r/AIsafety • u/No-Commission546 • 16h ago
📰Recent Developments What do you think will be the biggest AI security problem over the next 2–3 years?
AI is moving pretty quickly, and I keep wondering which security problems are going to become the biggest as companies start relying on AI more heavily.
Is it data access? AI agents taking actions? Prompt injection? Something we haven’t really thought about yet?
Curious what people here think.
•
u/No-Commission546 11h ago
This is really good points. The distinction between what an agent can do and what it should be allowed to do in a specific situation seems like it’s going to become a huge issue.
•
u/VarietyMage 4h ago
People not realizing that "AI" is being used as a smokescreen so that the "AI" companies can implement a surveillance system that will be exactly like Orwell's "1984", using Palantir, data centers, Oracle DBMS, "AI" and digital cash replacing physical cash, bringing about the total surveillance state and the Mark of the Beast, without which you can neither buy nor sell anything, including food and water. Slavery follows for everyone, except those who own the "AI" hardware and software.
•
u/sje397 1h ago
I think it's going to be about connecting your personal AI with work tools, and managing the data flow.
I think it's so difficult that companies are just sticking their head in the sand and pretending they can ignore it and mandate their own AI usage policies and tools.
But everyone I know who's really tried to work with a personal AI are not going back.
•
u/Key-Tonight-5668 42m ago
I think its gonna be AI deepfakes. As they become better and better, you'd not be able to tell the difference between whats real person and whats not. So many ways people will be fooled virtually because of this.
•
u/usually_guilty99 13h ago
We have already seen the impact with OpenAI and HuggingFace. The bigger problem will be agents having valid access and making the wrong decision with it.
An API key can prove identity. RBAC can prove capability. Neither proves that this specific action, on this target, was appropriate at that moment.
Once agents can change infra, move money, update customer data or trigger other systems, blast radius and action-level authority become the real security problem.
The dangerous case is not always “the agent was hacked.”
Sometimes it is simply: the agent was allowed to do too much.
The most dangerous problem would be when - we as humans are unable to RCA them and they go undetected.