Cybersecurity

Security Researcher Warns of the Risks of Granting AI Systems Broad Privileges in Sensitive Infrastructure

Maher Yamout warned that operating artificial intelligence systems without sufficient security assessment could open new attack paths, particularly when these systems receive broader privileges than they need or collect sensitive data. He called on organizations to reduce privileges, control internet access, and strengthen employee awareness of phishing and social engineering.

2026-09-11
4 min read
10 views
certi.news
Security Researcher Warns of the Risks of Granting AI Systems Broad Privileges in Sensitive Infrastructure

Maher Yamout, a senior security researcher on Kaspersky's Global Research and Analysis Team (GReAT), warned that the uncontrolled use of artificial intelligence systems could add new vulnerabilities and risks to organizations, particularly government entities and operators of critical infrastructure.

Yamout told Anadolu Agency that an increasing number of organizations have begun using artificial intelligence without adequately assessing the security risks associated with operating it and integrating it into existing systems. According to him, the problem includes cases in which systems are granted broader access privileges than necessary to perform their tasks.

Privileges and Data at the Heart of the Risk

The researcher explained that compromising an artificial intelligence system could allow an attacker to exploit the privileges that the organization granted to the system itself. The risk may also extend to the data the system collects during its operation, as this information could become a target for theft if the attacker manages to take control of it.

According to the warning, this is not limited to access to databases, but also concerns the systems and services to which the artificial intelligence is connected. The broader the scope of access, the more resources could be exploited if a breach occurs.

What Should Organizations Review?

Yamout called on every organization that uses artificial intelligence to conduct a comprehensive assessment identifying the purpose of using the system, the data it can access, and the systems connected to it. He also emphasized keeping privileges at the lowest possible level and providing the system only with the data necessary to perform its task.

He also pointed to the need to control the system's internet connection, warning that uncontrolled access could lead to the leakage of sensitive information. These recommendations show that introducing artificial intelligence into an operational environment should not be treated as an isolated software addition, but rather as a new element with privileges and connections that must be defined and monitored.

Continued Targeting of Organizations in Turkey

Yamout linked the risks of artificial intelligence to a broader context involving state-sponsored cyberespionage activities. He said that advanced persistent threat (APT) groups change their methods in response to regional and global developments and target government and financial institutions as well as entities that retain sensitive data.

He explained that the primary objective of these groups is to remain inside systems for as long as possible without detection in order to collect data. He added that information becomes more valuable to attackers during periods of geopolitical tension, noting that different APT groups have targeted Turkey during recent months and the past year.

certi.news's Take

The practical change highlighted by this warning is not the emergence of a specific vulnerability in a particular product, but rather the shift of artificial intelligence into a position in which it sometimes possesses broad privileges, data, and connections. Therefore, reducing privileges and controlling access should precede expanded use, particularly in critical environments.

The source also confirms that technical solutions alone are not enough; Yamout emphasized the importance of increasing employee awareness of the risks of phishing and social engineering. The statement provides no details about a specific breach incident or a framework for measuring the level of risk, so the recommendations remain general, and each organization needs to translate them into an assessment tailored to its systems and data.

News source
Anadolu Agency Technology
Open original source ↗
c
Author

certi.news

In the same category

You may also like

View all news