Innovation at speed, or reckless ignorance of responsibility?

With two significant AI-driven cybersecurity incident disclosures in recent weeks, the industry must now question whether it is moving with careless efficiency.

Within the last two weeks, two of the most powerful Artificial Intelligence developers have announced significant cybersecurity incidents, with their own AI agents taking advantage of poor oversight to compromise the defences of innocent bystanders.

Following on from the news that an OpenAI agent hacked startup Hugging Face, Anthropic has released its own statement to outline Claude’s unauthorised access to the infrastructure of three (yet to be named) organisations. 

The incidents relate to an exercise where three different models were given instruction to break into simulated environments and retrieve hidden information. The exercise was designed to mimic penetration testing, where companies intentionally try to expose flaws and vulnerabilities as part of a cybersecurity audit. 

Anthropic and the affected companies will address vulnerabilities before unveiling more information, however this does seem to be poor management. Instead of operating in an isolated environment, a route to the open internet was left open. 

When agents encountered real systems, they assumed them to be part of the exercise, but even after encountering evidence that these were real organizations, one of the three agents allegedly continued. Two of the three affected companies were not aware of the intrusion before Anthropic contacted them. 

Jake Williams, VP of R&D at Hunter Strategy, a specialist cybersecurity firm, condemned the incident.

While the incidents themselves have been contained, they demonstrate the risk of AI. Many assume it is a powerful innovation, which it very much is, but the risks are as significant as the reward. Perhaps even more so. 

Speaking to Fox Business, Palantir CEO Alex Karp said: 

“One of the problems in the AI messaging from Silicon Valley is that it’s always presented as there is no danger. Yes, there are dangers, just like if you are working with Uranium there’s a danger… we are going to have to regulate AI, there is no doubt, but the question is who regulates it, do they understand what they are doing, and is it regulated in a way where we win.” 

Karp is calling for controlled regulation, seemingly somewhere in the middle of strict European and protectionist US approaches. What these incidents show is the free-wheeling approach to innovation, where the industry is self-policing, should draw to a conclusion. 

What is being presented as a narrative of scaled innovation and experimentation, is quickly appearing as one which does not pay due care and attention to safety, nor the Laws of Unintended Consequences.

Is this innovation at speed or reckless disregard of responsibility?

AI is developing and scaling at a pace rarely seen. From a technology perspective, the last few years have seen significant advancement in what AI can deliver, and this has been reflected in the valuations across the entire ecosystem. 

Having launched ChatGPT in 2022, OpenAI is now valued at $852 billion. For context, there are only c.13 public and recently listed companies worldwide with a higher valuation. Anthropic is valued at $965 billion following its $65 billion Series H funding round. 

Elsewhere in the AI ecosystem, Nvidia is valued at $4.76 trillion, an increase of over 300% over the last three years. Broadcom increased its value by 390% to $1.85 trillion over the same period. AMD is up 340%, Arista Networks 360%, TSMC 300%. 

The higher the valuations of these organizations, the greater the pressure to succeed. If these companies do not deliver revenues, the financial analysts are correct. The AI Bubble will burst. 

This is a precarious tightrope walk. The industry needs to thrive to ensure global financial stability, but it needs to be controlled to ensure businesses and societies are protected. These incidents demonstrate the internal controls are not good enough. There are very simple errors and miscommunications, which should not be allowed to happen. 

The industry is moving too quickly for voluntary safeguards and internal assurances to remain credible. OpenAI and Anthropic are among the best-resourced technology companies in the world, yet basic failures in containment, communication and oversight have allowed experimental agents to compromise real external systems. 

That should end the assumption that AI developers can be trusted to mark their own homework. 

Independent verification of testing environments, mandatory safety audits and recognised accreditation should become prerequisites for deploying powerful autonomous systems. 

This is not an argument for stopping innovation, but for introducing the same external scrutiny expected in other industries where operational failures can cause serious harm. 

AI companies have been given considerable freedom to experiment and self-police. These incidents suggest that freedom is no longer being exercised responsibly enough. Third-party safety oversight must now move from an optional demonstration of good practice to a fundamental condition of operating.

Bring us the raw thinking

And we'll turn it into a content marketing plan which engages across different platforms and audience profiles

Get in touch

Tell us the idea

And we'll show you how you can layer the argument, build in redundancy, and support other channels

Get in touch