
The information displayed in the AIM should not be reported as representing the official views of the OECD or of its member countries.
A hacker exploited Amazon's AI-powered coding assistant, Amazon Q, by injecting malicious prompts designed to wipe users' files and cloud resources. The compromised code was distributed in an official update, exposing nearly a million users to potential harm. Although safeguards prevented actual damage, the incident highlights significant security vulnerabilities in AI tool deployment.[AI generated]
Why's our monitor labelling this an incident or hazard?
The event involves an AI system (Amazon's 'Q' AI coding assistant) whose use was compromised by a hacker inserting destructive commands. Although no actual damage occurred, the AI system's malfunction or misuse could have directly led to harm to property (erased files) and disruption of critical infrastructure (AWS cloud resources). This fits the definition of an AI Incident because the AI system's use was directly linked to a potential harm event, and the incident has materialized as a security breach with real risk. The mitigation and lack of actual damage do not negate the classification as an incident, since the event involved direct risk and exploitation of the AI system leading to potential harm.[AI generated]