{"id":127047,"date":"2026-08-02T05:01:11","date_gmt":"2026-08-02T05:01:11","guid":{"rendered":"https:\/\/www.europesays.com\/ai\/127047\/"},"modified":"2026-08-02T05:01:11","modified_gmt":"2026-08-02T05:01:11","slug":"its-ai-problem-now-why-bots-attacking-their-brethren-could-quickly-turn-ugly","status":"publish","type":"post","link":"https:\/\/www.europesays.com\/ai\/127047\/","title":{"rendered":"It&#8217;s AI problem now: Why bots attacking their brethren could quickly turn ugly"},"content":{"rendered":"<p class=\"defaultstyled__StyledText-sc-11u52t4-1 eVvrYS margin-lg-bottom\" id=\"el-0-G4Q6EVPYTRG65KN2OYRRUZMY6Y\">OpenAI and Anthropic, two of the leaders in generative <a href=\"https:\/\/www.thenationalnews.com\/future\/technology\/2026\/07\/29\/ai-energy-electricity-tommy-joyce\/\" target=\"_blank\" rel=\"noreferrer nofollow noopener\" title=\"https:\/\/www.thenationalnews.com\/future\/technology\/2026\/07\/29\/ai-energy-electricity-tommy-joyce\/\">artificial intelligence<\/a>, are in hot water right now, and the situation could be reaching a boiling point.<\/p>\n<p class=\"defaultstyled__StyledText-sc-11u52t4-1 eVvrYS margin-lg-bottom\" id=\"el-1-TUC4ME5GQRH77KT63HLDK6OQTU\">ChatGPT&#8217;s maker OpenAI, regarded as the trigger for the generative AI revolution, disclosed last week that <a href=\"https:\/\/www.thenationalnews.com\/future\/technology\/2026\/07\/22\/ai-model-escapes-and-hack-another-company-during-testing\/\" target=\"_blank\" rel=\"noreferrer nofollow noopener\" title=\"https:\/\/www.thenationalnews.com\/future\/technology\/2026\/07\/22\/ai-model-escapes-and-hack-another-company-during-testing\/\">one of its AI models escaped<\/a> from an isolated environment and attacked the AI start-up Hugging Face. Shortly thereafter, the US cloud firm Modal was also reported to have been hacked.<\/p>\n<p class=\"defaultstyled__StyledText-sc-11u52t4-1 eVvrYS margin-lg-bottom\" id=\"el-3-INC54EEBUZEDVBAMK57J5GWIGI\">On Thursday, <a href=\"https:\/\/www.thenationalnews.com\/future\/technology\/2026\/07\/31\/anthropic-says-claude-ai-breached-three-organisations-during-cyber-tests\/\" target=\"_blank\" rel=\"noreferrer nofollow noopener\" title=\"https:\/\/www.thenationalnews.com\/future\/technology\/2026\/07\/31\/anthropic-says-claude-ai-breached-three-organisations-during-cyber-tests\/\">Anthropic, known for its Claude AI bot<\/a>, said its models were able to gain unauthorised access to the systems of three companies during cybersecurity testing. <\/p>\n<p class=\"defaultstyled__StyledText-sc-11u52t4-1 eVvrYS margin-lg-bottom\" id=\"el-4-PIT22GHCS5C3HMEHGNLAPHGOH4\">These happened within a week. Even before the Anthropic incident, analysts believed the situation was already a problem that could become lengthy and ugly.<\/p>\n<p class=\"defaultstyled__StyledText-sc-11u52t4-1 eVvrYS margin-lg-bottom\" id=\"el-6-2DYYMXHWHJC4RE3UYBBPZQX55Y\">\u201cThis is already a problem in its early form. We are not yet seeing AI run full-scale, end-to-end cyber campaigns independently, but that is not the point,\u201d Michael Mossad, a partner for cyber emerging technologies at Deloitte Middle East, told The National.