Foreign control of AI vendors a board-level risk, ASD says

By
Follow google news

AI sovereignty issue raised in new guidance.

Australian boards should treat the foreign ownership, control and influence of their artificial intelligence (AI) providers as a cyber risk in its own right, the Australian Signals Directorate advises.

Foreign control of AI vendors a board-level risk, ASD says

That is one of the four key action points in new guidance from the ASD, co-written with the Australian Institute of Company Directors (AICD), that asks boards to assess the risks of relying on AI providers.

ASD and AICD do not refer to any particular reason for the advice in the guidance, which comes after the highly-publicised United States government access restriction order placed on American AI provider Anthropic's Mythos-class models in June this year.

Currently, nearly all leading frontier AI model developers are headquartered in the US, while China has emerged as the only other country with multiple companies developing competitive AIs.

Outside the US and China, France's Mistral remains one of the few credible independent alternatives.

Similar AI and digital sovereignty concerns have appeared in Australian public discourse recently.

"The inescapable lesson of the global instability of the 2020s, is that if we are always dependent on someone else, somewhere else, we will always be vulnerable," prime minister Anthony Albanese said in a speech at the University of Sydney on July 15.

Beyond the foreign control of AI, the guidance asks boards to review how frontier AI models could affect their organisations' security posture, which includes new AI-enabled threats.

Countering agentic AI-powered threat environments is another action item for boards, along with improving governance, processes and capabilities to mange use of the technology within their organisations.

The guidance also reiterates how frontier models accelerate the tempo of attacks.

It warns that vulnerability discovery and exploitation timelines could compress "from days to hours" lowering the technical skill barrier for malicious actors, while allowing frontier models to chain multiple low-severity vulnerabilities into high-impact compromises.

Boards are advised that models can now conduct malicious activity with "little to no human oversight", and that AI agents operating inside an organisation should be granted only the minimum access their duties require.

Add iTnews as your trusted source

Got a news tip for our journalists? Share it with us anonymously here.
Copyright © iTnews.com.au . All rights reserved.
Tags:

Most Read Articles

Microsoft can't kill dogged researcher's Copilot for Word worm

Microsoft can't kill dogged researcher's Copilot for Word worm

Russia-linked "Midnight Blizzard" group hijacks hotel wi-fi with CaptiveCrunch

Russia-linked "Midnight Blizzard" group hijacks hotel wi-fi with CaptiveCrunch

Services Australia describes fraud, debt-related machine learning use cases

Services Australia describes fraud, debt-related machine learning use cases

ASD to critical infrastructure ops: be ready to isolate systems for three months

ASD to critical infrastructure ops: be ready to isolate systems for three months

Log In

  |  Forgot your password?