
The information displayed in the AIM should not be reported as representing the official views of the OECD or of its member countries.
Multiple reports warn that using AI systems like ChatGPT, Llama, and DeepSeek to generate passwords could expose users to cyberattacks. Experiments have shown that many of these AI-generated passwords are weak and predictable, heightening the risk of breaches and necessitating caution in their use.[AI generated]
Why's our monitor labelling this an incident or hazard?
The event involves the use of AI systems (large language models) in generating passwords, which is a direct use of AI. The AI-generated passwords' weakness has directly led to a cybersecurity vulnerability that can cause harm to users' data security and privacy, which falls under harm to persons or communities through unauthorized access and potential data breaches. Therefore, this constitutes an AI Incident because the AI system's use has directly led to a realized harm (or at least a demonstrated vulnerability with high likelihood of harm).[AI generated]