AI-Generated Passwords Pose Cybersecurity Risks

Thumbnail Image

The information displayed in the AIM should not be reported as representing the official views of the OECD or of its member countries.

Multiple reports warn that using AI systems like ChatGPT, Llama, and DeepSeek to generate passwords could expose users to cyberattacks. Experiments have shown that many of these AI-generated passwords are weak and predictable, heightening the risk of breaches and necessitating caution in their use.[AI generated]

Why's our monitor labelling this an incident or hazard?

The event involves the use of AI systems (large language models) in generating passwords, which is a direct use of AI. The AI-generated passwords' weakness has directly led to a cybersecurity vulnerability that can cause harm to users' data security and privacy, which falls under harm to persons or communities through unauthorized access and potential data breaches. Therefore, this constitutes an AI Incident because the AI system's use has directly led to a realized harm (or at least a demonstrated vulnerability with high likelihood of harm).[AI generated]
AI principles
Robustness & digital securityPrivacy & data governanceSafetyAccountabilityTransparency & explainabilityRespect of human rights

Industries
Digital securityIT infrastructure and hosting

Affected stakeholders
Consumers

Harm types
Economic/PropertyReputationalHuman or fundamental rights

Severity
AI incident

Business function:
ICT management and information security

AI system task:
Content generationInteraction support/chatbots


Articles about this incident or hazard