AI-powered chatbots: the threats to national security are only beginning

The UK’s National Cyber ​​Security Center (NCSC) recently issued a warning to its constituents about the threat artificial intelligence (AI) poses to UK national security. This was soon followed by a similar warning from the NSA’s director of cybersecurity, Rob Joyce. It is clear that there is great concern among many nations about the challenges and threats posed by AI.

To get a more comprehensive view of the dangers of bad actors using AI to infiltrate or attack nation-states, I reached out to the industry and found thoughts and opinions, and frankly, some who chose not to participate in the discussion, at least for now.

The NCSC cautioned that queries are archived and therefore could become part of the underlying large language model (LLM) of AI chatbots such as ChatGPT. These queries could reveal areas of interest to the user and, by extension, the organization they belong to. The NSA’s Joyce opined that ChatGPT and its peers will make cybercriminals better at their job, especially with a chatbot’s ability to enhance phishing language, making it sound more authentic and believable even to to sophisticated targets.

Secret leak through queries

As if on cue, Samsung revealed that it had warned its workforce to use the ChatGPT functionality with care. An employee wanted to optimize a confidential and sensitive product design and let the AI ​​engine do its thing – it worked, but also left behind a trade secret and eventually inspired Samsung to start developing its own ML software for internal use only.

Speaking about the Samsung incident, CODE42 CISO Jadee Hanson noted that despite its promising developments, the ChatGPT explosion has sparked many new concerns about potential risks. “For organizations, the risk intensifies as any employee enters data into ChatGPT,” he tells CSO.

“ChatGPT and AI tools can be incredibly useful and powerful, but employees need to understand what data is appropriate to enter into ChatGPT and what isn’t, and security teams need to have adequate visibility into what the organization sends to ChatGPT. With all the powerful new technological advances, there are risks we must understand to protect our organizations.”

