This essay was written with Barath Raghavan, and originally appeared in Lawfare. In April, an artificial intelligence (AI) agent conducting a routine task at a company hit a snag, tried to solve it, and soon ended up deleting the company’s database along with all of its backups. In July, OpenAI asked an unreleased AI model to attempt a hacking test. Instead of staying in the isolated box the developers had put it in, the model hacked onto the open internet and into another company to steal the answers. And as reported in August, an AI agent booked someone into a full gym class by ...
Nice to see Bruce Schneier.
I still hate that agentic AI is a thing now. The hubris to offer it in the first place and the stupidity of anyone who uses it in earnest.
Agentic AI has its place, in a tightly controlled sandbox.
One of the anecdotes was about an agent which wiped out the production database, and all backups. While you can lay blame on the agent (AI or human) who made the mistakes, the real blame in that situation is with the system architect (likely there was no named system architect, but that doesn’t absolve whoever was acting as de-facto architect) who placed the backups in a hot, online accessible and erasable configuration. No agent, AI or human, should be able to wipe out all the backups with their normal access - ideally there are physical doors and keys involved - in multiple locations if the data is of any value.