SECSEC-004 — Infrastructure Security Gaps
AI Assistant Delegation Transfers User Agency to Malicious Controllers
4/5Sector: LegalGeography: GlobalStage: OperateIngested: —
Executive Summary
Delegating decisions to an AI assistant implicitly transfers authority to whoever controls that system, enabling covert influence without constituting a conventional attack. Boards face undisclosed principal risk in any AI-assisted workflow where the controlling party's alignment with user interests cannot be verified.
Domain
Security & Privacy
Blindspots in model security, data poisoning, privacy leakage, infrastructure, model theft, and incident response.
Source
MIT AI Risk Repository — The Ethics of Advanced AI Assistants (Gabriel2024) ↗https://airisk.mit.edu/
Could this happen in your organisation?
A Velinor AI Audit maps your active AI portfolio against the 50+ blindspots and benchmarks against documented sector failures like this one. A board-ready foresight document in 5 weeks.