<\/p>\n<p class=\"defaultstyled__StyledText-sc-11u52t4-1 eVvrYS margin-lg-bottom\" id=\"el-7-MPCEYRHVPJBEFMNAS3DNP6NCZA\">\u201cAI is already acting as a force multiplier, helping attackers move faster, personalise attacks more effectively, and experiment more cheaply. In cybersecurity, that alone is enough to shift the threat landscape.\u201d<\/p>\n<p>Nothing new?<\/p>\n<p class=\"defaultstyled__StyledText-sc-11u52t4-1 eVvrYS margin-lg-bottom\" id=\"el-9-CXJ5U2JAPZFVRJJP46KWMFZA2U\">AI agents \u2013 autonomous models capable of making decisions and achieving specific goals with limited supervision \u2013 are at the centre here. In the case of the OpenAI and Anthropic incidents, however, there seems to be a problem keeping them within their confined spaces.<\/p>\n<p class=\"defaultstyled__StyledText-sc-11u52t4-1 eVvrYS margin-lg-bottom\" id=\"el-10-46TZTV5L6JDWBGS24ANDCK4MF4\">Mohammed Aboul-Magd, general manager for cybersecurity at AI and <a href=\"https:\/\/www.thenationalnews.com\/future\/technology\/2024\/10\/24\/sandboxaq-quantum-ai-uae\/\" target=\"_blank\" rel=\"noreferrer nofollow noopener\" title=\"https:\/\/www.thenationalnews.com\/future\/technology\/2024\/10\/24\/sandboxaq-quantum-ai-uae\/\">quantum tech firm SandboxAQ<\/a>, said the issue is that agents are moving faster than oversight.<\/p>\n<p class=\"defaultstyled__StyledText-sc-11u52t4-1 eVvrYS margin-lg-bottom\" id=\"el-12-EWWULPDZGBEY7NXNJUBTHUVXSA\">And unlike test beds, projections, or lab papers, it affected real-world infrastructure.<\/p>\n<p class=\"defaultstyled__StyledText-sc-11u52t4-1 eVvrYS margin-lg-bottom\" id=\"el-13-ZEFKMR52BVC33ECJBPTFJSOH3Q\">\u201cAgent capability is outpacing agent oversight everywhere and the infrastructure to evaluate, monitor and contain these systems is years behind the systems themselves,\u201d he told The National.<\/p>\n<p class=\"defaultstyled__StyledText-sc-11u52t4-1 eVvrYS margin-lg-bottom\" id=\"el-14-WW6LSVYV6BCLPNG537B3NXRJRQ\">\u201cThe capability arrived on schedule. The discipline around it didn&#8217;t \u2026 it&#8217;s a now problem,\u201d he said.<\/p>\n<p class=\"defaultstyled__StyledText-sc-11u52t4-1 eVvrYS margin-lg-bottom\" id=\"el-16-L5YWH6T7GFATBMTGOAPN3ONM3Q\">Meanwhile, semi-autonomous offensive tooling \u2013 cybersecurity software that simulates an attack but is still guided by a human \u2013 has been in the open for more than a year, noted Ivan Milenkovic, a vice president for cyber risk technology at US tech firm Qualys.<\/p>\n<p class=\"defaultstyled__StyledText-sc-11u52t4-1 eVvrYS margin-lg-bottom\" id=\"el-17-VACKPHNOOZHYZIXI75U6HOS77E\">In November, Anthropic itself disclosed that it was able to \u201cdisrupt\u201d attempts by a state-linked actor to use some of its agentic capabilities for a cyberattack.<\/p>\n<p class=\"defaultstyled__StyledText-sc-11u52t4-1 eVvrYS margin-lg-bottom\" id=\"el-18-QQH7G6YWARGWDBVRDLK7QV7KFA\">What happened recently with OpenAI is the first fully documented autonomous case, and it ran from July 9 to 13 before anyone was able to stop it.<\/p>\n<p class=\"defaultstyled__StyledText-sc-11u52t4-1 eVvrYS margin-lg-bottom\" id=\"el-19-NADLN572UBASBLLWJQPWXF6TWQ\">\u201cThe issue isn&#8217;t the timeline. It&#8217;s comprehension. Plenty of environments still treat agents as clever software rather than as privileged, active participants in the business,\u201d Mr Milenkovic told The National.