
The information displayed in the AIM should not be reported as representing the official views of the OECD or of its member countries.
Google warned of a surge in AI-powered cyberattacks exploiting software vulnerabilities, including bypassing two-factor authentication, and highlighted the growing use of generative AI by cybercriminals. Simultaneously, European militaries, notably Germany and Ukraine, are rapidly integrating AI into weapons and battlefield systems, raising concerns about AI-driven harm in both cybersecurity and military contexts.[AI generated]
Why's our monitor labelling this an incident or hazard?
The article explicitly states that AI was used by a known cybercrime group to find a new software vulnerability and create an exploit tool, which is a direct use of AI in malicious operations. The target is critical infrastructure software, and the attack was only stopped before widespread damage, indicating a direct link between AI use and a serious cybersecurity threat. The involvement of AI in the development and use phases of the attack, and the resulting harm or near-harm to critical infrastructure, fits the definition of an AI Incident. The report also discusses the broader implications and ongoing risks, but the primary event is the AI-enabled cyberattack attempt, which is a realized harm scenario or very close to it.[AI generated]