AI-Driven Cyberattacks Expose Security Gaps, Prompting New AI Defense Initiatives

Thumbnail Image

The information displayed in the AIM should not be reported as representing the official views of the OECD or of its member countries.

Simulations by cybersecurity startup Corma revealed that AI-powered attackers successfully breached defenses in 88% of tests, while AI defense systems detected only 12% of threats. This highlights significant vulnerabilities in current cybersecurity measures and has prompted Corma to develop specialized AI defense models, already adopted by major enterprises.[AI generated]

Why's our monitor labelling this an incident or hazard?

The article explicitly mentions AI systems used as attackers and defenders in cybersecurity, with AI attackers successfully breaching defenses in 88% of simulated tests, indicating realized harm in the form of security breaches. The harm includes potential impacts on critical infrastructure and essential services, which aligns with the definition of AI Incident harm categories (a) injury or harm to persons, (b) disruption of critical infrastructure, and (d) harm to communities. The development and deployment of AI defense models are responses to this harm but do not negate the incident classification. The presence of AI-driven attacks causing or enabling harm, even in simulations reflecting real-world conditions, meets the criteria for an AI Incident rather than a hazard or complementary information.[AI generated]
AI principles
Robustness & digital securitySafety

Industries
Digital security

Affected stakeholders
Business

Harm types
Economic/Property

Business function:
ICT management and information security

AI system task:
Goal-driven organisation


Articles about this incident or hazard