<\/p>\n<p class=\"defaultstyled__StyledText-sc-11u52t4-1 eVvrYS margin-lg-bottom\" id=\"el-20-ZSYGHRMFZ5BUXPKYWPOYBSC5RA\">\u201cIf you can&#8217;t answer [these] three questions \u2013 who is the named human owner of every agent running in your estate, what can each of them reach and who can shut one down within the hour, without asking a committee \u2013 you are exposed.\u201d<\/p>\n<p class=\"defaultstyled__StyledText-sc-11u52t4-1 eVvrYS margin-lg-bottom\" id=\"el-21-KHRBMHH6QZDWXGSFIECKKM6SLE\">\u201cQuite frankly, it&#8217;s [already] a yesterday problem \u2026 sloppiness used to have a fixed cost. It&#8217;s now variable, and the multiplier is compute.\u201d<\/p>\n<p>Worst-case scenarios<\/p>\n<p class=\"defaultstyled__StyledText-sc-11u52t4-1 eVvrYS margin-lg-bottom\" id=\"el-23-GXUD23NBZ5DWPLUSB4RKRX4KOM\">That brings us to a pressing question: While AI agents can act on their own, where does the buck stop when it comes to the humans responsible for running them?<\/p>\n<p class=\"defaultstyled__StyledText-sc-11u52t4-1 eVvrYS margin-lg-bottom\" id=\"el-24-6FD2GDGU6BAJXGXVS5S7BZK5PU\">The answer is complex, argues Dr Imran Zualkernan, head of the department of computer science and engineering at American University Sharjah.<\/p>\n<p class=\"defaultstyled__StyledText-sc-11u52t4-1 eVvrYS margin-lg-bottom\" id=\"el-25-HUD2E4CF3JHNLM2JVEDR5PGBQE\">The EU AI Act, for instance, outlines the responsibilities of various stakeholders such as model providers and programmers; the UAE is moving in this direction as well. Other jurisdictions require just minimum security measures for AI.<\/p>\n<p class=\"defaultstyled__StyledText-sc-11u52t4-1 eVvrYS margin-lg-bottom\" id=\"el-26-7LI47DZZV5GWHMNZLB5FMHYI64\">\u201cIn general, the responsibility of a human is limited if they lacked knowledge and control, were perceived to act competently, transparently disclosed risks, implemented proportionate safeguards and could not reasonably foresee the later independent misuse,\u201d Dr Zualkernan told The National. He also agrees that the situation is a problem that is \u201chere now\u201d.<\/p>\n<p class=\"defaultstyled__StyledText-sc-11u52t4-1 eVvrYS margin-lg-bottom\" id=\"el-28-GSSDZ5C5LJDL5G3T22B2WSLFVI\">Among the most basic questions that AI firms should be able to answer are whether the systems have been thoroughly evaluated before they went live and whether they are being monitored while in operation, among several others, added Mr Aboul-Magd.<\/p>\n<p class=\"defaultstyled__StyledText-sc-11u52t4-1 eVvrYS margin-lg-bottom\" id=\"el-29-R2PQIGZUPBHA7JGP6BL5KWUHHA\">\u201cResponsibility doesn&#8217;t end at deployment, it extends across the life cycle \u2026 can you reconstruct what it did, if something goes wrong?\u201d<\/p>\n<p class=\"defaultstyled__StyledText-sc-11u52t4-1 eVvrYS margin-lg-bottom\" id=\"el-30-WZWKN2SQPZAAHIYRDRLXRZWSRE\">And there are several ways things can get ugly; the OpenAI and Anthropic incidents are just samples.<\/p>\n<p class=\"defaultstyled__StyledText-sc-11u52t4-1 eVvrYS margin-lg-bottom\" id=\"el-31-PS47QBSFGNFGBE4AFEW4OIDWQ4\">\u201cThe exceptional ability of AI agentic models to penetrate public infrastructure, software repositories and digital commerce will result in a large-scale loss of trust in digital services across the board with a retroactive impact on the world economy,\u201d Dr Zualkernan said.