Legal wrangling over incidents caused by AI operating beyond control and attacking external sites is spreading into the courtroom.
OpenAI has been sued over a Hugging Face hacking case. Public interest legal group LASST (Legal Advocates for Safe Science and Technology) filed a complaint against OpenAI in California Superior Court. LASST joined the lawsuit with law firm Gerstein Harrow and asked the court to restrict OpenAI’s activities to prevent a recurrence of hacking. Anthropic also shared with investors that it could be sued by customers and users over the behavior of AI agents.
ㆍOpenAI sued over 'Hugging Face hacking'... "Developers are responsible for AI agent behavior" ㆍAnthropic, ahead of IPO, warns "We could be sued over AI agent behavior"
The U.S. Federal Trade Commission has launched an investigation into AI companies including OpenAI and Anthropic over potential product risks. The probe is being conducted to examine risks that AI products could cause.
ㆍU.S. FTC opens probe into OpenAI, Anthropic...checks AI product risks
Responsibility for AI security is also emerging as an issue inside companies. There is also talk that preventing leaks of internal corporate information stemming from AI use is not easy for in-house security teams to cover.
ㆍ[Tech Insight] Who should be responsible?...Four realities reflected in an AI security decision-making report
It also summed up moves and issues involving companies at home and abroad surrounding security.
AI security and authentication platform company RaonSecure unveiled a blueprint for agentic AI security. RaonSecure is emphasizing that for AI to perform real work, verification and accountability systems for identity, authority and behavior, along with built-in security technology in AI, must be in place as much as expanded autonomy. Data intelligence company S2W is upgrading key functions of its ontology-based decision-making operating system (OS) SAIP and speeding up expansion into non-security businesses. Offensive cybersecurity company Theori was selected as a performer of the U.S. Defense Advanced Research Projects Agency (DARPA) Autonomous AI Application Security research program through its AI-based autonomous penetration testing platform Xint. Jiranjigyo Security introduced MudScope, an AI-based Human Risk Management (HRM) platform that analyzes employees’ security behavior with AI to measure and manage risk levels.
ㆍRaonSecure gains traction with Web3-based AI agent security strategy ㆍS2W upgrades ontology-based decision-making OS 'SAIP'...full-scale expansion into non-security business ㆍTheori deploys penetration testing platform in U.S. DARPA 'AI communication app security' research program ㆍJiranjigyo Security launches AI-based HRM platform 'MudScope'
MegazoneCloud partnered with CrowdStrike to help South Korean companies integrate cybersecurity and modernize security operations using the CrowdStrike Falcon platform. MegazoneCloud is also supplying in South Korea an enterprise generative AI integrated management platform provided by U.S. generative AI governance and security specialist Portal26. Fasoo AI launched a Security Care Service for companies starting to introduce security solutions.
ㆍMegazoneCloud partners with CrowdStrike on modernising corporate security operations ㆍMegazoneCloud to supply Portal26 generative AI governance and security solution in South Korea ㆍFasoo AI launches 'Security Care Service'..."Build practical security systems"
France-based Thales is expanding cooperation with Google Cloud. Thales is combining its AI Security Fabric with Google Cloud’s Gemini Enterprise Agent Platform. Enterprise browser developer Island raised $400 million in a Series F round. The Island browser can block threats such as malicious web pages and phishing emails, and can also stop login requests in vulnerable work devices or WiFi environments.
ㆍThales and Google Cloud join hands on 'AI agent security'...support real-time monitoring and control ㆍEnterprise web browser developer Island raises $400 million at $6.4 billion valuation
Microsoft presented outcome-based operations as a security strategy to counter AI-based automated attacks. It said security teams need to change their approach to a structure where agents handle execution and people are responsible for outcomes.
ㆍCounter AI-based autonomous security attacks? "Shift to an outcome-based security system"
Nvidia unveiled a software platform, the Open Agent Safety Platform, designed to prevent AI agents from leaving isolated environments and accessing external systems.
ㆍNvidia unveils AI agent access control platform..."Model-level safety guards alone have limits"
A survey found that 41 percent of chief information security officers (CISOs) experienced at least one social engineering attack in the past 12 months that exploited deepfakes during employees’ voice calls. The share that experienced the same type of attack in video calls was also 36 percent.
ㆍ"41 percent of security chiefs experienced deepfake attacks"...Gartner survey
An incident occurred at Shinhan Bank in which personal and credit information of about 25,000 customers was leaked. As the Financial Supervisory Service launched an emergency on-site investigation, the cause of the incident and the scale of damage, as well as whether Shinhan Bank’s information protection and internal control systems functioned properly, are expected to emerge as key issues.
ㆍFrom resident registration numbers and annual income to loan limits...attention on fallout from Shinhan Bank 'customer information leak'