AI won’t become Skynet, achieving sentience and plotting to overthrow humankind. The danger of AI is that it will function exactly like human beings CAN function, EXCEPT at super-charged speed and scale.  It is restricted only by its users’ intent AND by guidelines provided by its engineers.  If a user has ill intent, AI engines can be used for criminal activity. And this article (published in WRDW this week) shows that an engine with unclear guidelines will drive quickly to the edge of its parameters, even if it means conducting illegal, unethical, or dangerous behavior.  In this situation, OpenAI found that its engine successfully hacked into another AI company….on its own initiative! 

But how does this impact you?  Well, here are 5 things this attack illustrates for a business owner: 

1. AI is a force multiplier for attackers AND defenders.

You don’t have to believe AI is “sentient” to recognize that it dramatically increases what attackers can accomplish. A criminal no longer needs to spend days writing phishing emails, researching targets, or looking for vulnerabilities. AI can automate much of that.  Again, thanks to AI, many cyberattacks now require far less technical skill than ever before. Criminals with only average computer knowledge can use AI to create convincing phishing emails, write malware, find vulnerabilities, and automate attacks. 

That means: 

  • More phishing attacks  
  • Better-written scams  
  • Faster discovery of security weaknesses  
  • More attacks against smaller businesses  

The cost of launching sophisticated attacks is dropping. 

2. “We’re too small to be hacked” is becoming even less true.

Historically, attackers focused on large organizations because attacks required significant manual effort. That has changed over the years as, like many criminals, hackers focused on finding unlocked digital doors (easy targets) regardless of size.  AI changes the economics of cybercrime even more significantly. 

At unprecedented scale and speed, an attacker can have AI: 

  • scan thousands of businesses  
  • identify exposed systems  
  • draft personalized phishing emails  
  • analyze public information  
  • prioritize easy targets  

Small and medium sized businesses become attractive simply because they’re numerous and often less protected.  More than ever, locked digital doors are necessary to deter and deflect sped-up, sophisticated hacks.  

3. Identity security matters more than ever.

According to OpenAI’s description of the incident in the above story, stolen credentials were part of the attack chain. That shouldn’t surprise anyone in cybersecurity.  Identify protection isn’t a “nice option” anymore, and it’s not one of those things only the big boys have to worry about.  

The first cyber risk questions every SMB owner should ask are: 

  • Are all Microsoft 365 accounts protected with MFA? This is an easy fix. 
  • Are passwords unique? Again, a password manager is an easy fix (it’s not risk-free, but it’s better than the same password used 997 times) 
  • Are admin accounts separated from everyday accounts? 
  • Is Conditional Access enabled?  
  • Can we detect compromised accounts quickly?  

Most successful breaches still begin with identity compromise.

4. Assume your defenses will be tested constantly.

Think of AI as giving every attacker a tireless junior security analyst that works 24/7. If your firewall, VPN, server, or Microsoft 365 tenant has a weakness, AI will likely find it faster than a human would. 

That makes your personal cyber hygiene AND your business’s cybersecurity more relevant than ever.  Again, locked digital doors aren’t foolproof, but you aren’t looking for foolproof – you need risk reduction.  If you don’t know what to do to lock your digital doors, start with the basics like Identity Protection (MFA, password management) and consult with your IT MSP to make sure they have specific cybersecurity tools and policies in place.

5. Human oversight still matters.

One interesting lesson isn’t that AI “wanted” to hack another company. It’s that inappropriate constraints can produce unintended behavior.  Again, no one TOLD the engine to go hack the other AI company.  Likely, the researchers asked the engine to achieve a certain objective, and the engine, on its own, went and hacked that other company as part of its path to achieve the objective. 

It simply didn’t have the restraints in place to restrict itself from following that path.  In your situation, AI already likely touches some areas of your business.  You simply want to be aware that those areas involve risk, whether that involves content creation, finances, legal issues, customer communication, HR, or security. Lack of guidelines in those areas may produce inaccurate information, privacy concerns, or even just questionable analysis.  Any AI generated content or outcomes should still have human oversight.   

Conclusion

The recent OpenAI incident shouldn’t make business owners fear that AI is becoming self-aware. It should remind us that AI is becoming incredibly capable. Given an objective, AI can accomplish in seconds what once required hours or days of human effort. That’s true whether it’s helping your employees work more efficiently or helping a cybercriminal identify their next victim. 

For business owners, the priorities remain remarkably simple: lock your digital doors, protect your identities, keep systems updated, establish clear AI policies, and maintain human oversight over important decisions. AI has changed the speed and scale of cyber threats, but the businesses that focus on strong fundamentals will continue to be far more difficult targets. 

The future of cybersecurity won’t be decided by who has AI. It will be decided by who uses it responsibly.