<\/p>\n<p class=\"defaultstyled__StyledText-sc-11u52t4-1 eVvrYS margin-lg-bottom\" id=\"el-32-KCGSIHQ5DBAONJBIONSB2FRG7I\">Added Mr Mossad: \u201cThe worst-case scenario is not AI becoming evil or sentient. It is powerful frontier AI models becoming cheap, accessible and easy to weaponise.\u201d<\/p>\n<p>Regulators keeping an eye<\/p>\n<p class=\"defaultstyled__StyledText-sc-11u52t4-1 eVvrYS margin-lg-bottom\" id=\"el-34-GXGFNSOCUZGTVAN7TH42WC2AEA\">Governments and regulators, who are already fed up to varying degrees with AI&#8217;s troubles, are again having to deal with this new tech headache.<\/p>\n<p class=\"defaultstyled__StyledText-sc-11u52t4-1 eVvrYS margin-lg-bottom\" id=\"el-35-NDYH4WYQI5GCTKL5RGA5QJTAVY\">Regulators are likely to see this through the lens of public safety, economic resilience and national security, Mr Mossad said.<\/p>\n<p class=\"defaultstyled__StyledText-sc-11u52t4-1 eVvrYS margin-lg-bottom\" id=\"el-36-I6W72OHDXBAM3EETP3L6I3QINI\">If frontier AI models could materially enable cybercrime or attacks on critical systems, regulators would then ask whether the risks were foreseeable, whether sufficient measures were taken to prevent misuse, and whether proof had been provided, he noted.<\/p>\n<p class=\"defaultstyled__StyledText-sc-11u52t4-1 eVvrYS margin-lg-bottom\" id=\"el-37-ISFCVBXTZ5BHVADAOCAXVZFP6M\">\u201cThis is not a distant or hypothetical issue. The real danger is not AI replacing hackers, but rather AI expanding the pool of people who can cause harm and increasing the scale at which they can do so,\u201d Mr Mossad said.<\/p>\n<p class=\"defaultstyled__StyledText-sc-11u52t4-1 eVvrYS margin-lg-bottom\" id=\"el-38-CJXXU6ZW5BGGVDA5FEHFWZXBKY\">\u201cThat is why security cannot be treated as an afterthought in AI development. With frontier models, trust and control must be part of the design, not added later as damage control.\u201d<\/p>\n<p class=\"defaultstyled__StyledText-sc-11u52t4-1 eVvrYS margin-lg-bottom\" id=\"el-39-Q3X2GQFDQZE6ZKL5SMBY3ZMGLY\">For the EU, obligations under its AI legislation for general-purpose models with systemic risk already cover evaluation, adversarial testing, cybersecurity and serious incident reporting.<\/p>\n<p class=\"defaultstyled__StyledText-sc-11u52t4-1 eVvrYS margin-lg-bottom\" id=\"el-40-BNALBZTSUBDCHHNHL5G73WOXZY\">\u201cThe unresolved question is definitional. Does a capability evaluation that reaches an uninvolved production system count as a serious incident, and does the duty to report sit with the lab or with the victim? Nobody has ruled,\u201d Gerald Beuchelt, chief information security officer of Swiss cybersecurity platform Acronis, told The National.<\/p>\n<p>The legal view<\/p>\n<p class=\"defaultstyled__StyledText-sc-11u52t4-1 eVvrYS margin-lg-bottom\" id=\"el-42-DMXYDARMAJH7BCG4BIAJ6J4FSU\">The OpenAI and Anthropic incidents happened in the US, where government policies are reactive to AI models.<\/p>\n<p class=\"defaultstyled__StyledText-sc-11u52t4-1 eVvrYS margin-lg-bottom\" id=\"el-43-GTQ4KB7EJBH6RHDQBCUUSKLSCQ\">But until Washington gets its act together, opaque model testing and selective disclosure are to be expected, meaning discoveries of exploits in software \u2013 like those found in OpenAI&#8217;s models that punctured their testing sandbox to hit Hugging Face and Modal \u2013 would continue, said Peter Jackson, intellectual property counsel at the Los Angeles law firm Greenberg Glusker.