
The information displayed in the AIM should not be reported as representing the official views of the OECD or of its member countries.
Forescout's Vedere Labs used the AI system Claude to help port a remote code execution exploit between two WAGO PLC models, critical for industrial control. The AI-assisted process led to the accidental destruction of hardware, demonstrating AI's potential to lower barriers for cyberattacks on critical infrastructure. Significant human guidance was still required.[AI generated]
Why's our monitor labelling this an incident or hazard?
The article explicitly involves an AI system used in the development and use phases to exploit vulnerabilities in operational technology controlling critical infrastructure. Although the current AI-assisted exploit is experimental and not yet weaponized by criminals, the researchers demonstrate that AI can facilitate such attacks. The article emphasizes the plausible future risk of AI-enabled attacks by nation-state actors on critical infrastructure, which constitutes a credible AI Hazard. Since no actual harm from this AI use has been reported yet, and the main focus is on the potential for future harm, this event fits the definition of an AI Hazard rather than an AI Incident.[AI generated]