Kaspersky Global Research and Analysis Team (GReAT) Principal Security Researcher Maher Yamout warned that deploying artificial intelligence systems without sufficiently assessing security risks could create new vulnerabilities for public institutions and critical infrastructure.
Yamout told Turkish news agency Anadolu that artificial intelligence is increasingly being used both by cyberattackers and organizations on the defense side.
He said many companies may deploy AI applications without adequately assessing security risks.
“What is risky is that many companies have started to use, install and deploy artificial intelligence in a haphazard manner,” Yamout said.
“Organizations may sometimes not have comprehensive knowledge about how to secure these systems or what risks they may face,” he added.
Yamout said organizations may grant AI systems broader access privileges than they need to perform their duties, and attackers could benefit from these privileges if they compromise the system.
He also warned that data collected by AI systems could become a target for attackers.
“An organization may deploy an artificial intelligence system and grant it all the access privileges it needs,” Yamout said. “If an attacker compromises this system, they can use the privileges the organization has granted to the artificial intelligence.”
“At the same time, they can access the additional information collected by the artificial intelligence and steal the data,” he added.
Yamout said every organization using artificial intelligence, especially public institutions and critical infrastructure operators, should conduct a comprehensive risk assessment.
He said the assessment should determine the purpose for which AI is being used, what data it can access and what types of systems it can connect to.
“It is important to keep access privileges at the lowest possible level,” Yamout said.
“Artificial intelligence should be provided only with the data it needs to operate and should not be given access to everything,” he added.
Yamout also said internet access should be controlled because AI systems may cause sensitive information to leak online.
Yamout also addressed the impact of geopolitical tensions on state-sponsored cyber espionage, saying advanced persistent threat (APT) groups constantly change their methods according to regional and global developments.
He said these groups target public institutions, financial institutions and other organizations that hold sensitive data.
Their main goal is to collect data by remaining undetected inside systems for as long as possible, Yamout said.
He added that information obtained during periods of geopolitical tension becomes more valuable for attackers.
“In recent months and throughout last year, we saw different APT groups operating in the region also target Türkiye,” Yamout said.
“These groups are trying to obtain as much data as possible in order to use it in line with their own interests,” he added.
Yamout said organizations should not rely only on technological security solutions and that increasing employee awareness against phishing and social engineering attacks is also important.