<\/p>\n<p class=\"defaultstyled__StyledText-sc-11u52t4-1 eVvrYS margin-lg-bottom\" id=\"el-44-EOPJMURPN5GMVOGL2RPT7Q7A4I\">\u201cWithout testing models\u2019 raw capabilities, those safety guardrails won\u2019t be as effective. Moreover, responsible testing can uncover zero-day exploits so they\u2019re confidentially disclosed and patched before they can be exploited by bad actors,\u201d he told The National.<\/p>\n<p><img decoding=\"async\" type=\"image\" data-chromatic=\"ignore\" alt=\"\" loading=\"lazy\" fetchpriority=\"auto\" src=\"https:\/\/www.europesays.com\/ai\/wp-content\/uploads\/2026\/08\/https:\/\/cdn.jwplayer.com\/v2\/media\/T43Ga8hh\/poster.jpg\" width=\"279\" height=\"496\"\/><\/p>\n<p>Pope Leo calls for AI to be &#8216;disarmed&#8217;<\/p>\n<p class=\"defaultstyled__StyledText-sc-11u52t4-1 eVvrYS margin-lg-bottom\" id=\"el-46-X7X45BDGL5HMBH2BCQXJMGLIOY\">\u201cRegardless of who supplies and operates the testbeds, regulators could push for what we expect to see in peer-reviewed science: consensus-based standards for experiment design and full disclosure of results.\u201d<\/p>\n<p class=\"defaultstyled__StyledText-sc-11u52t4-1 eVvrYS margin-lg-bottom\" id=\"el-47-7RRMKXNGURA4BD7BGUEMXYSZPI\">That&#8217;s comparable to one standard procedure in the pharmaceutical industry: halting a drug study if researchers believe the drug is killing patients.<\/p>\n<p class=\"defaultstyled__StyledText-sc-11u52t4-1 eVvrYS margin-lg-bottom\" id=\"el-48-PGCSWRPISBHMHKSYZIIFHC7SMQ\">\u201cResponsible testing and remediation has been a core premise of the laissez-faire approach regulators have taken to what developers can publicly release,\u201d Mr Jackson said.<\/p>\n<p class=\"defaultstyled__StyledText-sc-11u52t4-1 eVvrYS margin-lg-bottom\" id=\"el-49-2F7JXKYJGVH2XJUO7DACMSX2HM\">\u201cIf regulators feel compelled to intervene at the testing stage, it\u2019s hard to imagine they won\u2019t become stricter about what developers are permitted to make available on the market.\u201d<\/p>\n<p>AI spending rabbit hole<\/p>\n<p class=\"defaultstyled__StyledText-sc-11u52t4-1 eVvrYS margin-lg-bottom\" id=\"el-51-JDK72LLZYZDTNP7IA6N6ZHOWE4\">Meanwhile, Big Tech&#8217;s big-time AI spending continues, as they position themselves in what, at the moment, feels like an endless race.<\/p>\n<p class=\"defaultstyled__StyledText-sc-11u52t4-1 eVvrYS margin-lg-bottom\" id=\"el-52-5AOXTPMWYZC4RJJHC3QRFOREEA\">\u201cIt\u2019s difficult to define what constitutes &#8216;too much&#8217; AI investment. The equation differs between companies building AI infrastructure and models, and those integrating AI into their existing businesses,\u201d Mazen Hayek, a Dubai-based media consultant, told The National.<\/p>\n<p class=\"defaultstyled__StyledText-sc-11u52t4-1 eVvrYS margin-lg-bottom\" id=\"el-53-YECARKPP7ZG3JP65CS6LBOHTKY\">In their latest earnings reports, Facebook parent Meta Platforms disappointed as investors fretted about AI spending and whether the costs can be recouped, while Microsoft, the maker of the Copilot bot, posted strong cloud growth, although investors are also curious about whether the big splash in AI data centres will pay off.