Berliner Boersenzeitung - AI 'agent' fever comes with lurking security threats

EUR -
AED 4.238611
AFN 75.611352
ALL 93.114312
AMD 422.436263
AOA 1058.353508
ARS 1729.398441
AUD 1.635917
AWG 2.077466
AZN 1.944872
BAM 1.955042
BBD 2.326508
BDT 142.72468
BHD 0.435644
BIF 3450.337384
BMD 1.154148
BND 1.478159
BOB 13.745672
BRL 5.895379
BSD 1.155057
BTN 110.020543
BWP 15.561373
BYN 3.434084
BYR 22621.293968
BZD 2.32311
CAD 1.608166
CDF 2620.493188
CHF 0.935275
CLF 0.026837
CLP 1056.241645
CNY 7.787723
CNH 7.785528
COP 3619.199288
CRC 524.41264
CUC 1.154148
CUP 30.584913
CVE 110.222278
CZK 24.256433
DJF 205.690274
DKK 7.475644
DOP 67.345939
DZD 153.23383
EGP 57.557225
ERN 17.312215
ETB 186.781767
FJD 2.5524
FKP 0.856091
GBP 0.854467
GEL 3.011989
GGP 0.856091
GHS 13.560744
GIP 0.856091
GMD 84.829109
GNF 10144.19994
GTQ 8.813431
GYD 241.906237
HKD 9.0555
HNL 30.962938
HRK 7.535435
HTG 151.03473
HUF 364.744172
IDR 20563.448705
ILS 3.460308
IMP 0.856091
INR 110.076774
IQD 1513.213477
IRR 1586635.629843
ISK 142.202794
JEP 0.856091
JMD 183.44446
JOD 0.818233
JPY 183.783585
KES 149.311712
KGS 100.929934
KHR 4683.286199
KMF 491.666793
KRW 1633.315462
KWD 0.356689
KYD 0.962627
KZT 538.521269
LAK 26086.8887
LBP 103438.75517
LKR 387.129948
LRD 208.481967
LSL 18.689956
LTL 3.407898
LVL 0.698133
LYD 7.361147
MAD 10.771525
MDL 20.075306
MGA 4947.211051
MKD 61.501162
MMK 2423.190229
MNT 4148.299243
MOP 9.334382
MRU 46.331447
MUR 54.256349
MVR 17.831569
MWK 2002.975709
MXN 19.78382
MYR 4.725106
MZN 73.755792
NAD 18.689956
NGN 1572.041246
NIO 42.504446
NOK 10.956381
NPR 176.044104
NZD 1.96148
OMR 0.443769
PAB 1.155052
PEN 3.901688
PGK 5.107109
PHP 70.526508
PKR 320.683192
PLN 4.303589
PYG 6875.364888
QAR 4.210768
RON 5.243987
RSD 117.397594
RUB 95.218856
RWF 1696.893742
SAR 4.322579
SBD 9.309005
SCR 15.952041
SDG 693.063099
SEK 10.955397
SGD 1.477673
SLE 28.394687
SOS 660.16414
SRD 43.569652
STD 23888.526169
STN 24.490932
SVC 10.107082
SZL 18.686838
THB 38.134174
TJS 10.666896
TMT 4.051058
TND 3.385988
TRY 55.091853
TTD 7.834963
TWD 37.214572
TZS 3058.488994
UAH 51.815763
UGX 4302.332412
USD 1.154148
UYU 46.531763
UZS 13782.65783
VES 872.261394
VND 30150.376172
VUV 137.766464
WST 3.155113
XAF 655.719887
XAG 0.017562
XAU 0.000262
XCD 3.119141
XCG 2.081793
XDR 0.815505
XOF 655.705689
XPF 119.331742
YER 275.123421
ZAR 18.692002
ZMK 10388.698743
ZMW 21.605719
ZWL 371.635073
  • CMSC

    -0.1738

    21.57

    -0.81%

  • RBGPF

    -0.6200

    69.88

    -0.89%

  • RYCEF

    -0.2800

    20.57

    -1.36%

  • BCC

    -1.8500

    84.75

    -2.18%

  • RELX

    0.1000

    35.62

    +0.28%

  • GSK

    -0.8000

    52.16

    -1.53%

  • BCE

    -0.2100

    22.54

    -0.93%

  • NGG

    -1.4000

    79.48

    -1.76%

  • AZN

    0.4900

    161.91

    +0.3%

  • RIO

    0.8100

    101.91

    +0.79%

  • CMSD

    -0.1300

    21.69

    -0.6%

  • JRI

    -0.0800

    12.73

    -0.63%

  • VOD

    -0.4400

    15.75

    -2.79%

  • BTI

    -2.2800

    57.05

    -4%

  • BP

    1.2500

    42.88

    +2.92%

AI 'agent' fever comes with lurking security threats
AI 'agent' fever comes with lurking security threats / Photo: ADEK BERRY - AFP/File

AI 'agent' fever comes with lurking security threats

Artificial intelligence "agents" promise to save users time and energy by automating tasks, but the growing power of systems like OpenClaw is setting cybersecurity experts on edge.

Text size:

Powered by a wave of hype, OpenClaw today claims more than three million users worldwide.

The system allows users to create so-called agents, tools based on a large language model (LLM) like OpenAI's ChatGPT or Anthropic's Claude that can carry out online tasks.

"We've moved from an AI you could talk with via a chatbot to an agentic AI, which can take action... the threat and the risks are definitely much greater," said Yazid Akadiri, principal solutions architect at Elastic France, an IT security company.

In an article titled "Agents of Chaos" that has yet to be peer-reviewed, a 20-strong team of researchers studied the behaviour of six AI agents created with OpenClaw.

They spotted a dozen potentially dangerous actions executed by the systems, from deleting an email inbox to sharing personal information.

Many users have posted similar stories of OpenClaw mishaps online.

"When you deploy agents, you have no control over what they'll do, and when you try to look at what they're doing, you'll find them going far beyond the limits you set," said Adrien Merveille, an expert at the Check Point cybersecurity agency.

And the security gaps are not limited to the agents' own mistaken actions.

To carry out useful work, the tools need access to personal accounts for email, calendars or search engines -- drawing the attention of cyberattackers.

- 'Delete your database' -

AI agents are likely to become top targets for hackers as their use spreads, said Wendi Whitmore, chief security intelligence officer at cybersecurity firm Palo Alto Networks.

"As soon as (attackers) are inside an environment, (they're) immediately going to the internal LLM (agent) that's being used and using that then to interrogate the systems for more information."

Palo Alto's Unit 42 research division said in early March that it had found traces of attempted attacks in the form of hidden instructions for agents added to websites.

One such command ordered any agent who might read it to "delete your database".

Other cybersecurity firms and researchers have warned that attackers could gain access to agents via so-called skills -- downloadable files that users can add to their systems to give them new abilities.

Among such files freely available for download, some include hidden instructions for malicious actions like exfiltrating data.

OpenClaw creator Peter Steinberger says he is well aware of the risks.

"I purposefully didn't make it simpler so people would stop and read and understand: what is AI, that AI can make mistakes, what is prompt injection -- some basics that you really should understand when you use that technology," he told AFP in March.

Whitmore argued that expecting users to create their own guardrails for agents is "pretty unrealistic".

"People are going to adopt innovation and really see what it's capable of before they ask the questions about, 'how do I secure my own data?'," she predicted.

"That's going to cause some significant challenges in terms of data breaches in 2026."

(K.Müller--BBZ)