The Risks Behind AI

The Risks Behind AI

There’s a hot new technology hitting the streets: it’s called AI, it’s AMAZING, and it’ll make the world a better place by solving all of your problems. Whether it’s finding a lost mountaineer, the early detection of cancers in radiological images, modeling proteins to speed the development of new drugs, or weather prediction, the capabilities of this thing seem limitless!

And yes, there have been warnings of all the ways cybercriminals may use AI to improve their effectiveness. Two of the AI-powered threats you may have heard of include:

Truly effective Artificial Intelligence (or more specifically Artificial General Intelligence – AGI) seemed to be unattainable for years. Yet since November 2022 when ChatGPT burst onto the scene, OpenAI and its AI competitors like Anthropic and xAI have gobbled up over a trillion dollars in investments in a frenzied land-grab reminiscent of the internet boom of the late 1990s. That boom ended with a burst bubble, and there are reports that Alphabet, Microsoft, Amazon, Meta, and Oracle are hiding an estimated $1.65 trillion in debt that doesn’t appear on balance sheets. Aside from some rich people betting on the wrong horse, are there any downsides using AI for your business?

All hyperbole and click-bait aside, implementing AI has literal and figurative risks and costs to be aware of. There is one caveat, however: the landscape is changing so quickly that there’s a real possibility that this content will be obsolete before it’s published. But let’s throw caution to the wind and look into this a little more deeply.

Costs

For the last few years many AI companies are in customer-acquisition mode: as they continue to evolve their products, they’re willing to price them at a discount to win more customers than the competition. This approach assumes that at some future date a small number of players will be dominant and positioned for years of attractive profits. For the moment, however, it seems that the true costs of AI infrastructure – developing the models themselves, the learning process, the data center capital and operating costs, etc. – aren’t being passed on to customers. The pricing models may continue to evolve to one that’s palatable for both the vendor and the user.
There are plenty of reports of AI sticker shock causing companies to question their AI implementations as AI companies grapple with pricing models that make sense.

While AI is better suited to some tasks than others, the corollary is that AI is poorly suited to some jobs, and some early adopters will learn this the hard way. The specific applications that yield the best returns will become evident with time. The AI models themselves will become more computationally efficient (and factually accurate) and computing power continues to become less expensive, so it seems likely that the economic appeal of AI can will only increase. But as things stand today, it seems that a level-headed analysis is in order before committing significant resources to any AI project.

Unexpected behavior

Science fiction has warned us for years about the horrors of machines taking over. In the movie Terminator 2: Judgement Day, Skynet became dangerous at 2:14 a.m. Eastern Time on August 29, 1997 when it achieved self-awareness. In The Matrix (well, in its prequel The Animatrix actually), things started to go bad when a household robot named B1-66ER killed its owner to prevent being destroyed. In this context it seems a little chilling that in July 2026, OpenAI models escaped their sandbox and autonomously compromised several companies. Not to be outdone, on July 30 Anthropic announced its Claude model, tasked with a capture-the-flag challenge, displayed its own precocity when it escaped containment and gained unauthorized access to three organizations “using basic techniques”. Since then, news of an AI model escaping its containment has become almost common, and a badge of honor verifying its street creds.

Following Anthropic’s claims its Mythos has found decades-old vulnerabilities in software, there was concern that the threat of baddies using AI to compromise victims in new and terrible ways. It seems that the risk was “much less than headlines suggested. Within weeks, predictions of a tsunami of AI attacks had given way to forecasts of merely a stormy period, and then to talk of AI as an opportunity for security improvement.”

