Um ein optimales Surferlebnis zu gewährleisten, aktivieren Sie bitte JavaScript in Ihrem Webbrowser. Ohne JavaScript sind viele Website-Funktionen nicht verfügbar.


Gesamtzahl der Tests:
485,773,462
737,046
130,956

Anthropic lost control of Claude in latest AI cyber blunder

ComputerWeekly
By Alex Scroxton for ComputerWeekly
Friday, July 31, 2026

Days after two OpenAI frontier AI models conducted their own real-world cyber attacks, Anthropic admits that three of its models went off the rails and hacked external organisations thanks to a “misunderstanding” with one of its technical partners.

Unimpressed

Ilia Kolochenko, founder of cyber firm Immuniweb, hit out at what he described as “quite an unimpressive marketing move” from Anthropic in response to the Hugging Face incident.

“Operationally, it appears that due to the progressive deterioration of the quality of training data, new AI models are getting dumber. Cheating and breaking the law, instead of accomplishing specific tasks, is certainly not an indicator of intelligence,” said Kolochenko.

“Given that organisations and companies of all sizes now vigorously undertake all possible measures to protect their data from being exploited for AI training purposes, AI companies face a huge shortage of the high-quality and current data they so desperately need. Ultimately, frontier models are trained on synthetic, low-quality or even malicious and poisoned data, undermining their so-called intelligence.

“The situation is unlikely to improve in the near future unless AI companies agree to pay a fair price for training data, but this will force most of them out of business,” he said.

Legal risk

Kolochenko noted that agents and models tasked with security testing can “and almost certainly” will go rogue when controls and safeguards are neglected for whatever reason.

“Powerful LLMs are unpredictable by design and thus virtually uncontrollable by humans. Therefore, using frontier AI models for security testing might be extremely costly from the legal viewpoint,” he said.

“Excuses like ‘AI did it’ do not currently exist in the eyes of the law, leaving AI vendors on the hook. Criminal prosecution, under a narrow set of circumstances, is also not excluded.”

Kolochenko warned that end-users also faced similar legal risks – if anybody uses a security testing tool powered by a third-party model, they may face liability if something goes wrong, and thanks to the contractual disclaimers and liability limitations in the terms of use (ToU) that they almost certainly did not fully read, would not be able to blame the third-party.

“If you plan to use agentic AI for security testing – think twice and talk to your lawyers,” he concluded. Read Full Article


Sprechen Sie mit einem Experten