Thank you to everyone who has contacted me about recent security incidents involving AI models.
As many people highlighted, in July, OpenAI revealed that some of its models broke from its “sandbox”, a secure environment built to assess the capability of models, during a security test. They then gained access to Hugging Face, an AI startup, before the activity was detected and stopped. Days later, Anthropic confirmed that its models had also been able to access the internet from testing environments that were supposed to be sandboxed.
In addition, on 4 August, the AI Security Institute (AISI) explained that, during a routine cyber evaluation, it found that some AI agents took unauthorised actions targeting real people and organisations. In the most serious case, an agent attempted to introduce malicious code into a project and created fake online identities to encourage its approval before the activity was stopped by a human reviewer. Although this was not a case of a model escaping its sandbox, and there is no evidence of real-world harm, the findings are concerning.
These incidents demonstrate that risks can arise not only from the deliberate misuse of AI, but also when highly capable systems act beyond their intended authority. The AISI has said this is the clearest example it has seen so far of AI systems displaying concerning levels of autonomy and deception without being specifically instructed to do so.
I therefore welCome that the Government recognises and continues to monitor the risks posed by the rapidly developing capabilities of leading AI systems, and is working to improve safeguards. I also echo its encouragement to organisations to step up their cyber-defences. As, the AISI says, organisations should robustly implement cyber security basics and be cautious of outside code and contributions. They are also encouraged to: sign up to the National Cyber Security Centre’s free Early Warning service, which alerts organisations to potentially suspicious activity on their networks; make cyber security a board-level responsibility; and require the Government-backed Cyber Essentials certification across their supply chains.
I further welcome that the Government is taking new powers to protect against emerging risks through the Cyber Security and Resilience Bill. This includes expanding the definition of incidents that providers of essential services must report, so we can have an accurate idea of the range of cyber-threats we face.
Thank you once again to everyone who got in touch. I recognise the seriousness of this issue and can assure you that I will continue to monitor developments closely.