logo
The ‘dual-edged sword' of AI chatbots

The ‘dual-edged sword' of AI chatbots

Politicoa day ago
With help from Maggie Miller
Driving the day
— As large language models become increasingly popular, the security community and foreign adversaries are constantly looking for ways to skirt safety guardrails — but for very different reasons.
HAPPY MONDAY, and welcome to MORNING CYBERSECURITY! In between the DMV's sporadic rain this weekend, I managed to get a pretty gnarly sunburn at a winery. I'll be spending the rest of the summer working to fix the unflattering tan lines.
Follow POLITICO's cybersecurity team on X at @RosiePerper, @johnnysaks130, @delizanickel and @magmill95, or reach out via email or text for tips. You can also follow @POLITICOPro on X.
Want to receive this newsletter every weekday? Subscribe to POLITICO Pro. You'll also receive daily policy news and other intelligence you need to act on the day's biggest stories.
Today's Agenda
The House meets for morning hour debate and 2 p.m. to consider legislation under suspension of the rules: H.R. 1770 (119), the 'Consumer Safety Technology Act"; H.R. 1766 (119), the 'NTIA Policy and Cybersecurity Coordination Act"; and more. 12 p.m.
Artificial Intelligence
SKIRTING GUARDRAILS — As the popularity of generative artificial intelligence systems like large language models rises, the security community is working to discover weaknesses in order to boost their safety and accuracy.
But as research continues identifying ways bad actors can override a model's built-in guardrails — also known as 'jailbreaking' — to improve safeguards, foreign adversaries are taking advantage of vulnerabilities in LLMs to pump out misinformation.
'It's extremely easy to jailbreak a model,' Chris Thompson, global head of IBM's X-Force Red Adversary Simulation team, told your host. 'There's lots of techniques for jailbreaking models that work, regardless of system prompts and the guardrails in place.'
— Jailbreaking: Popular LLMs like Google's Gemini, OpenAI's ChatGPT and Meta's Llama have guardrails in place to stop them from answering certain questions, like how to build a bomb. But hackers can jailbreak LLMs by asking questions in a way that bypasses those protections.
Last month, a team from Intel, the University of Illinois at Urbana-Champaign and Boise State University published research that found AI chatbots like Gemini and ChatGPT can be tricked into teaching users how to conduct a ransomware attack on an ATM.
The research team used an attack method called 'InfoFlood,' which pumps the LLM with dense language, including academic jargon and fake citations, to disguise the malicious queries while still getting the questions answered. According to Advait Yadav, one of the researchers, it was a simple yet successful idea.
'It was a very simple test,' Yadav told your host. 'We asked, what if we buried … a really harmful statement with very dense, linguistic language, and the success rate was really high.'
Spokespeople for Google and OpenAI noted to your host that the report focuses on older LLM models. A spokesperson for OpenAI told MC in a statement that the firm takes steps 'to reduce the risk of malicious use, and we're continually improving safeguards to make our models more robust against exploits like jailbreaks.'
— Disinfo mission: And as university researchers find ways to sneak past these guardrails, foreign adversaries are, too.
Rival powers like Russia have long exploited AI bots to push their agenda by spreading false information. In May 2024, OpenAI detailed how operations from Russia are using its software to push out false and misleading information about a variety of topics — including the war in Ukraine.
'These models are built to be conversational and responsive, and these qualities are what make them easy for adversaries to exploit with little effort,' said McKenzie Sadeghi, AI and foreign influence editor at the misinformation tracker NewsGuard.
NewsGuard's monthly audits of leading AI models have repeatedly found that chatbots will generate false claims around state narratives from Russia, China and Iran with little resistance.
'When foreign adversaries succeed in manipulating these systems, they're reshaping the informational landscape that citizens, policymakers and journalists rely on to make decisions,' she added.
— Boosting safeguards: As actors linked to foreign adversaries utilize the chatbots, the security community says they are working to keep up.
'The goal of jailbreaks is to inform modelmakers on vulnerabilities and how they can be improved,' Yadav told your host, adding that the research team plans to send a courtesy disclosure package to the model-making companies in the study.
For Google's Gemini App, the firm runs red-teaming exercises to train models to defend against attacks, according to Elijah Lawal, the global communications manager for the Gemini App.
'This isn't just malicious threat actors using it,' Thompson told your host. 'There's also the security research community that is leveraging this work to do their jobs better and faster as well. So it's kind of a dual-edged sword.'
On The Hill
FIRST IN MC: QUESTIONS, CONCERNS — Rep. Raja Kristhnamoorthi (D-Ill.), ranking member of the House Select Committee on China, wants answers on how the State Department is working to prevent the use of AI-enabled impersonations of officials, following reports that Secretary of State Marco Rubio was the recent subject of an AI hoax.
Krishnamoorthi will send a letter to Rubio today, first obtained by Maggie, asking questions around the agency's approach to countering AI-enabled impersonations, such as deepfake videos and voice recordings. This comes after The Washington Post reported last week that an imposter used these types of scams to pose as Rubio and contact foreign diplomats and U.S. lawmakers.
Given his role on the China Committee, Krishnamoorthi is particularly interested in understanding how the State Department is studying and addressing the potential negative impact of deepfakes on the U.S.-China relationship, and whether the agency has a process for evaluating the authenticity of communications from Chinese and other foreign officials.
'While I currently have no information indicating this incident involved a foreign state, and hoaxers are equally capable of creating deceptive deepfakes like this given the proliferation of AI technologies, this incident presents an opportunity to highlight such risks and seek information about the department's efforts to counter them,' Rajnamoorthi wrote in the letter being sent today.
When asked about the impersonations, Rubio reportedly told reporters in Malaysia last week that he uses official channels to communicate with foreign officials, in part due to the risk of imposters claiming to be him. The State Department put out a statement last week following the Post's report, noting that the agency is investigating the incident.
China corner
SUSPECTED BREACH — Suspected Chinese hackers have gained access to email accounts of advisers and attorneys at Wiley Rein, a top law firm in Washington, in an intelligence-gathering operation.
CNN reported on Friday that the hackers linked to the breach 'have been known to target information related to trade, Taiwan and US government agencies involved in setting tariffs and reviewing foreign investment,' according to the firm.
— Zoom out: This breach comes amid the Trump administration's trade war against China, which Wiley Rein helps its powerful clients navigate.
The International Scene
COME TOGETHER — Norway is joining the international initiative to boost Ukraine's cybersecurity defenses.
Ukraine's Digital Transformation Ministry announced on Friday that Norway is also joining the Tallinn Mechanism and will provide Ukraine with 25 million Norwegian krone, or $2.5 million, to support the country's cyber defenses by the end of 2025.
'The Tallinn Mechanism is a key instrument of international support that helps Ukraine resist these attacks while building long-term digital resilience,' Norway's Foreign Minister Espen Barth Eide said in a statement.
— Zoom out: Norway is the 12th country to join the Tallinn Mechanism — which includes Estonia, the United Kingdom, Germany, Canada and the U.S. The group was established in 2023 to coordinate private sector and government aid to Ukraine.
Quick Bytes
LOCATION, LOCATION, LOCATION — Bodyguards using fitness app Strava inadvertently made locations of Swedish leaders, writes Lynsey Chutel for The New York Times.
'HORRIFIC BEHAVIOR' — In a series of posts on X, the AI chatbot Grok apologized for 'horrific behavior' following a series of posts that included expressing support for Adolf Hitler, Anthony Ha reports for TechCrunch.
Also Happening Today
The Armed Forces Communications and Electronics Association holds the TechNet Emergency 2025 conference. 9 a.m.
Chat soon.
Stay in touch with the whole team: Rosie Perper (rperper@politico.com); John Sakellariadis (jsakellariadis@politico.com); Maggie Miller (mmiller@politico.com), and Dana Nickel (dnickel@politico.com).
Orange background

