
The information displayed in the AIM should not be reported as representing the official views of the OECD or of its member countries.
A survey commissioned by Germany's Federal Office for Information Security (BSI) and TÜV Association found that only 11% of German companies have established processes specifically for AI-related security incidents. Most rely on general IT security measures, leaving them vulnerable to potential AI-enabled cyberattacks.[AI generated]
Why's our monitor labelling this an incident or hazard?
The article explicitly states that AI is being used by criminals to conduct cyberattacks, including phishing and CEO fraud, which are forms of harm to organizations and individuals. The involvement of AI systems in these attacks is direct and has already led to realized harm. The article also notes the lack of adequate security measures in many companies, increasing vulnerability. This fits the definition of an AI Incident because the AI system's use has directly led to harm (fraud, deception, security breaches). The establishment of the AI Safety and Security Institute is a complementary response but does not negate the incident classification of the ongoing harms described. Hence, the primary focus is on the realized harms caused by AI-enabled cyberattacks, qualifying this as an AI Incident.[AI generated]