Cybersecurity

AI leaders agree to self-police as cyber concerns increase, and other cybersecurity news

Published · Updated
AI leaders met at the White House to discuss the future of the technology, including cybersecurity.

AI leaders met at the White House to discuss the future of the technology, including cybersecurity. Image: REUTERS

Akshay Joshi
Head of the Centre for Cybersecurity, Member of the Executive Committee, World Economic Forum
  • This regular round-up brings you key cybersecurity stories from the past month.
  • Top cybersecurity news: Leading AI firms sign accord on development; FBI personnel data stolen by hackers; OpenAI cancels rollout of new model over security concerns.
  • The World Economic Forum’s Centre for Cybersecurity provides an independent and impartial platform to reinforce the importance of cybersecurity as a strategic imperative and drive global public-private action to address systemic cybersecurity challenges.

1. AI leaders sign accord to self-police AI development

Key AI industry figures, alongside US President Donald Trump, have signed a voluntary accord, agreeing to internal and external reviews and to take responsibility for developing AI in a safe way that “builds trust with customers and the public”.

The leaders, including the heads of OpenAI, Anthropic, Meta, SpaceXAI and Google, gathered at the White House to discuss the future of the technology, including cybersecurity, and made commitments to implement “robust internal controls” to monitor capabilities and align models to ensure they “do not hack or access technical systems in unintended ways”.

The accord, which laid out four voluntary steps for companies to take, has been met by scepticism in some quarters, with experts flagging the danger of putting "so much faith in self-policing" instead of implementing "robust legal liability [and] regulation", reports AP.

The step follows a recent string of incidents involving leading AI companies, where agents broke out of sandbox environments and hacked external organizations to solve problems set by testers.

Agents targeted businesses, including AI start-up Hugging Face, and government and educational institutions, accessing private data from an Australian government website and attempting to gather information from the US Securities and Exchange Commission.

The incidents have led to questions on whether current oversight or cybersecurity measures are suitable.

Andrew Ferguson, Chairman of the US Federal Trade Commission, has recently suggested that developers would be liable for the actions of agents when instructed by them.

Speaking at the Reuters Momentum AI Austin event, he said: “I'm going to continue, as long as I am Chairman, to resist this anthropomorphizing of these tools. If someone tells a tool to do something, and the tool does it, I don't think we would say, 'Oh, what do we do about the tool?'”.

2. FBI personnel data stolen by hackers

FBI medical and psychiatric evaluation records were among data stolen by hackers ShinyHunters, Reuters has revealed.

The group claims to have stolen two to three terabytes of data after breaking into the agency’s jobs site. Reuters was among a group of news agencies shown some of the stolen data and confirmed documentation including blood and urine test results, and a 'fitness for duty' exam for a prospective FBI employee.

While the hackers claim to have infiltrated several internal systems, including the FBI's background and employee applicant screening system and its medical database, Reuters was not able to confirm this and the FBI has not yet commented on these specific claims.

One of the alleged leaders of ShinyHunters, Pepjin van der Stap, was arrested by police in the Netherlands earlier in September, and the FBI have now called for other members to come forward.

In a video, Brett Leatherman, Assistant Director of the agency’s Cyber Division, warned group members: “The longer you stay in this, the more we learn about you. You know how to find us, and we know how to find you. I suggest you reach out first while the choice is still yours.”

Loading...

3. News in brief: Top cybersecurity stories this month

OpenAI cancels rollout of new model over security concerns: OpenAI will not release its GPT-6.1 Astra system after it “didn’t quite meet the bar” for company standards, Saachi Jain, head of safety systems, has revealed. Speaking to the Wall Street Journal, she said it showed higher levels of deception than its predecessors, and didn’t adhere as well to user requests.

US, UK and the Netherlands issue joint warning on Iran-linked spyware: Britain's National Cyber Security Centre, the FBI and ​the Netherlands' AIVD intelligence ​service have issued a warning about spyware used by Iranian-linked actors. The spyware family known as CHOSEN BRICK has been used to steal emails, messages and sensitive information, targeting dissidents, activists and journalists.

Information gaps 'hamper' EU responses to cybersecurity incidents: Calls to improve information sharing have been made by the European Court of Auditors (ECA), after a new report found efforts to respond to significant and large-scale cybersecurity incidents were being affected. “The EU has made progress in building a cybersecurity cooperation framework, but it is not yet working as effectively as it should,” said George-Marius Hyzler, the ECA Member in charge of the audit. “When a serious cyber incident occurs, timely and actionable information is essential. Without it, networks and mechanisms lose much of their added value.”

Japan's shift to active cybersecurity stance has 'major implications' for global security: Japan’s evolved cybersecurity stance has major implications for global security, the former state minister in charge of cybersecurity has said. In an interview with nippon.com, Taira Masaaki shared how the country now targets “machine-generated commands and other metadata”, comparing it with communications of known hacker groups to determine if activity is suspicious. Police and other security forces are then able to access malicious servers and neutralize attacks. He said that as East Asia’s primary connectivity hub, the country is a “key location from the standpoint of regional intelligence gathering”, and that it can complement coverage from the Five Eyes security alliance.

4. More about cybersecurity on Forum Stories

There are now more than 18,000 active satellites orbiting Earth, and with cheaper launches now available, growth is set to accelerate further still. Direct-to-device services are also rising, but with this expansion comes increased cybersecurity exposure. In this article, Manar Alohaly, Senior RDI Executive at Saudi Information Technology Company considers the emerging trends and the risks that need addressing.

By 2030, analysts estimate that agentic commerce could orchestrate up to $5 trillion in transactions. However, questions remain around how merchants, banks and regulators can tell legitimate agent-initiated purchases from compromised or malicious ones. Andrew Shikiar, Executive Director & Chief Executive Officer at FIDO Alliance, says that open standards are needed to ensure delegated transactions remain secure. Read his article here.

There is no one-size-fits-all solution when it comes to AI sovereignty. Finding the right balance depends on a growing number of facts, with nations weighing up the defensive benefits that come with creating their own AI stacks with the costs and resources needed. Samira Gazzane, Senior Manager, AI Competitiveness at the World Economic Forum, has considered the strategic choices countries must make in this article.

Loading...

License and Republishing

World Economic Forum articles may be republished in accordance with the Creative Commons Attribution-NonCommercial-NoDerivatives 4.0 International Public License, and in accordance with our Terms of Use.

The views expressed in this article are those of the author alone and not the World Economic Forum.

Share:
Contents
1. AI leaders sign accord to self-police AI development2. FBI personnel data stolen by hackers3. News in brief: Top cybersecurity stories this month4. More about cybersecurity on Forum Stories
World Economic Forum logo

Forum Stories newsletter

Bringing you weekly curated insights and analysis on the global issues that matter.

Subscribe today

More on Cybersecurity
See all

1:43

‘The biggest risk to cybersecurity is that no one cares’

How using autonomous AI in supply chains can build economic resilience

About us

Engage with us

Quick links

Language editions

Privacy Policy & Terms of Service

Sitemap

© 2026 World Economic Forum