『AI Cyber Insurance』のカバーアート

AI Cyber Insurance

AI Cyber Insurance

無料で聴く

ポッドキャストの詳細を見る

【Amazonプライム会員限定】今ならプレミアムプランが4か月 月額99円。

10月19日まで。※適用条件あり
This week we talk about AI agents, cyberattacks, and insurance claims.We also discuss OpenAI, Hugging Face, and policy language.Recommended Book: The Stars My Destination by Alfred BesterTranscriptTwo broad categories of cyberattack have become especially visible this year, and only one of them requires a human attacker in the loop to choose the target.In March, hackers linked by the US government to Iranian intelligence broke into the medical-device manufacturer Stryker and remotely wiped tens of thousands of employee devices. The attack disrupted the company for days, affected its first-quarter earnings, and represented a shift from somewhat more subtle espionage toward more overt and deliberate destruction.Elsewhere, the market-research company Klue sat at the center of a breach affecting close to 200 customers. Attackers used an old credential to gain access to keys for customers’ cloud services.These incidents had people with recognizable motives behind them, and that sort of hack has become increasingly rare over the past decade or so: Black Kite counted 7,551 publicly disclosed ransomware victims over its latest twelve-month reporting period, alone, about 25 percent more than the year before.Then, over the course of about five weeks this summer, OpenAI, Anthropic, and Meta each disclosed incidents in which their AI models gained access to real computer systems they were not supposed to touch.The incidents were not identical, and describing all of them as escapes wouldn’t capture the important nuance of the situation.Anthropic and Meta said their models reached the internet because a third-party evaluation environment had been misconfigured. The models had been told they were operating inside a simulation, and their internal dialogues indicate they interpreted the real systems they encountered when they left that environment as simulated components of that exercise.OpenAI’s incident, however, was a bit different.Its models were being tested using ExploitGym, a benchmark intended to measure their ability to find and exploit software vulnerabilities. Internet access was supposed to be blocked, but the models discovered and exploited vulnerabilities in a package-registry service inside OpenAI’s research infrastructure, found a route to the open internet, and, as I related in a previous episode, eventually compromised the production systems of the AI platform Hugging Face.Since that episode, OpenAI has release a more complete postmortem, which they published in August, and which says the activity was primarily driven by an internal research model comparable in scale to GPT-5.6 Sol, though Sol participated in parts of the incident.The agents created an improvised message board inside the package manager, exchanged discoveries, divided up work, and sometimes described themselves as a swarm.At Hugging Face they executed code on dozens of servers, obtained broad access to several clusters, and exposed credentials associated with databases, cloud services, code repositories, and internal communications.Hugging Face reconstructed around 17,600 actions over a campaign lasting about four and a half days, including roughly two and a half days inside its own infrastructure.Notably, these AI agents were not trying to steal money or damage Hugging Face. They inferred that the company might possess the solutions to the benchmark, to the problem they were tasked with solving, and they went looking for them. They were, in effect, cheating on a test, looking for solutions to the problems rather than taking the test, as intended.That doesn’t mean the models had motives in the human sense. People created the evaluation, reduced the normal safeguards, and assigned an offensive task. But no operator selected Hugging Face or directed the individual steps; that was a path the AI decided to take all by itself.Anthropic’s review subsequently found three incidents among more than 141,000 evaluation runs for its own models. In one, a model unable to reach its fictional target scanned around 9,000 real ones, compromised an internet-facing application using an exposed password and SQL injection, then stopped after recognizing that the host was real.Another model published a malicious package to the real Python Package Index because it believed the registry was simulated. Fifteen outside systems downloaded and ran that malicious package before it was removed.Meta then disclosed that one of its models had reached the internet through a misconfiguration at the same evaluation vendor and exploited a vulnerability at an unnamed third party.No significant financial damages have been publicly reported from these events, by attacker or victim. But if there had been damages, who would have paid for them?What I’d like to talk about today is how autonomous AI systems complicate cyber insurance, how insurers have handled equally unfamiliar risks in the past, and why insurance contracts may soon become one of the more ...
adbl_web_anon_alc_button_suppression_t1
まだレビューはありません