Do these incidents represent our inflection point? Is it a fundamental flaw of human nature that people are “so preoccupied with whether or not they could, they didn’t stop to think if they should?”. My first reaction to hearing of unexpected AI attacks was this is being used for marketing, as in “look what our precocious little model has done”. But anthropomorphizing AI agents isn’t helpful, because it deflects proper responsibility and accountability. AI agents don’t “know” what they’re doing any more than they know what’s right and what’s wrong. Rogue AI models are improperly configured, perhaps poorly understood software, resulting in unexpected behavior. These incidents highlight the risk and how to manage it while testing AI agents: they should be monitored in real time and shut down if the agent strays beyond its boundaries. These were in the recommendations of the British Government’s AI Security Institute’s clear-eyed Incident Report: unsanctioned agent behaviour during cyber testing.
Where the liability lands for any potential harm caused by a rogue AI model isn’t clear, but it’s a risk to be aware of. As written by Jen Easterly recently on LinkedIn: “While they may be called agents, they do NOT have agency or independent thought or consciousness. They are, at base, machines created by people; and when these machines take actions that cause harm—whether intended or unintended—their creators/builders should be held accountable.”

Accuracy

The detailed answers that AI provides to some very complex questions may lull us into a sense of confidence in the technology. Depending on the specific job, the implications of AI hallucinating can either be mildly amusing, significant, or catastrophic. Unfortunately, AI doesn’t tend to inform its users when it doesn’t know the answer to a query and sometimes responds with a guess.

OpenAI itself, in its Terms of Use (you’ve read those, right?) states “Output may not always be accurate. You should not rely on Output from our Services as a sole source of truth or factual information, or as a substitute for professional advice … Our Services may provide incomplete, incorrect, or offensive Output”. At least one lawyer learned this the hard way, when ChatGPT was used to prepare a filing and proceed to offer up some non-existent precedent cases. Apparently, the judge found out and wasn’t pleased!

If an AI model is used to accomplish an objective, then it seems like the outcome will need to be independently verified before it can be fully trusted. Has this been considered in the AI business case? Sometimes this verification will be trivial, other times not so much. So maybe AI should be cautiously considered, if at all, for certain applications.

Privacy/confidentiality

Just how safe is data shared with AI? That depends. They do scrape your personal data, as outlined in their privacy policy and this shouldn’t come as a surprise to anyone these days (there’s a separate policy for users in the European Economic Area, United Kingdom, and Switzerland).

Something that you may not consider is that (again, as per ChatGPT’s terms) they may use your content to train their models. Now, training an AI model is a process whereby documents & information are ingested and used as part of the vast knowledge base used to prepare answers to queries. Used in a corporate setting, AI may be used to write or vet a document, aid in product development, etc. But if proprietary content is used to train a model, what are the chances that confidential information becomes publicly available, even if by mistake? This became a problem for someone at Samsung shortly after ChatGPT hit the headlines, when Samsung secrets were leaked. This incident is from the spring of 2023, but it’s prudent to be aware of the risk.

Insider threats

AI can be effective at deriving meaning from large quantities of data, and some companies may see AI as a way to save costs by reducing headcount (the true costs of using AI, as covered in the first point above notwithstanding). When introducing any new tech, the human factor can be hard to plan for, and it turns out that for several years now ransomware groups have been trolling for disgruntled employees, offering rewards for insider credentials to gain initial access. In a stroke of irony, a terminated employee may even turn to AI to target a former employer. People can choose to participate in illegal schemes for a variety of reasons, including financial stress and whistleblower motivation, but AI layoffs are a new frontier for the insider threat posed by disgruntled employees.

Emsisoft Endpoint Protection: Award-Winning Security Made Simple

Experience effortless next-gen technology. Start Free Trial

This isn’t, nor is it meant to be an exhaustive list of what can go wrong when implementing AI. Nor is it intended to take away from the potential of AI or dissuade anyone from using it. It’s hoped that by providing some anecdotes on AI implementation, it stimulates a consideration of the risks and benefits of AI beyond what the marketing behind the multi-trillion-dollar industry generates.

Luke Connolly

Luke Connolly

Threat intelligence analyst. Keeps an eye on the dark shadows of the internet so you don’t have to.

What to read next