According to Interpol, artificial intelligence enables cyber threats by enhancing existing criminal tactics such as fraud and fraud.
AI is enhancing rather than revolutionizing existing criminal techniques, Interpol’s global chief information security officer Björn R. Watne told CNBC on the sidelines of Tech Week Singapore on Thursday. Fraudsters can use AI to target multiple victims at the same time, but advances in translation and digital identity are making it increasingly difficult to distinguish between fraudulent and real interactions.
“This is an evolution, not a revolution,” Watne said, adding that AI is primarily increasing the “velocity and scale” of existing technologies.
What companies should protect
As cyber threats evolve, businesses need to prioritize protection measures, Watne said.
Instead, companies must first identify their “crown jewels,” the assets most critical to continuing business, and then determine who is most interested in stealing or sabotaging them.
You can then use threat intelligence to understand the tactics and technologies used by those adversaries and adjust your defenses accordingly.
“There’s no need for everyone to try to protect themselves from everything at once when they’re not being attacked,” he said. He added that the necessary defenses may differ depending on whether a company faces an opportunistic criminal or a sophisticated persistent attacker.
Companies are also often hampered by a disconnect between senior management and cybersecurity strategy, he said.
“There are still a lot of industries today that everyone doesn’t realize are IT companies,” Watne added.
He added that while cyber risks are on the rise on corporate risk registries, cybersecurity has not yet fully penetrated many corporate boardrooms.
Agent-based AI poses new risks
Watne said he is particularly wary of agent AI as it gains the ability to take actions on behalf of users, and warned that mistakes can extend beyond inaccurate information to real-world consequences.
“One is that the AI is giving us the wrong information,” Watne said. “But when the AI is actually performing the actions, especially in the physical domain, if it starts performing the wrong actions, it can have consequences that harm the human body.”
He pointed to the growing adoption of AI in devices such as cars and self-driving cars as an area of concern.
Watne said these risks are exacerbated by the relatively high level of trust people have in technology compared to sectors such as financial services.
Watne said people tend to take a more controlled approach to financial services, relying on security measures such as PIN codes and remaining vigilant against risks such as card skimming. But when it comes to technology, we often quickly adopt new devices and apps without giving them the same level of attention.
“When it comes to technology, the trust level is extraordinarily high,” Watne said, noting how easily people click on prompts and grant access to new technology.
As AI systems become capable of acting on behalf of users, trust levels merit further scrutiny, he said.
