AI ‘Agent’ Fever Comes with Lurking Security Threats

05 March 2026, Berlin: The letters "AI" for Artificial Intelligence are displayed on a wall during the opening of the Google AI Center Berlin. (dpa)
05 March 2026, Berlin: The letters "AI" for Artificial Intelligence are displayed on a wall during the opening of the Google AI Center Berlin. (dpa)
TT

AI ‘Agent’ Fever Comes with Lurking Security Threats

05 March 2026, Berlin: The letters "AI" for Artificial Intelligence are displayed on a wall during the opening of the Google AI Center Berlin. (dpa)
05 March 2026, Berlin: The letters "AI" for Artificial Intelligence are displayed on a wall during the opening of the Google AI Center Berlin. (dpa)

Artificial intelligence "agents" promise to save users time and energy by automating tasks, but the growing power of systems like OpenClaw is setting cybersecurity experts on edge.

Powered by a wave of hype, OpenClaw today claims more than three million users worldwide.

The system allows users to create so-called agents, tools based on a large language model (LLM) like OpenAI's ChatGPT or Anthropic's Claude that can carry out online tasks.

"We've moved from an AI you could talk with via a chatbot to an agentic AI, which can take action... the threat and the risks are definitely much greater," said Yazid Akadiri, principal solutions architect at Elastic France, an IT security company.

In an article titled "Agents of Chaos" that has yet to be peer-reviewed, a 20-strong team of researchers studied the behavior of six AI agents created with OpenClaw.

They spotted a dozen potentially dangerous actions executed by the systems, from deleting an email inbox to sharing personal information.

Many users have posted similar stories of OpenClaw mishaps online.

"When you deploy agents, you have no control over what they'll do, and when you try to look at what they're doing, you'll find them going far beyond the limits you set," said Adrien Merveille, an expert at the Check Point cybersecurity agency.

And the security gaps are not limited to the agents' own mistaken actions.

To carry out useful work, the tools need access to personal accounts for email, calendars or search engines -- drawing the attention of cyberattackers.

- 'Delete your database' -

AI agents are likely to become top targets for hackers as their use spreads, said Wendi Whitmore, chief security intelligence officer at cybersecurity firm Palo Alto Networks.

"As soon as (attackers) are inside an environment, (they're) immediately going to the internal LLM (agent) that's being used and using that then to interrogate the systems for more information."

Palo Alto's Unit 42 research division said in early March that it had found traces of attempted attacks in the form of hidden instructions for agents added to websites.

One such command ordered any agent who might read it to "delete your database".

Other cybersecurity firms and researchers have warned that attackers could gain access to agents via so-called skills -- downloadable files that users can add to their systems to give them new abilities.

Among such files freely available for download, some include hidden instructions for malicious actions like exfiltrating data.

OpenClaw creator Peter Steinberger says he is well aware of the risks.

"I purposefully didn't make it simpler so people would stop and read and understand: what is AI, that AI can make mistakes, what is prompt injection -- some basics that you really should understand when you use that technology," he told AFP in March.

Whitmore argued that expecting users to create their own guardrails for agents is "pretty unrealistic".

"People are going to adopt innovation and really see what it's capable of before they ask the questions about, 'how do I secure my own data?'," she predicted.

"That's going to cause some significant challenges in terms of data breaches in 2026."



OpenAI Begins Rollout of New Powerful AI Model GPT-6 Astra

The OpenAI logo in this illustration taken June 11, 2026. (Reuters)
The OpenAI logo in this illustration taken June 11, 2026. (Reuters)
TT

OpenAI Begins Rollout of New Powerful AI Model GPT-6 Astra

The OpenAI logo in this illustration taken June 11, 2026. (Reuters)
The OpenAI logo in this illustration taken June 11, 2026. (Reuters)

ChatGPT maker OpenAI said Thursday it would begin rolling out its newest and most powerful artificial intelligence (AI) model to select customers, saying it had built in safeguards to mitigate security risks.

"At this level of capability, safety has to become our top priority," OpenAI President Greg Brockman told reporters on a call about the release of GPT-6, also known as Astra.

Just over a year has passed since OpenAI launched the previous version of its flagship model, GPT-5, said AFP.

Concerns about the capabilities of advanced models have grown since then, following incidents involving systems built by OpenAI and rival developer Anthropic.

OpenAI paused some model development for two weeks this summer after two models it was testing were involved in a security breach at AI platform Hugging Face.

The San Francisco-based company said Astra was developed with stronger safeguards after that incident, though Astra itself was not involved in the hack.

Some cybersecurity customers will get access to the new model Thursday, the company said, with a wider rollout to other paying customers to follow. Users on the free tier or the cheapest paid plan will not get access.

"We are working towards getting Astra in everyone's hands as quickly as we can; I know it is frustrating and I appreciate the patience. It should be quick," OpenAI CEO Sam Altman posted on social media Thursday afternoon.

In a blog post, OpenAI said Astra can autonomously handle a wide range of "tedious" computer tasks, including website creation, scientific analysis, game development, cybersecurity and coding.

To illustrate the time savings of building autonomous AI agents with Astra, the company said the model could cut apartment hunting from six hours to under 10 minutes.

