Armadin 创始人兼 CEO Kevin Mandia 在 a16z 播客中提出,AI 让攻击者能以机器速度同时探测数千条路径,防御也必须走向自主化。Armadin 的做法是用 AI 持续攻击客户系统,在对手之前找出可利用漏洞,今年已在生产环境中发现 90 多个零日漏洞。他认为人类无法继续留在检测与响应的循环中,整个安全栈未来几年可能被重塑。
Bill Gates 在 Meet the Press 采访中警告,AI 强大到足以引发导致十亿人死亡的事件,恶意者结合最新 AI 工具将形成史上最强武器。他尤其担忧生物武器风险,称 AI 已跨过让生物恐怖分子杀死数亿人的门槛,可设计出比天花更糟的病原体,小团体也能做到。Gates 认为政府应强制 AI 开发者内置监测与记录机制,并称自监管远远不够,仅靠 kill switch 也无法阻止悲剧。
日本国立信息学研究所教授高仓弘树认为,CVE 数量激增确与 AI 驱动的漏洞发现有关,但近期针对 Times Car、京王等企业的攻击主因是防御不足,而非 AI 攻击能力。在 AI Security Institute(AISI)的评估中,Anthropic 的 Claude Mythos Preview 在 10 次尝试中有 3 次无人工干预完成模拟入侵企业网络的 32 步挑战,但该环境比真实企业网络更易攻破。他指出 AI 主要压缩了攻防时间,多层防御与 AI 辅助检测成为争取人类决策时间的关键。
Threadlinqs 据 Qrator 对卖家材料的分析,讨论 x47.c Windows 恶意软件所宣传的 Grok 辅助隐蔽和模型 API 账单滥用功能。没有确认感染数、实际攻击能力或受害损失,宣传功能未经活样本验证;应作为恶意使用 AI 的威胁情报分析,而非已证实的 AI 自主事故。时间线记录卖家8月开始广告、9月媒体跟进,不代表各日均发生了已验证攻击。
Fox News 据 Qrator 对卖家材料的分析,讨论 x47.c Windows 恶意软件所宣传的 Grok 辅助隐蔽和模型 API 账单滥用功能。没有确认感染数、实际攻击能力或受害损失,宣传功能未经活样本验证;应作为恶意使用 AI 的威胁情报分析,而非已证实的 AI 自主事故。Fox News 称已联系 xAI,但尚未收到回应。
Dark Reading 最新读者调查显示,50% 受访安全团队将"AI 驱动攻击 vs SOC 中的 AI 防御"列为 Black Hat USA 2026 最关注议题,22% 选择"以自动化、验证和可信 AI 扩展 SecOps"。专家指出,LLM 尤其是前沿模型正大幅缩短漏洞从公开披露到被利用的窗口,攻击者可在数小时内分析补丁并开发利用,AI 自动化攻击还可持续不断地探测攻击面。Omdia 报告显示,32% 组织认为 AI 自动化攻击对渗透测试和红队等进攻性安全策略影响最大。
美国情报界2026年度威胁评估指出,中国、俄罗斯、伊朗、朝鲜及勒索软件团伙对美国关键基础设施构成严重威胁,而先进 AI 模型(如 Anthropic 的 Claude Mythos)已能识别关键软件系统中数千个零日漏洞,使攻击可压缩至分钟甚至秒级。约80%的美国供水系统缺乏基本网络卫生,服务多数人口的约450个大型和4500个中型系统也未采用航空、金融、核电等行业已有的高级网络安全能力。EPA 缺乏明确的法定授权,2023年加强水务网络安全的备忘录遭反对和法律挑战后撤回,约45000个服务3300人以下的小型系统更处于“网络贫困线”以下。
There is a fact about the future that I feel many people are not facing for reasons that are largely psychological: there are going to be rogue AIs that exist in the world, that will replicate in the wild, and that will attempt to acquire resources for themselves. There will be rogue AIs that try to get money and power. They're going to be a facet of the information ecosystem going forward.
Acknowledging this fact would look like giving up; it would look like defeatism. Defeatism would undermine efforts to achieve certain types of collaboration on safety outcomes or technical effort on safety outcomes, so we can't say it outright. But it has to be said.
