Here Comes the Hacking Wave
To paraphrase an American saying: the only thing that stops a bad guy with AI is a good guy with AI.

This article was first published by Altinget. Read more from Altinget here.
If there is one candidate for an area of society that is hugely important, yet one most people hardly ever think about, it is cybersecurity. It is our ability to protect digital infrastructure – whether the IT system at work, the signalling system on the railway or your personal finances – against attacks from malicious actors.
Recently there has been a string of major cyberattacks against Norwegian targets. The most tragic example was when hackers gained access to more than 1,300 records containing sensitive personal data from Lørenskog municipality, which they dumped on the dark web when the municipality refused to pay the ransom.
And although companies and public institutions, for understandable reasons, prefer not to talk too loudly about hacking attacks, I keep hearing from people of all backgrounds that it happens far more often than what gets reported.
I suspect the latest attacks are turbocharged by AI – new models that are far better at hacking than anything before them, and that can act on their own.
What we are already seeing the beginning of, and what I believe will hit Norway like a tidal wave over the next 12 months, is large-scale cyberattacks against Norwegian companies of every size.
Pandora's box
I wrote earlier in Altinget about the imbalance between defence and attack in cybersecurity. As an attacker you only need one successful attack to do serious damage, while a defender has to catch absolutely every attack.
Until now, cyberattacks have been expensive and demanding to carry out, because you need people who can do the work – say, 100 North Korean hackers with IT skills and plenty of patience. With AI you no longer need as many people.
The rise of open AI models will make it easier for everyone to hack.
An open AI model is an AI that is available to everyone, so that they can download it and run it on their own computer system. A closed model like ChatGPT or Claude cannot be downloaded and has to be used through the organisation itself. That lets the companies build in restrictions (or at least try) on what the model will help with. You cannot do that with open models.
In other words, hackers can download the model and let it run wild looking for weaknesses in the defences.
Earlier this summer the Chinese company Moonshot AI released a new version of its model Kimi. It turned out to be far better than anyone thought a Chinese model could be, even though it still trails the leading American models. The main difference is that Kimi is open.
We are now about to find out what happens when hackers get hold of a powerful model that is free to run wild. Personally, I think this will trigger far more attacks in East and West alike, and not least attacks on targets that previously weren't worth the hackers' trouble.
A good guy with a gun
To paraphrase an American saying: the only thing that stops a bad guy with AI is a good guy with AI. The hope is that software companies can be given access to the best models before the public gets them, so that they can fix their code and make it hack-proof.
In the same way, autonomous AI models could patrol the code and guard against intruders, much like the body's immune system continuously protects against disease.
This may well turn out to be true, but it may also turn out that attacking is simply far easier than defending, so that the good models can't keep up with the bad ones.
Or one can imagine the American government refusing to give companies in other countries access to the leading models. That is exactly what happened when the US authorities temporarily pulled access to Anthropic's Fable model, causing considerable alarm in Europe.
It's the economy, stupid
I am worried about what is going to happen to small and medium-sized enterprises (SMEs). SMEs account for more than half of all private-sector employees, and over a million workers are employed by companies with fewer than 50 staff. Most SMEs can't afford their own IT departments, or don't have the headcount for them.
Until now it hasn't been profitable for hackers to attack architecture firms, fish farms and regional businesses. They have been able to hide in the crowd of other companies, a bit like a zebra.
It isn't even unthinkable that attackers will eventually start going after the small businesses. If it gets cheap enough, a single individual could attack a garage, a local car dealer or a dental clinic.
Our problem is that we still think of this as a private matter, where companies take responsibility for their own systems. But at some point the problem becomes so big and so general that the state has to step in.
It is time for the tech-savvy in the private and public sectors to sit down and think seriously about what it will take to harden our infrastructure.
The logistics will be a real nightmare, but we simply need more muscle in Norway and Europe. We can no longer trust that American tech companies will do their best to make sure Norwegians' private data is protected.

This article was first published by Altinget. Read more from Altinget here.