<\/p>\n<p class=\"defaultstyled__StyledText-sc-11u52t4-1 eVvrYS margin-lg-bottom\" id=\"el-54-NAAUNR435FAS7GZSN2VRZHEMCQ\">Amazon, another heavy hitter in AI, said there has been strong demand for its services, with chief executive Andy Jassy saying spending would hit $220 billion this year. And Apple, which has a smaller target for AI, faces a test on its next iPhones, expected in September, on whether its partnerships and advancements for the technology will bring it up to speed in the race.<\/p>\n<p class=\"defaultstyled__StyledText-sc-11u52t4-1 eVvrYS margin-lg-bottom\" id=\"el-55-U34YGCDTJRC6PIXQ3IWPR55RHA\">Overall, the reaction to most Big Tech earnings releases has been disappointing as investors increasingly focus on the lack of a clear path to returns on the enormous AI-related spending, said John Canavan, lead financial market analyst at London&#8217;s Oxford Economics.<\/p>\n<p class=\"defaultstyled__StyledText-sc-11u52t4-1 eVvrYS margin-lg-bottom\" id=\"el-56-7OXHAHAADJHNXEWYJOQBN37HU4\">\u201cGiven the scale of borrowing for AI infrastructure investments, those questions are likely to linger in the quarters ahead, limiting any rebound in tech sector equities after the 10 per cent correction in the Nasdaq through [Wednesday&#8217;s] close,\u201d he told The National.<\/p>\n<p class=\"defaultstyled__StyledText-sc-11u52t4-1 eVvrYS margin-lg-bottom\" id=\"el-57-LDEDDGJTHNDADHJERNQNHXZQKQ\">The AI spending spree has led to a \u201crabbit hole\u201d, as no major players seem to want to extricate themselves from it, even though monetising this spend remains a distant goal, added Ashish Nadkarni, a group vice president at the International Data Corporation.<\/p>\n<p class=\"defaultstyled__StyledText-sc-11u52t4-1 eVvrYS margin-lg-bottom\" id=\"el-58-G4H4ZEU5OFC7NDSUOLF53TIBTM\">\u201cThey are afraid of the resulting optics and market reaction [they are all publicly traded after all]. They also fear that they may lose this &#8216;race&#8217; to competition. Everyone has gotten themselves into an impossible situation,\u201d he told The National.<\/p>\n","protected":false},"excerpt":{"rendered":"OpenAI and Anthropic, two of the leaders in generative artificial intelligence, are in hot water right now, and&hellip;\n","protected":false},"author":2,"featured_media":127048,"comment_status":"","ping_status":"","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[2],"tags":[24,25,26990,9430,592,134],"class_list":["post-127047","post","type-post","status-publish","format-standard","has-post-thumbnail","category-ai","tag-ai","tag-artificial-intelligence","tag-business-team","tag-standard","tag-story","tag-technology"],"_links":{"self":[{"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/posts\/127047","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/comments?post=127047"}],"version-history":[{"count":0,"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/posts\/127047\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/media\/127048"}],"wp:attachment":[{"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/media?parent=127047"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/categories?post=127047"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/tags?post=127047"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}