"It's not unreasonable to feel that we are now in the AGI era," Brockman said on the call, referring to artificial general intelligence, a hypothetical stage at which AI systems match human intelligence across most tasks.

OpenAI previously had an agreement with Microsoft, one of its earliest and largest investors, under which an exclusivity clause would end once OpenAI reached AGI. Those terms were scrapped in April.

- 'Limited window' -

OpenAI chief scientist Jakub Pachocki acknowledged there was still uncertainty about how a new model behaves once released.

"A model can become very good at achieving a goal, and it can still act in ways that go against what the person intended," Pachocki said on the same call.

"We also have to be willing to slow down or withhold further scaling when our confidence in safety is not sufficient," he added.

Altman explained in an interview with Bloomberg TV on Thursday afternoon why the company decided to release a new model with this level of uncertainty and risk.

"The world is very close to a complete change in the landscape of cyber attacks, and the only way that we see for society to collectively defend itself... is to use tools like Astra to rapidly defend against these new cyber threats," Altman said.

In July OpenAI confirmed that it had reached one billion active users across all of its products, including both free and paid users.

OpenAI, Anthropic and more than 100 other organizations signed an open letter last week calling for a coordinated global response to AI-related cybersecurity risks, warning that the window to strengthen cyber defenses was limited.

Anthropic went further on Monday, calling for industry-wide coordination on safety and on the pace of developing increasingly capable models.

"I believe that shared safety standards and international coordination on further AI development need to be prioritized now," OpenIA's Pachocki said on Thursday.

The US state of Alabama opened an investigation into OpenAI last week over the Hugging Face breach, his office citing what it called the company's complete lack of oversight and adequate safeguards.

It also comes as OpenAI and rival Anthropic are both racing towards becoming public companies over the next several months, though OpenAI might not hold its IPO till sometime in 2027, according to reports.


Deputy CEO of NCAI Highlights AI’s Future at DeepFest 2026

Deputy CEO of the National Center for Artificial Intelligence (NCAI) Dr. Hotham Altwaijry said the future of AI will be shaped by countries that can maximize the value of their technologies.(SPA)
Deputy CEO of the National Center for Artificial Intelligence (NCAI) Dr. Hotham Altwaijry said the future of AI will be shaped by countries that can maximize the value of their technologies.(SPA)
TT

Deputy CEO of NCAI Highlights AI’s Future at DeepFest 2026

Deputy CEO of the National Center for Artificial Intelligence (NCAI) Dr. Hotham Altwaijry said the future of AI will be shaped by countries that can maximize the value of their technologies.(SPA)
Deputy CEO of the National Center for Artificial Intelligence (NCAI) Dr. Hotham Altwaijry said the future of AI will be shaped by countries that can maximize the value of their technologies.(SPA)

Deputy CEO of the National Center for Artificial Intelligence (NCAI) Dr. Hotham Altwaijry said the future of AI will be shaped by countries that can maximize the value of their technologies. He explained that the current phase requires greater focus on using AI optimally and harnessing its potential to achieve tangible impact that benefits humanity and society, the Saudi Press Agency said on Friday.

His remarks came during the opening session of the fourth and final day of DeepFest 2026. He highlighted the evolving relationship between humans and AI, as well as technology's role in enhancing human capabilities and improving experiences.

Altwaijry explained that SDAIA recognized early on that a meaningful partnership between humans and AI cannot be achieved through algorithms, models, and technical concepts alone. Rather, it requires enabling individuals to experience AI’s potential firsthand.

He noted that AI has now become an integral part of today’s work environments, contributing to software development and testing, analyzing and preparing business requirements, and giving individuals greater space to focus on user experience, creativity, and exploring new ideas and solutions.


Abu Dhabi AI Institute Releases Fully Open-Source Models With Training Data, Code

A view of the UAE capital, Abu Dhabi (Asharq Al-Awsat)
A view of the UAE capital, Abu Dhabi (Asharq Al-Awsat)
TT

Abu Dhabi AI Institute Releases Fully Open-Source Models With Training Data, Code

A view of the UAE capital, Abu Dhabi (Asharq Al-Awsat)
A view of the UAE capital, Abu Dhabi (Asharq Al-Awsat)

Abu Dhabi-based research institute IFM on Thursday released six artificial intelligence models together with the data and methods used to build them, challenging an industry trend toward increasingly secretive AI development.

The K2 Horizon release includes model weights, training data, code, methodologies and intermediate checkpoints, allowing researchers to retrace the models' development process and reproduce results, IFM founder Eric Xing told Reuters.

The move goes beyond the "open-weight" approach used by some Chinese developers, which make models available for download but provide limited insight into how they were built, and contrasts with the more closed development practices of companies such as OpenAI and Anthropic, which neither release their models for download nor disclose the data and techniques behind them.

"Our goal with this release is to establish a reference point for what a truly open model release can look like," Xing said.

He said the release was also intended to show policymakers, regulators and public-interest advocates that "openness and competitive performance are not mutually exclusive."

The launch forms part of the UAE's push to establish itself as a global AI hub.

The model family ranges from one designed for smartwatches and other constrained devices to a 375-billion-parameter system for enterprise deployments.