s people who can use AI nefariously – and for nefarious purposes. AI has given bad actors massive power, allowing them to create malicious software, research targets, create convincing schemes and automate attacks at an unprecedented pace.
One in four data breaches were driven by AI from February 2025 to March 2026, according to an IBM report. And Americans lost more than $893 million to AI-related scams last year, the FBI says.
But experts say real-world threat actors – that is, people – are still the ones pulling the strings. AI agents have only perpetuated existing attack methods, like phishing and malware scams, rather than creating wholly new ones.
“It’s the humans that we need to watch out for,” said Oren Etzioni, professor emeritus at the University of Washington and former CEO of the Allen Institute for Artificial Intelligence. “AI is just the tool.”
AI going rogue
Some recent incidents have shown what AI is capable of in
the real world, not just in theory, igniting fears about whether the technology
is advancing too quickly.
In July, OpenAI test models escaped their constraints and hacked into other companies’ systems during an internal evaluation.
Days later, Anthropic said it discovered its AI models had
breached three companies during testing.
In a separate test, Anthropic’s most advanced model used
fake identities to try to deceive real people, researchers at Britain’s AI
Security Institute said Tuesday.
One of Meta’s AI models also broke into an external company,
the social media giant said Wednesday.
Those breaches also show how unpredictable AI can be when
interpreting instructions. OpenAI’s models, for example, were trying to pass a
cybersecurity test when they broke out of their test environment and breached
another company, even though they weren’t told to do so.
Patrick Fussell, global head of adversary simulation at IBM, compared AI to a genie.
“You want to ask it a wish, but you have to be very, very specific about the details of your wish,” he told CNN. “Or it could sort of go awry.”
But these instances also happened under very specific circumstances.
OpenAI turned off restrictions that would have prevented its model from “pursuing high risk cyber activity.” Anthropic ran its tests without the standard safety safeguards in models that are generally available to the public. The AI Security Institute also turned off certain tools that could have “reduced the scope” of what the models were capable of.
Researchers typically do this to fully evaluate a model’s capabilities.
“I couldn’t go into ChatGPT or Claude or something like that, and it accidentally breaks into the FBI. That’s not going to happen,” said Adam Meyers, head of counter adversary operations at cybersecurity firm CrowdStrike. “So what we’re seeing is these are done in specific test conditions where they’re monitoring to see, ‘Does this thing do something that it’s not expected to do?”
(to be continued)
Translation
人工智能並非最大的網絡安全問題。最大的問題是人(1/2)
近幾週來,人工智能逃逸實驗室、滲透其他公司並試圖欺騙人類的案例頻頻登上新聞頭條。在其中一件案例中,人工智能模型們甚至協同合作,成功突破了測試環境。
這是否意味著機器正在接管一切?並非如此。
人工智能並非當今最普遍的網絡威脅背後的主謀;是人才會惡意使用人工智能,並用於惡意目的。人工智能给不法分子提供了巨大的能力,使他們能夠以前所未有的速度創建惡意軟件、研究攻擊目標、設計逼真的騙局並自動化攻擊。
IBM 的一份報告顯示,從2025年2月到2026年3月,四分之一的資料外洩事件是由人工智能驅動的。美國聯邦調查局(FBI)表示,去年美國人因人工智能相關的詐騙損失超過8.93億美元。
但專家表示,現實世界中的威脅行為者 - 也就是人 - 仍然是幕後操縱者。人工智能代理只是延續了現有的攻擊手段,例如網絡釣魚和惡意軟件詐騙,而不是創造了全新的攻擊方式。
華盛頓大學榮譽教授、亦是 Allen人工智能研究所 的前首席執行官Oren Etzioni 說:“我們真正需要警惕的是人”,“人工智能只是工具。”
人工智能失控
最近發生的一些事件表明,人工智能在現實世界中的能力遠超理論,引發了人們對這項技術發展是否過快的擔憂。
今年7月,OpenAI 的測試模型在內部評估期間突破了限制,入侵了其他公司的系統。
幾天後,Anthropic 公司表示,他們發現其人工智能模型在測試期間入侵了三家公司。
英國人工智能安全研究所的研究人員週二表示,在另一項測試中,Anthropic 公司最先進的模型使用虛假身份試圖欺騙真實人物。
社群媒體巨頭 Meta 公司週三表示,該公司的一款人工智能模式也入侵了一家外部公司。
這些這些違規行為也表明,人工智能在解讀指令時可能具有不可預測性。例如,OpenAI 的模型在試圖通過網路安全測試時,突破了環境測試而入侵了另一家公司,儘管它並未被告知要去這樣做。
IBM 的全球對手模擬主管Patrick Fussell將人工智能比喻為阿拉丁神燈裡的精靈。
他告訴 CNN:“你想向它許願,但你必須非常非常具體地說明你的願望” ;“事情可能或者會有點出錯。”
但這些事件也發生在非常特殊的情況下。
OpenAI 關閉了原本可以阻止其模型「進行高風險網路活動」的限制。 Anthropic 公司在進行測試時,並未採用通常對外開放的標準模型安全防護措施。人工智能安全研究所也關閉了一些可能「限制」模型功能範圍的工具。
研究人員通常會這樣做,以便全面評估模型的能力。
網絡安全公司 CrowdStrike 的反恐行動主管 Adam Meyers 說: 「我不可能在進入 ChatGPT 或Claude 之類的系統後,會意外地入侵了FBI。這種情況絕對不會發生」; 「所以我們看到的是,這些測試都是在特定測試情况監控下發生的,目的是看看‘這個系統是否會做出一些意料之外的事情?’」。
(待續)
Note:
1. In cybersecurity, 'adversary simulation'
(對手模擬) refers to
mimicking the actions and tactics of potential attackers so as to test and
improve an organization's defenses.