Agentic AI Creates A New Kind of Terrorist Threat

🚨 A new kind of terrorist threat: Once an AI can act on our behalf, a security breach becomes something more serious than someone stealing our data. An attacker may be able to use the AI to act as us.

Imagine this scenario: An attacker infiltrates the White House computer system with agentic AI, coordinating a Presidential announcement and multi-part follow-on communications that seem to come from him, but don’t.

They count on the confusion to carry out their deadly scheme.

If you’re not familiar with agentic AI, think of a chatbot on steroids. Instead of simply answering questions when prompted, it connects to email, calendars, financial systems, customer databases, vendor portals, and more.

It logs in, carries out tasks, communicates with other AI agents, and keeps its work product in the vendor cloud.

Your computer may be shut down, but it never sleeps.

For an individual, that might mean a brand-building PR machine.

For a business, it could mean AI agents that answer incoming queries, write proposals, update customer records, communicate with vendors, reconcile invoices, and coordinate supply-chain operations.

The efficiency benefits are extensive. Automating routine work could save organizations and individuals countless hours.

But there is a catch: an AI cannot act unless we give it something to act with.

That usually means credentials, permissions, access to private information, and connections to other software. And because many AI systems operate through third-party cloud providers, sensitive activity may pass through infrastructure that an organization does not directly control.

This creates a security problem that is different from a traditional data breach.

If criminals steal a database containing passwords, financial information, or customer records, they have obtained information that they can potentially exploit.

If criminals compromise an AI agent, however, they may gain access to something much more powerful: an active digital worker with permission to do things.

An attacker might manipulate the agent through techniques such as prompt injection, steal its credentials, compromise one of the tools it relies on, or exploit weaknesses in the connections between systems.

The result could be far more consequential than simply exposing information.

A compromised agent might approve a transaction, change a customer record, send a convincing message to a vendor, access an internal system, trigger an automated workflow, or move money—all while appearing to operate through a legitimate account.

And of course, there are even worse scenarios.

As these systems become common in the workplace, simply refusing to use them may no longer be economically realistic.

So the question will not be whether organizations use AI agents.

An entirely new set of safeguards, implemented broadly and rigorously, will be needed to ensure that smarter AI doesn’t become deadly AI.

AI image.

Pages

Archive

Alert: The content on this site is frequently migrated. If you land on a broken link, please visit the Annual Diaries.