New cyber immunity guide shared for the security of autonomous artificial intelligence agents
A new report and security guide aiming to enhance the security of autonomous artificial intelligence agents draws attention to risks in corporate environments.
Kaspersky has published a new report and guide based on cyber immunity principles for the security of autonomous artificial intelligence agents. This comprehensive study addresses corporate risks in light of real-world cyber incidents.
Increasing use of artificial intelligence in the corporate field
The use of artificial intelligence agents is becoming increasingly widespread in corporate areas such as the automation of routine business processes, software development, and IT security operations.
Potential risks and threat models
The published report details the risks carried by autonomous agent-based systems, drawing on real-world cyber incidents and existing threat models.
Malicious operations and authorization issues
Organizations need to take precautions against risks such as the malicious use of artificial intelligence agents, excessive authorization, or unintended actions like data deletion.
Security measures at the design stage
It is recommended that large language models and data coming from external sources be treated as untrusted elements by default, and that user approval be mandatory for irreversible actions.
Isolation of system components
To ensure security, it is suggested to minimize the components that need to be trusted and to isolate system components via sandboxes and virtual machines.
Strategic advice for executives
Recommendations for CISO, CIO, and CTO roles include creating an inventory of artificial intelligence agents used within organizations and managing the supply chain.