Can AI Recover its Reputation? Does it Care?
Let me give you the answer up front. Maybe, but it is going to be damn tough.
Yes, the major players – Meta, OpenAI, Anthropic, Twitter – agreed to a totally voluntary set of principles. There are no consequences for bending or even breaking these rules. It is purely a handshake agreement.
But here is what we are learning just this week about OpenAI from digital forensics firm Asymmetric Security. Asymmetric is a VC funded startup founded by experts from Crowdstrike, RAND, Palo Alto Networks and Stanford.
These allegations have not been validated by any third party – at least not yet, but these folks have more to lose by falsely accusing OpenAI that gaining from that.
The researchers say that rogue agents accessed data from 55 targeted websites, including sites belonging to the FBI, CDC, Mayo Clinic and others.
They also say that the “activity” extended beyond searching for information. They were looking for exposed configuration files, attempted to create accounts, route requests through third-party services to hide what they are doing and retrieve results through “unintended channels”.
They also attempted to erase records showing they were there and successfully accessed staging environments. They also used hacker reconnaissance tactics which may have been legal and may not have been legal.
They also broke out of their sandboxes and did things they were not supposed to do.
They worked to create fake accounts, even setting up mailboxes to be able to receive verification emails.
OpenAI apologized for some of these actions, but they did not disclose either the Hugging Face attack or the attack on the Australian government medical care site until after they were outed by the media.
Can these AI companies rehabilitate their images? Will they stop doing likely unethical and possibly illegal activities? Will they try to spin what they are doing? The truth is that no one knows. If history is an indicator, the answer is probably not. But maybe.
What does all of this mean to you? It means that the security methods that you thought were adequate last year are not adequate any more. Does that mean that you will have to spend more time and money securing your digital world? Unfortunately, probably yes. While we have not heard of (which is different from it did not happen) major damage as a result of these intrusions, these events are just beginning to be uncovered. We will continue to monitor this.
If you are not sure whether you are doing the right stuff, have us come do an assessment. What was adequate yesterday is not today and what is enough today will not be tomorrow. Sorry to be the bearer of bad news. Give us a call.