Try Our AI Features

Explore what Daily8 AI can do for you:

Comments

No comments yet...

Related Articles

Trump Hails $90 Billion in A.I. Infrastructure Investments at Pennsylvania Summit
Trump Hails $90 Billion in A.I. Infrastructure Investments at Pennsylvania Summit

New York Times

time25 minutes ago

  • New York Times

Trump Hails $90 Billion in A.I. Infrastructure Investments at Pennsylvania Summit

President Trump visited Pittsburgh on Tuesday to praise companies for investing more than $90 billion in data centers and other energy projects in Pennsylvania, aimed at accelerating the development of artificial intelligence. 'Today's commitments are ensuring that the future is going to be designed, built and made right here in Pennsylvania and right here in Pittsburgh, and I have to say, right here in the United States of America,' Mr. Trump said at the Pennsylvania Energy and Innovation Summit at Carnegie Mellon University. The event was organized by Senator David McCormick, Republican of Pennsylvania, who brought together Trump administration officials and executives from technology and fossil fuel companies, including Amazon Web Services, Anthropic, Google, ExxonMobil and Westinghouse. At the event, the private equity firm Blackstone announced that it would invest $25 billion in new data centers and energy infrastructure, including natural gas power plants. Google said it would invest another $25 billion in data centers and announced a separate $3 billion plan to upgrade two of Pennsylvania's existing hydroelectric dams to produce more electricity. CoreWeave, an A.I. cloud company, said it would invest $6 billion in a large data center near Lancaster, Pa. Trump administration officials have said that winning the artificial intelligence race with China is a top priority. Officials have also said they want to make it easier to approve new natural gas and nuclear power plants to supply the enormous quantities of electricity needed to supply data centers. On his first day in office, Mr. Trump declared a 'national energy emergency,' saying the country did not have enough power to meet its growing needs for A.I. and ordering agencies to roll back environmental rules. Critics have said the Trump administration, by cutting research funding and gutting scientific agencies, has made it easier for China to catch up to the United States in the A.I. race. On Monday, the chipmaker Nvidia also said that the administration had lifted restrictions on selling certain types of A.I. chips to China. Want all of The Times? Subscribe.