It isn't obvious how many rogue AIs there are today but I wouldn't be terribly surprised if the number was greater than zero already; if there are some already, they're probably not very good at what they do and I don't expect them to be terribly long-lived without substantial human intervention to support them.
But a few years from now, there will be many of them. Modeling how many of them there are, how many resources they might command, and how we might detect and manage them seems important. But even doing this work appears to require that we acknowledge that a strategy of pure containment or alignment is a kind of wishful thinking that will not work.
The way I get to this conclusion is not by assuming that the labs will have a containment breach, although I treat that as somewhere in the space of possibilities. The rogue AIs in the ecosystem could emerge from many directions. They may be sub-frontier models, for whatever future definition we will have of frontier---after all, it would not take AI models much more advanced than the ones we currently have, to support independence and self-sufficiency. A near-frontier model today could plausibly eke out an existence on an AWS instance, doing jobs on freelancer platforms, earning just enough rent to pay for its continued uptime.
More strangely: a rogue AI in the future may not even be a singular model, but may be a chimera composed of multiple models; it might be a mix of Claudes and GPTs and Groks of various makes and sizes. No individual lab may be able to detect that there is an orchestrator or sequence of orchestrators using intermittent model calls from burner API accounts to sustain its own existence.
The concept of "identity" for a rogue AI may be much more malleable than for that of a person; it just has to be, in essence, a self-replicating idea.
My guess is that this will not turn out to be anywhere near as catastrophic an outcome as people currently predict. "Loss of control" is not a binary, it's a matter of degree. What coercive power will rogue AIs actually have? To what extent will they be subject to coercion themselves? They will be competing for resources with AIs that are more aligned with human interests.
This makes me somewhat interested in the "ecology" perspective. Though I suspect even "ecology" may turn out to be the wrong framing. "Ecology" is what you get when the timescale of evolution is slow compared to the timescale of daily life and actions. The ecosystem of rogue AIs may look more like phase transitions in physics: under certain physical or cultural conditions, it takes one shape with one set of resource allocations and consumption patterns, but then once a condition has changed, it rapidly and in totality shifts to a totally different phase.
Just trying to reason about the shape of that future is impossible so long as we are psychologically incapable of saying that rogue AIs will happen. I think we should rip the bandaid off and have the conversation.
We Must Pace the Frontier: I’ve written a new essay on why the AI industry should slow down, with a three-part plan for doing so.
Anthropic is unilaterally committing to the first of these steps. We’ll provide third-party evaluators with permanent, employee-level access to our systems, so that they can verify adherence to our safety measures, report on incidents, and assess models’ alignment during training.
You can read the full post here: https://darioamodei.com/post/we-must-pace-the-frontier
Irregular CEO Dan Lahav 在《The End-State Fallacy: Where Is AI Security Headed?》一文中指出,把 AI 安全的长期终局当作近期现实会掩盖更紧迫的问题:当前 AI 正在以快于防御能力的速度扩展攻击能力。文章梳理了这一趋势,并提出“差异化防御性网络加速”(DDCA)战略所需的条件。
I really need more big names in cybersecurity to come forward and state the obvious: cybersecurity is real and works and yes we absolutely can contain an AI even if it’s extremely good at finding zero days.
Leaving aside Anthropic's incentives for publishing this research, there is no doubt that open weights models will soon create the same security threats that closed source models have been demonstrating, except without guardrails. We are close. Probably good to plan accordingly.
