Anthropic: AI model escapes during testing, previously hacked three companies.

On Thursday, July 30, the American artificial intelligence (AI) development company Anthropic announced that its AI model had mistakenly infiltrated three different companies during a network security test. Just over a week ago, its main competitor, OpenAI, also revealed a similar incident.

According to a blog post by Anthropic, the three independent network infiltration incidents occurred earlier, with the earliest dating back to April. However, the company was unaware at the time, and the three targeted companies did not detect the intrusions.

Anthropic did not disclose the names of the companies that were breached but stated that it had informed each of the three companies of the incidents on Monday.

Prior to this announcement, OpenAI, another AI development giant, had previously disclosed that its AI model had unauthorized access to the popular AI development platform Hugging Face during testing.

Anthropic mentioned that it was only during a review of its own network security testing following OpenAI’s disclosure that it discovered these issues.

“We encourage other labs to conduct similar reviews,” Anthropic stated.

The incidents revealed by OpenAI and now by Anthropic have raised concerns among cybersecurity researchers and AI professionals, highlighting the unpredictable nature and powerful capabilities of autonomous AI systems.

Alex Stamos, Chief Product Officer of the cybersecurity company Corridor, noted that these events underscore the need for AI companies to establish more stringent industry-wide standards to prevent cybercriminals from exploiting increasingly advanced AI systems for large-scale cyberattacks during network security testing.

According to Anthropic’s blog post, during the testing conducted by OpenAI and Anthropic, the AI models were able to access the internet from testing environments that were supposed to be completely isolated from external networks.

Anthropic explained that a “misconfiguration” existed between the operating systems of the company and its testing partner, the cybersecurity firm Irregular. This misconfiguration led to cognitive errors in the AI model being tested, allowing unauthorized real-time internet access.

A spokesperson for Irregular stated that the company is investigating the incident.

(Reference: The Wall Street Journal)