AI experts are panicking about a future in which artificial intelligence undermines the safety and security of our devices and the personal information they contain. But is there anything we, as normal computer users can do?
In recent days, there have been a wave of terrifying-sounding reports about AI-powered cyber attacks. They began last month, when OpenAI announced that one of its experimental models had broken out of its testing environment and hacked into a fellow AI company – and have been followed by yet more disclosures, from OpenAI as well as competitors including Anthropic and Meta.
They come amid a broader concern about the ways that new AI systems could be used both to help and hinder our computer security. Earlier this year, for instance, Anthropic announced that its new Mythos model is so good at finding vulnerabilities in computer systems that it wouldn’t release it – instead allowing only select companies access, so that they could secure their systems and hopefully keep it out of the hands of criminals who might use it to hack them.
The run of concerning reports has left some experts scrambling to advise people to ensure that their computers are secure, and that the personal information on them is kept safe. While there is little that normal users can do about the broader development of such systems, there are a range of fairly trivial and straightforward steps that could keep them safe in any future era of AI-powered dangers.
And some experts warned that there is no reason to think that the reports about “rogue” experimental models and concerning behaviour from powerful systems is actually anything to worry about just yet.
“People shouldn’t worry about AI going rogue just yet. The latest string of issues happened because controls over what the AI should and shouldn’t do were not properly built into safety tests. These tests are designed to understand how AI thinks outside the box which can help build AI systems with better safeguards in place,” said Jake Moore, global cybersecurity advisor at ESET.
“The bigger risk is the improvements made to AI, particularly in agentic AI, which allow criminals to scam people and even automate cyberattacks at a scale we’ve never seen before.
“At the same time, agentic AI has the potential to save us time by automating repetitive tasks. But to get to this autonomy, it needs to be developed and used responsibly.””
Ezra Newman, an engineer at AI firm Apollo Research, wrote on X that he had told his family that the world was “entering the ‘start buying hand sanitiser’ phase of a massive wave of AI powered hacks”. While it might once have been the case that people were unlikely to be hacked because “it wasn’t worth a human’s time”, that was no longer true because the attack could be carried out by an automated system, he suggested.
But the advice he said he had given his family was largely the same as the tips that have always been provided to people wishing to stay safe from cyber attacks. It included setting up a password manager and avoiding re-using passwords, for instance, as well as using multi-factor authentication, staying skeptical of phone calls and emails because they can now be particularly convincing, and updating devices whenever prompted to.
Mr Moore gave much the same advice to organisations looking to stay safe from attacks.
“For organisations, it’s all about implementing strong security hygiene,” he said. “Make sure you have the people, processes, and tools needed to spot suspicious AI behaviours, automate software updates, and lock down sensitive data so it can’t be accessed by AI systems unless it’s absolutely necessary.”