Putting artificial intelligence systems into use before their security assessments are completed increases cyber risks because of their broad access privileges. Kaspersky GReAT Lead Security Researcher Maher Yamout says that systems should access only the data and resources they need.
Yamout reports that advanced persistent threat groups are also targeting institutions in Turkey by exploiting geopolitical tensions. For this reason, in addition to technical measures, it is important for employees to recognize social engineering and phishing attacks.
Why it matters
This assessment shows that, in the use of artificial intelligence, access boundaries and security oversight must be part of institutional decision-making just as much as speed. The issue concerns not only technology teams, but also managers who grant these systems access to data and resources, as well as employees expected to notice signs of attacks. The fact that institutions in Turkey may be targeted by threat groups linked to geopolitical tensions requires vulnerabilities arising from artificial intelligence to be addressed together with phishing and social engineering attempts. However, the current framework leaves open questions about which oversight steps institutions will implement and how access privileges will be restricted before security assessments are completed.