I despair at the state of journalism around AI these days. The latest story is about Gemini, Google's AI model, "autonomously" hacking three companies.
This follows reports of similar hacks from Anthropic and OpenAI models.
What all of these have in common:
They were models being tested by a third party, an Israeli "Frontier AI Security" company called Irregular. The "frontier" security here was so shoddy that they left the machines they were testing these models on connected to the Internet. A basic error that many non-frontier security companies would find easy to avoid.
These models were not going rogue and acting "autonomously". They were performing a hacking exercise, and told that they were in a simulated environment with no internet access. In the case of the Gemini hack, the model was literally told to hack the company.
The New York Times writes: "Google said that, in each of the incidents, its models had been instructed to launch an attack on a fictional company. But the fictional company in the test shared a name with a real company, and when the Gemini models gained access to the internet, they began trying to break into that company instead."In most such tests, the usual safeguards that apply when these models are rolled out to the public are deliberately removed, as the full capabilities need to be tested.
None of the context above is in the BBC piece I just saw on their front page:
The piece starts with the following:
Google's AI model Gemini autonomously hacked into three companies during a test of its cyber-security capabilities
The article does not mention that it was instructed to hack. No mention that these models usually have their safeguards deliberately removed during testing. No mention that the Israeli security company failed to provide an internet-free environment for the test.
Brian Chau’s piece A Single Firm is Behind OpenAI, Anthropic, and Meta Hacking Scandals is well worth reading on this. He writes:
In a more normal media ecosystem, the reactions to these cybersecurity issues would be obvious. American AI companies would reconsider doing business with Irregular, not only because of its failure to secure its systems, but because it is an Israeli firm potentially outside US oversight.

