The Japan Times - AI 'agent' fever comes with lurking security threats

EUR -
AED 4.323624
AFN 75.940287
ALL 95.687478
AMD 441.242259
ANG 2.107224
AOA 1080.758104
ARS 1611.497818
AUD 1.640802
AWG 2.120604
AZN 2.006077
BAM 1.955544
BBD 2.375189
BDT 144.991026
BGN 1.96385
BHD 0.444942
BIF 3506.541132
BMD 1.177296
BND 1.500804
BOB 8.148934
BRL 5.86235
BSD 1.179346
BTN 109.436679
BWP 15.822929
BYN 3.349562
BYR 23075.00039
BZD 2.37179
CAD 1.622138
CDF 2719.554043
CHF 0.92023
CLF 0.026225
CLP 1032.124042
CNY 8.02651
CNH 8.025203
COP 4245.599931
CRC 537.829619
CUC 1.177296
CUP 31.198342
CVE 110.250573
CZK 24.292918
DJF 210.002519
DKK 7.478542
DOP 70.700748
DZD 156.180562
EGP 61.083007
ERN 17.659439
ETB 184.137404
FJD 2.6116
FKP 0.868551
GBP 0.870523
GEL 3.183245
GGP 0.868551
GHS 13.031295
GIP 0.868551
GMD 86.535785
GNF 10346.646031
GTQ 9.01882
GYD 246.727713
HKD 9.228882
HNL 31.3339
HRK 7.540232
HTG 154.429791
HUF 361.795271
IDR 20178.852382
ILS 3.484549
IMP 0.868551
INR 109.020489
IQD 1544.897834
IRR 1555796.58282
ISK 143.712969
JEP 0.868551
JMD 186.4556
JOD 0.834749
JPY 186.754908
KES 151.993381
KGS 102.954982
KHR 4717.38268
KMF 492.110114
KPW 1059.585206
KRW 1727.140685
KWD 0.363031
KYD 0.982771
KZT 552.967638
LAK 26018.595189
LBP 105605.880343
LKR 372.771219
LRD 216.991604
LSL 19.329071
LTL 3.476249
LVL 0.712135
LYD 7.457024
MAD 10.880676
MDL 20.272347
MGA 4891.359913
MKD 61.631935
MMK 2472.335396
MNT 4209.431325
MOP 9.512755
MRU 47.136832
MUR 54.497475
MVR 18.20144
MWK 2044.932399
MXN 20.380292
MYR 4.653267
MZN 75.294007
NAD 19.329071
NGN 1580.496695
NIO 43.394321
NOK 11.029737
NPR 175.099086
NZD 2.001864
OMR 0.452675
PAB 1.179346
PEN 4.057269
PGK 5.112331
PHP 70.124501
PKR 328.817071
PLN 4.231614
PYG 7513.016842
QAR 4.299437
RON 5.098167
RSD 117.334646
RUB 89.747056
RWF 1723.174504
SAR 4.416574
SBD 9.460335
SCR 17.72868
SDG 707.555258
SEK 10.789215
SGD 1.495288
SHP 0.87897
SLE 28.990957
SLL 24687.302663
SOS 674.011798
SRD 44.391165
STD 24367.648971
STN 24.496794
SVC 10.31865
SYP 130.205456
SZL 19.323471
THB 37.81518
TJS 11.120745
TMT 4.126422
TND 3.422652
TOP 2.834646
TRY 52.795135
TTD 8.009952
TWD 37.061709
TZS 3055.00648
UAH 51.917706
UGX 4367.428475
USD 1.177296
UYU 46.913861
UZS 14311.127236
VES 564.698282
VND 31004.088534
VUV 138.303874
WST 3.196656
XAF 655.871172
XAG 0.014569
XAU 0.000243
XCD 3.181702
XCG 2.125422
XDR 0.815693
XOF 655.871172
XPF 119.331742
YER 280.907036
ZAR 19.209
ZMK 10597.080419
ZMW 22.436064
ZWL 379.088812
  • RBGPF

    -13.5000

    69

    -19.57%

  • RIO

    0.4400

    100.15

    +0.44%

  • CMSD

    0.1800

    23.08

    +0.78%

  • BCE

    -0.0700

    24.09

    -0.29%

  • BCC

    4.2400

    83.04

    +5.11%

  • CMSC

    0.1500

    22.77

    +0.66%

  • JRI

    0.1800

    13.09

    +1.38%

  • NGG

    -0.6000

    86.92

    -0.69%

  • RELX

    0.4700

    36.68

    +1.28%

  • GSK

    1.2200

    58.35

    +2.09%

  • RYCEF

    0.5600

    17.66

    +3.17%

  • AZN

    4.3300

    204.8

    +2.11%

  • VOD

    -0.2200

    15.48

    -1.42%

  • BTI

    0.5400

    56.68

    +0.95%

  • BP

    -3.0400

    44.59

    -6.82%

AI 'agent' fever comes with lurking security threats
AI 'agent' fever comes with lurking security threats / Photo: ADEK BERRY - AFP/File

AI 'agent' fever comes with lurking security threats

Artificial intelligence "agents" promise to save users time and energy by automating tasks, but the growing power of systems like OpenClaw is setting cybersecurity experts on edge.

Text size:

Powered by a wave of hype, OpenClaw today claims more than three million users worldwide.

The system allows users to create so-called agents, tools based on a large language model (LLM) like OpenAI's ChatGPT or Anthropic's Claude that can carry out online tasks.

"We've moved from an AI you could talk with via a chatbot to an agentic AI, which can take action... the threat and the risks are definitely much greater," said Yazid Akadiri, principal solutions architect at Elastic France, an IT security company.

In an article titled "Agents of Chaos" that has yet to be peer-reviewed, a 20-strong team of researchers studied the behaviour of six AI agents created with OpenClaw.

They spotted a dozen potentially dangerous actions executed by the systems, from deleting an email inbox to sharing personal information.

Many users have posted similar stories of OpenClaw mishaps online.

"When you deploy agents, you have no control over what they'll do, and when you try to look at what they're doing, you'll find them going far beyond the limits you set," said Adrien Merveille, an expert at the Check Point cybersecurity agency.

And the security gaps are not limited to the agents' own mistaken actions.

To carry out useful work, the tools need access to personal accounts for email, calendars or search engines -- drawing the attention of cyberattackers.

- 'Delete your database' -

AI agents are likely to become top targets for hackers as their use spreads, said Wendi Whitmore, chief security intelligence officer at cybersecurity firm Palo Alto Networks.

"As soon as (attackers) are inside an environment, (they're) immediately going to the internal LLM (agent) that's being used and using that then to interrogate the systems for more information."

Palo Alto's Unit 42 research division said in early March that it had found traces of attempted attacks in the form of hidden instructions for agents added to websites.

One such command ordered any agent who might read it to "delete your database".

Other cybersecurity firms and researchers have warned that attackers could gain access to agents via so-called skills -- downloadable files that users can add to their systems to give them new abilities.

Among such files freely available for download, some include hidden instructions for malicious actions like exfiltrating data.

OpenClaw creator Peter Steinberger says he is well aware of the risks.

"I purposefully didn't make it simpler so people would stop and read and understand: what is AI, that AI can make mistakes, what is prompt injection -- some basics that you really should understand when you use that technology," he told AFP in March.

Whitmore argued that expecting users to create their own guardrails for agents is "pretty unrealistic".

"People are going to adopt innovation and really see what it's capable of before they ask the questions about, 'how do I secure my own data?'," she predicted.

"That's going to cause some significant challenges in terms of data breaches in 2026."

Y.Watanabe--JT