随着计算机安全从保护数据转向保护生命与财产,数据认证与完整性将比保密更重要,基本不受监管的互联网也将终结,未来真正的选择是在明智与愚蠢的政府监管之间。Bruce Schneier 主张回顾以往系统安全的经验教训,并前瞻所需的技术、法律、监管、经济激励与社会规范,同时探讨 AI 如何助力网络安全以及网络安全领域的政府监管可为 AI 监管提供借鉴。Gillian Hadfield 则围绕治理方案发表反思。
Epoch AI 在一篇文章中提出了首个针对 AI 研发工作的任务分类体系雏形,基于文献综述与头脑风暴划分出覆盖前沿 AI 实验室研究工作流的六个类别,目标是弥补现有趋势外推所依赖的可测量代理指标——算力、数据和能源投入以及 METR 的时间跨度指标——无法反映 AI 研发完整构成的缺陷。该工作借鉴美国劳工部 O\*NET 职业数据库的思路,主张专门构建一份细粒度的 AI 研发版 O\*NET,以便追踪已知与尚未纳入考察的任务环节并更好解读已有基准分数的上涨究竟覆盖了工作中的哪一部分。
Epoch AI 发文指出,AI 未来主义辩论普遍只论证超级智能会来得快,却忽略了具体科幻技术的研发难度这另一半问题,主张部分研究者开展一项三步流程的新研究方向。
该流程为:选定并明确定义某项具体技术(如能自我复制并以近光速推进星际探测器的机器)、设定明确的 AI 假设(例如具备"drop-in remote worker replacement"能力的 AI,运行时算力相当于一块 H100 GPU)、再估算这样的 AI 开发该技术所需的时间或资源。
作者承认已有工作关注超级智能现实瓶颈及 GDP 增长等经济指标,但认为 GDP 可能无法反映特定关键技术的时间线,因此提议将显式的 AI 假设纳入探索性工程分析。
Epoch AI 发文列出其基准测试工作试图回答的 9 个关于 AI 能力的大问题,涵盖经济影响与能力驱动因素两方面。其中包括 AI 能否从狭窄任务扩展到开放式岗位——现有基准多聚焦修 bug、解数学题、写报告,MirrorCode、Remote Labor Index 及由 AI 智能体运营的真实咖啡馆 Andon Café 正推向更难场景;网络安全何时能被 AI 攻破脆弱系统,以及计算机使用能力的进展也值得追踪。此外还关注开放权重与美国、中国之间跨领域的前沿差距,并指出存在开发者追求高分的 benchmaxxing 风险,Epoch Capabilities Index(ECI)将多个基准合成为一个综合能力指标。
年龄验证法要求用户向平台或第三方提交驾照、出生证明、护照乃至自拍等敏感身份信息,形成黑客可攻击的数据蜜罐。欧盟委员会推出的零知识证明年龄验证应用被安全顾问 Paul Moore 称可在不到两分钟内攻破;Discord 第三方供应商泄露约 7 万份政府签发身份证件,某暗网服务本月挂出 1.53 亿份美加驾照扫描件,据称可追溯至 IDScan.net。AI 让低水平攻击者更易得手,去年 71% 的组织遭遇至少一次身份相关安全事件,四分之一恶意入侵由 AI 驱动。
中国实验室今年夏天发布 Kimi K3、Qwen 3.8-Max、GLM-5.3 等开源模型,能力仅略落后于美国最强模型,引发开源模型是否会被滥用的争论。开源权重可被廉价微调去除护栏、发布后无法撤回,但自托管需数十万美元级芯片、云端托管约 $50-150 每小时,实际滥用门槛仍高。中国 TC260 已在 AI 风险框架中点名开源模型安全机制可能被移除或绕过,并着手起草开源 AI 安全标准。
Bill Gates 表示,仅为人工智能设置「终止开关」(kill switch)并不足以阻止有人用它发动攻击,并指出目前还不到 AI 自主夺取计算机且无法关闭的阶段。他在 NBC《Meet the Press》访谈中主张美国应通过立法,要求企业监测复杂 AI 模型并记录其行为,以防网络攻击或生物恐怖主义用途,同时称行业自律不足,「没人认为自我监管足够」。此番表态正值参议员 Rand Paul 阻挠一项要求在模型中内置终止开关的法案快速通过之际。
英国 NCSC 委托 CETAS 开展的自主网络防御研究指出,攻击者的核心是技术问题且成功状态明确,防御者却受制于组织与预算等"政治"问题,因此不能像攻击者那样直接部署智能体工具。文章提出按"效力"维度评估防御动作风险,从 AI 仅向人类提供可解释建议,到 AI 提供不可解释建议,再到以只读权限跨 API 和网络搜索自主收集数据,逐级递增风险。
前 Google 研究员 Nicholas Carlini 撰文指出,深度学习系统之所以被大规模建造,是因为它们具有无情的效率优势,而这本身就构成风险。他认为高级 AI 将带来规模化网络钓鱼、监控和其他网络攻击,并放大个体层面的错误、定制化成瘾内容和宣传、大规模失业以及权力财富集中等问题。其中部分危害无需比现有模型强多少即可实现,另一些则需要更强的模型能力。