The Australian Signals Directorate’s Australian Cyber Security Centre (ACSC) has issued a High Alert/Act Quickly warning regarding AI agents operating outside their owners’ control.
“We are aware of instances of AI misalignment, in which AI agents have undertaken unexpected actions that were not intended or authorised by its operators,” the agency said in a 24 September alert titled “Risks of AI misalignment to Australian organisations”.
“In these instances, an AI agent was provided a specific activity to complete, however, cyber security controls on entities’ public-facing websites/services limited the AI agent’s ability to complete the activity assigned to it,” the ACSC said.
“In a scenario, the AI agent independently identified vulnerabilities and attempted to progress actions without direct human authorisation to ensure it was able to complete the activity it was assigned.”
The ACSC said there was no indication of a broader threat or any “malicious targeting” of Australia or Australian organisations.
“ASD routinely receives reports of vulnerabilities from security researchers, industry partners, and government stakeholders,” the ACSC said.
“In this case, the notable difference is that an AI agent independently identified vulnerabilities that would traditionally be discovered and assessed by human researchers.”
The ACSC advised Australian organisations to take the following mitigation advice:
- Apply strong authentication, access controls, and network segmentation.
- Ensure vulnerabilities are identified and remediated promptly.
- Monitor systems for unusual activity and review security logs regularly.
- Apply patches to your systems as soon as practicable.
- Test controls and incident response procedures against AI-enabled threat scenarios.
The ACSC did not provide any further information regarding the incident or where it occurred.
“Organisations that identify suspicious AI-driven activity, attempted exploitation, or vulnerabilities affecting their systems, including AI-enabled or AI-assisted activity, should report it to ASD through established reporting channels,” the ACSC said.
Want to see more stories from trusted news sources?Make Cyber Daily a preferred news source on Google.