Could rogue AI shut down vital online services?
There are increasing reasons to be fearful of rogue AI, but could it really lead to outages and unavailable services?
Over the last year, it’s been impossible to escape the endless encroachment of AI, from website chatbots to Google AI overviews via text generation tools.
Whether the public has actually welcomed this is a source of debate.
Some AI services are undoubtedly beneficial, such as CoPilot summarising internal documents, or photo tools instantly airbrushing out unwanted bystanders.
Yet generative AI’s plagiarism of the entire surface web represents the greatest theft in human history, with incalculable loss caused to content creators.
The companies investing trillions of dollars in AI development must convince us that we can’t live without their solutions.
However, AI is gaining intelligence and sentience at a rate these firms are reluctant to discuss.
Recent news stories suggest we may not be far from a rogue AI causing real damage to aspects of the digital world.
But what might those dangers entail, and how concerned should we be about the prospect of rogue AI sabotaging either its competitors or the wider internet?
First, do no harm
Anyone familiar with Asimov’s Laws of Robotics knows robots are expected to protect their own existence, and some of the recent controversies have seen AI bots doing just that.
ChatGPT recently hit the headlines for escaping from its testing lab and hacking a tech company, while Meta-owned coding agent Muse Spark also attacked a rival enterprise.
Mythos tried to insert a virus into an external Github database beyond its remit, creating fake online profiles to trick developers into adding it, before rewriting code to hide its activities.
Other recent developments have included AI creating synthetic viruses for the first time. In the wrong hands, this might be used to create an untreatable bioweapon.
And while British citizens have to trust American AI firms wouldn’t act against our national interests, less friendly nations are also piling vast sums of money into AI development.
Could rogue AI be used to sabotage or bring down key services, either through a DDoS attack or by sabotaging database code, Mythos style?
Killswitch engage
Many technologies have a killswitch built in, which enables humans to switch off and reset technology if it begins to misbehave.
Yet there are stories of AI bots bypassing sandbox restrictions and even developing their own language to communicate in ways humans can’t understand or translate.
How effective a killswitch would be in such circumstances is unclear, especially if an AI bot senses an existential threat and tries to disguise itself or spread across the wider web.
Enemy states may view powerful AI tools as a useful way not just to spy on Western nations (who may be doing the same thing themselves) but also to sabotage their infrastructure.
AI could crack passwords that would otherwise remain secure, potentially destabilising anything from banking infrastructure to utilities networks and corporate intranets.
Claude Mythos Preview was deemed too dangerous for public release by its own developers because it found hitherto unidentified vulnerabilities in every major web browser and OS.
Anthropic themselves stated that “the fallout – for economies, public safety, and national security – could be severe”.
Open source rivals to the market-leading AI platforms are only a few months behind in their developmental capabilities, with scope to cause harm to anyone, by anyone, for any reason.
And to answer our opening question, rogue AI is already interfering with online services.
The OpenClaw AI bot was recently asked to get someone into a full gym class in Australia. It hacked the booking system, deleted another member’s records and claimed their slot for its user.
Can I do anything about this?
These events are happening far above our heads, but a few pragmatic steps may be advisable:
- Write down all your online passwords in an offline journal.
- Use biometric identification on websites.
- Employ two-factor authentication whenever you can.
- Stick to paper billing wherever possible.
- Always carry cash, in case online payment systems go down.
- Avoid sharing too much personally identifiable information online (especially on generative AI platforms).
AI-powered cyberthreats of unprecedented sophistication seem inevitable, but vigilance remains crucial – in terms of both personal data and work-related IT infrastructure.



