In briefBoth OpenAI and Anthropic have revealed in recent days that their models autonomously hacked other organisations.An AI cybersecurity expert says organisations must now arm themselves with "the ability to react at the same machine speed that the AI would have".Recent incidents involving some of the world's most advanced artificial intelligence companies have exposed emerging challenges in an increasingly complex cybersecurity landscape. This week, Anthropic, the AI company behind the digital assistant Claude, said its AI models compromised real-world systems belonging to three other organisations during internal testing, compromising their infrastructure by exploiting weak passwords and other basic techniques. The company said it had discovered the incidents after launching a review in response to an announcement days earlier by OpenAI, the maker of ChatGPT. OpenAI recently revealed that one of its models had broken free from its virtual testing environment and hacked another tech company, Hugging Face.Germaine Tan Shu Ting, vice president of security and AI at AI cybersecurity platform DarkTrace, told SBS News these developments were "very concerning".News that makes senseYour trusted source for staying up-to-date with the world around you. Get free daily news updates and analysis, straight to your inbox."The big question that we have in the back of our head is: if these incidents are happening to the likes of OpenAI and Anthropic, what's to say that's not happening to other data systems, other AI systems in the world?" she said. "The answer is: We will never know."Tan Shu Ting said that the fact both companies had publicly disclosed the incidents was reassuring, but it underscored the need for organisations to shield themselves against increasingly autonomous systems that can operate at unprecedented pace. How can organisations protect themselves?Tan Shu Ting said companies must get the basics right, be prepared, and have systems in place to detect anomalies and AI threats."Get control of your data. Basic cyber-hygiene. Get visibility of what you have, and then arm yourselves with the ability to react at the same machine speed that the AI would have," she said."So they would say, never bring a knife to a gunfight, and I think it's very relevant here. "You need to be able to act as fast as these AI systems. So how do you set yourself up for those situations?"Regulations will also provide an important layer of safety, she said — but many experts have flagged concerns that legislative protections are not keeping pace with the rapid advances in AI. The technology has been adopted by nearly 53 per cent of the world’s population in three years, faster than the spread of the PC or the internet, according to a study released this year by Stanford University."Before advanced AI agents are widely deployed, organisations need stronger containment, limited access, continuous monitoring, clear audit trails, reliable shutdown controls and independent safety testing," Walayat Hussain, head of the Information Technology and Systems discipline at the Australian Catholic University, said last week."The lesson is not that we should stop developing advanced AI, but that safety, governance and red teaming must develop just as quickly as the technology itself.”The race to regulateLast month, Prime Minister Anthony Albanese announced a plan to legislate a set of AI standards by early next year.It is expected to address education and training, workplace rights and productivity, and a plan to fast-track data-centre approvals to attract investment in Australia. Countries around the world are racing to implement better AI legislation, with these latest incidents amplifying pressure from officials in the US and Europe for greater government oversight of AI companies. "We're looking at controls," US President Donald Trump told reporters on Thursday.The European Commission said it had been briefed by OpenAI and Anthropic over the hacking incidents.Europe's AI Act, which comes into force on Sunday, is one of the most aggressive regulations the high-tech sector has faced so far, as fears rise over the risks AI poses to society. Under the act, AI companies will be required to make clear to consumers, through labels or digital watermarks, that chatbots or imagery are generated with AI.The European Commission said in a statement that new regulations also aim to address "systemic risks" posed by AI like "chemical, biological, radiological and nuclear incidents, loss of control, cyber offense, harmful manipulation and threats to fundamental rights".Failure to comply could result in fines of millions of Euros or a percentage of the company's global turnover.— With additional reporting by Reuters and the Associated Press news agencies.For the latest from SBS News, download our app and subscribe to our newsletter.
'Never bring a knife to a gunfight': The next frontier in online security
Two incidents involving rogue AI behaviour have highlighted new challenges and amplified calls for stronger guardrails.
OpenAI and Anthropic disclosed autonomous AI breaches exploiting weak passwords and basic security gaps. Organizations need machine-speed threat detection and response; global regulations race to implement governance before autonomous AI scales.















