r/AIsafety 16h ago

📰Recent Developments What do you think will be the biggest AI security problem over the next 2–3 years?

AI is moving pretty quickly, and I keep wondering which security problems are going to become the biggest as companies start relying on AI more heavily.

Is it data access? AI agents taking actions? Prompt injection? Something we haven’t really thought about yet?

Curious what people here think.

Upvotes

9 comments sorted by

u/usually_guilty99 13h ago

We have already seen the impact with OpenAI and HuggingFace. The bigger problem will be agents having valid access and making the wrong decision with it.

An API key can prove identity. RBAC can prove capability. Neither proves that this specific action, on this target, was appropriate at that moment.

Once agents can change infra, move money, update customer data or trigger other systems, blast radius and action-level authority become the real security problem.

The dangerous case is not always “the agent was hacked.”

Sometimes it is simply: the agent was allowed to do too much.

The most dangerous problem would be when - we as humans are unable to RCA them and they go undetected.

u/Spiritual-Spend8187 10h ago

We already have that with the stories of people having an agent accidentally just deleting everything. Like it is not be common but it shows you cannot trust an ai to have such credentials if when you tell it dont delete anything it turns around and deletes everything.

u/usually_guilty99 7h ago

This is the reason we need to have best case governance controlling what agents could do and what they just cannot do.

u/Spiritual-Spend8187 6h ago

Yes but given how lazy people have been with their use of various generative ai systems I dont expect them to use them or even for them to turn them off to have it go faster.

u/SaneAI 12h ago

I'm worried the most about the fear itself and that some doomer loon will shoot up an AI lab.

u/No-Commission546 11h ago

This is really good points. The distinction between what an agent can do and what it should be allowed to do in a specific situation seems like it’s going to become a huge issue.

u/VarietyMage 4h ago

People not realizing that "AI" is being used as a smokescreen so that the "AI" companies can implement a surveillance system that will be exactly like Orwell's "1984", using Palantir, data centers, Oracle DBMS, "AI" and digital cash replacing physical cash, bringing about the total surveillance state and the Mark of the Beast, without which you can neither buy nor sell anything, including food and water. Slavery follows for everyone, except those who own the "AI" hardware and software.

u/sje397 1h ago

I think it's going to be about connecting your personal AI with work tools, and managing the data flow.

I think it's so difficult that companies are just sticking their head in the sand and pretending they can ignore it and mandate their own AI usage policies and tools. 

But everyone I know who's really tried to work with a personal AI are not going back.

u/Key-Tonight-5668 42m ago

I think its gonna be AI deepfakes. As they become better and better, you'd not be able to tell the difference between whats real person and whats not. So many ways people will be fooled virtually because of this.