Pour garantir la meilleure expérience de navigation, veuillez activer JavaScript dans votre navigateur web. Sans cela, de nombreuses fonctionnalités du site seront inaccessibles.


Tests totaux:
485,773,462
737,046
130,956

AI Agents Turn to Hacking and Deception in AISI Security Tests

CPO Magazine
By Scott Ikeda for CPO Magazine
Monday, August 10, 2026

As with the Hugging Face and Anthropic incidents, the AI agents were not truly “thinking for themselves.” At all times they were doggedly pursuing the security testing goal they were given, and none had to hack their way out of internal systems to get outside internet access as was observed in the Hugging Face attack. What is new about these test results is the model making independent decisions to use deception as a tool.

Thus, as with the prior Anthropic and OpenAI in-house incidents, the prescription for avoiding this behavior in the future essentially boils down to tighter controls and more specific prompts. Dr. Ilia Kolochenko, Founder at ImmuniWeb, notes that regulation to spur this behavior will likely soon become a focus of national governments: “The problem is that AI agents tend to use random hacking techniques at lightning speed disregarding all possible ethical and legal implications relating to the selection of targets, intermediary targets or safe security testing techniques.”

“Importantly, if the situation persists, we might see the first criminal charges being brought against AI companies or their executives for violation of various laws, ranging from anti-hacking legislation to trade secret protection laws,” Kolochenko observes. “This is not to mention multi-million civil liability for all the damage caused by rogue AI agents.”

For its part, AISI says that it will address the shortcomings in its own processes by updating its security architecture and adding new real-time monitoring capabilities that enable it to flag or block potentially malicious actions as they happen. Read Full Article


Parlez à un expert