The Dual Nature of Artificial Intelligence: Opportunities and Risks
Artificial Intelligence (AI) is undeniably powerful, offering remarkable opportunities for business transformation . However, the rapid integration of AI technologies also introduces significant risks that organizations must address. The accelerated adoption of these solutions leads to the emergence of new vulnerabilities, creating a precarious balance between leveraging AI’s benefits and safeguarding against potential attacks.
At the core of these risks lies a “ toxic combination ” formed by four key factors.
Understanding the Threat Landscape
The first factor is critical vulnerabilities . Systems built on Unix, which are often employed for AI workloads, contain numerous libraries that may not always be audited or updated regularly. Research indicates that cloud workloads incorporating AI display a vulnerability rate of 70% , compared to approximately 50% for non-AI workloads.
Cloud workloads involving AI show a higher vulnerability rate (70%) than those that do not include this technology.
The second element of concern is exposed public access . For instance, 14% of data storage on platforms like Amazon Bedrock has public access blocking disabled, which paves the way for potential attackers to exploit these openings.
Next, we have excessive privileges . Data shows that 77% of organizations utilizing Vertex AI Workbench on Google Cloud have at least one instance configured with the default Compute Engine service account set to “editor.” This setting allows full access to the project, thereby exposing sensitive information and critical resources.
Finally, there are dangerous default configurations . A startling 90.5% of SageMaker notebooks enable root access by default. Such configurations allow any user with access to compromise the environment with administrative privileges.
The Jenga Effect in Cloud Systems
The coexistence of these four elements amplifies the risk of attack while complicating the detection and control of adverse impacts. In the realm of AI, where models process sensitive data or make critical decisions, the repercussions can be catastrophic—ranging from the manipulation of predictions to the unauthorized disclosure of personal information.
This issue encapsulates what we refer to as the “ Jenga effect .” Cloud service providers typically build new services on top of existing ones, thus inheriting default characteristics that may not align with best security practices . A default configuration in an underlying component like a virtual machine or a service account can jeopardize the entire stack of services layered above it, including machine learning tools such as notebooks, training pipelines, or inference APIs.
The most alarming aspect is that these issues often remain “behind the scenes,” going unnoticed by security and development teams.
The silent nature of these vulnerabilities means that security and development teams frequently rely on automated cloud management systems, inadvertently overlooking the potential risks lurking in their environments. As such, adopting a robust exposure management strategy is vital for navigating the nuanced landscape of AI.
Building a Safe AI Environment
Given this complex and rapidly evolving scenario, companies must embrace a fortified and automated solution for risk management. Doing so will transform the lofty ambitions surrounding AI into tangible and secure business benefits. It will ensure that the soaring aspirations of innovation rest on solid foundations rather than precarious ones that could easily collapse.
The author is the Director of Security Engineering for Tenable Latin America and the Caribbean.