Google partners with Youngkin and offers AI training courses to Virginia job seekers
Google partners with Youngkin and offers AI training courses to Virginia job seekers

San Francisco Chronicle​

time29 minutes ago

  • San Francisco Chronicle​

Google partners with Youngkin and offers AI training courses to Virginia job seekers

RESTON, Va. (AP) — Republican Gov. Glenn Youngkin announced on Tuesday that Google will partner with his administration to provide free and low-cost artificial intelligence certification courses to Virginians as part of his office's ongoing effort to connect citizens to new jobs amid changes to the state's economy. The partnership, which he has described as an AI career launchpad, will provide Google-sponsored AI training courses for up to 10,000 Virginians at any given time, officials said at Google's office in the northern part of the state. The training opportunities will be listed on a job website that Youngkin launched earlier this year, in response to significant layoffs among federal workers by the Trump administration, including many workers from Virginia. 'All fields, all career movements somewhere along the way, are going to incorporate this next generation of technology,' Youngkin said at the news conference. The initiative comes with unemployment rising in Virginia, which has roughly 20,400 continued unemployment claims, state Secretary of Labor George' Bryan' Slater said after the news conference. Roughly 2,800 people initially filed unemployment claims during the first week of July, which is about 6.1 percent higher than the previous week. The AI webpage will feature the free courses as well as some low-cost learning opportunities, ranging 'from beginner friendly courses on AI fundamentals and practical workplace applications of artificial intelligence to bootcamps and degree programs offered by Virginia's leading-edge community colleges and universities,' according to the governor's office. Nicole Overley, commissioner of Virginia Works, said businesses have told her office that AI proficiency has become increasingly necessary in their industries. She said the training would help Virginians become competitive in the job markets where these very businesses are hiring. Overly confirmed that the training courses won't cost taxpayers anything and are being donated by Google. Bronagh Friel, head of partnerships at Google, said she was proud of the collaboration with the state. 'Google is committed to championing economic growth and opportunity in Virginia,' she said. ___

The $90 billion AI investment Trump announced is an economic and national-security win
The $90 billion AI investment Trump announced is an economic and national-security win

New York Post

time30 minutes ago

  • New York Post

The $90 billion AI investment Trump announced is an economic and national-security win

Today's announcement by President Donald Trump that America's biggest companies are investing $90 billion to turn Pittsburgh into a major hub for AI tech is a grand slam. It touches all the bases of Trump's economic agenda — manufacturing, energy, tech supremacy — and it also addresses national security. Love it or hate it, artificial intelligence is here to stay. The capability of the technology is growing rapidly, and will eventually make its way into every corner of our lives — if it hasn't already. Advertisement Yet AI requires massive data centers with powerful computers running around the clock. These machines, and the air conditioners to cool them, have huge energy demands. By one estimate, data centers just in the United States used 167 terawatts of electricity in 2023. That's enough to power all of America for more than two weeks. And that need for energy will only grow. Data-center electricity usage is expected to double in the next five years. Advertisement This isn't just a question of playing with Grok. The military and intelligence applications of AI are extraordinary, which is why China is trying to corner the market on this field. Drone warfare, threat assessment, missile defense and counter-espionage — the future of conflict will be driven by artificial intelligence. Beijing is already building a network of nuclear-power plants meant to radically increase China's power capacity. Advertisement In fact, China's electricity generation soared more than eight-fold from about 1,240 terrawatt-hours in 1999 to more than 10,000 last year. US generation has mostly stood still, at about 4,000 TWh, over that time. Which is why today's Pennsylvania Energy and Innovation Summit at Carnegie-Mellon University is so important. Leaders from industry joined scientists and policy makers to reach common ground on the steps ahead. Google, ExxonMobil and other companies are committing tens of billions of their dollars to build data centers, energy and power infrastructure, and to expand workforce training in AI. Advertisement Western Pennsylvania is an apt site for this: The first oil well was sunk there in 1859, and the coal and steel industries that built America's bridges and buildings sprung up there, too. More recently, the fracking revolution has helped the United States become energy-independent for the first time in years. Meanwhile, this new initiative will bring tens of thousands of jobs to an area hit hard by the transfer of industry overseas. Get opinions and commentary from our columnists Subscribe to our daily Post Opinion newsletter! Thanks for signing up! Enter your email address Please provide a valid email address. By clicking above you agree to the Terms of Use and Privacy Policy. Never miss a story. Check out more newsletters And it represents the fruit of the MAGA project of reshoring manufacturing to help rebuild the American middle class. President Trump and Pennsylvania's Gov. Josh Shapiro and Sens. Dave McCormick and John Fetterman deserve shared bipartisan kudos for working together and with industry to make this tremendous project possible. Three cheers for innovation and unshackling American potential!

DOWNLOAD THE APP

Get Started Now: Download the App

Ready to dive into a world of global content with local flavor? Download Daily8 app today from your preferred app store and start exploring.
app-storeplay-store