It’s typical that bad guys make use of new technologies more quickly, and profitably, than good guys. A.I. is not an exception, as is emphasized by a column in New Hampshire Business Review (read it here) titled “Will hackers use your own A.I. against you?”
Businesses have spent years asking what AI can do for their employees. Fewer have asked what it would do for an intruder inside an employee’s account.
Consider how a network intrusion used to unfold. An attacker obtained credentials, logged in, and then faced the slow work of orientation. Which server holds the financial records? Where are the contracts? Who has access to payroll? That reconnaissance took days or weeks, and it generated noise.
An AI assistant removes that obstacle. An intruder holding valid credentials no longer needs to hunt. They can simply ask. Show me everything about the pending acquisition. Summarize our correspondence with our largest customer. Find any document containing bank account numbers. The assistant searches every location that employee can reach, reads the results, and delivers an organized answer in seconds.
The solutions are similar to solutions against traditional phishing: training, inconvenient double-checking, limits on sharing information. Annoying, difficult, inefficient, but increasingly necessary. Cue the “this is why we can’t have good things” lament!
