What The Hugging Face Cyberattack Teaches Executives About Using AI
The cyber crisis that hit the Hugging Face technology start-up last month is a good example of why AI is a double-edged sword for business leaders. The company said in a blog post that an autonomous AI agent broke into its systems, but that it also used AI to help detect the intrusion and determine what had happened.
Five days later, OpenAI announced that its own AI models were responsible for the incident during an internal cybersecurity test. In response to the episode, on August 18, Reuters reported that OpenAI had since slowed down the development of some of its AI models and took steps to strengthen safeguards so the attack would not be repeated.
The episode illustrated the advantages and dangers of the rapidly developing technology—and what business leaders can learn from using AI to help manage a business crisis.
Advantages and dangers of AI
Thomas Wolf, the co-founder of Hugging Face, which is an online platform for AI builder, said that the incident is "a wake-up call" for the industry. He told BBC’s Newsday program that "this will be one of the most common types of cyber attacks we see,” but that most firms are not aware that the "game has changed.”
Trudi Beggs, director of client services for 8020 Communications, thinks that AI will never replace flesh-and-blood communications teams when a crisis strikes. That’s because “the vulnerabilities of the technologies need to be understood before incorporating it into crisis response plans. But used properly, it gives teams a much clearer picture of what is happening, much faster. It is particularly valuable for media and social monitoring , sentiment analysis, identifying emerging narratives and scenario planning…. ,” she told me in an email message.
Business leaders should regard AI platforms as crisis communication tools, not as replacements or substitutes for hands-on experience in dealing with emergencies. “Let’s say you have a crisis playbook ready for your organization and a crisis hits and you want to move quickly. This is where an AI platform—ideally a confidential one—can be helpful. You can feed it information about the crisis, and it can customize the playbook for that specific situation,” Vishakha Mathur, a communications expert, told me in an email message.
Effective crisis management requires judgment, empathy and a moral compass, “characteristics which are not yet present in AI agents. So, delegating responsibility for crisis management to AI is not an option. However, while decision-making responsibility must remain with business leaders, there are ways in which AI can assist them,” Jonathan Hemus, managing director and crisis management consultant at Insignia, told me in an online interview.
Another practical application for AI is using it to help avoid groupthink and challenge what could be dangerous assumptions. “Under the pressure of a crisis, leaders can turn in on themselves, thinking only of the impact of the situation on them and their business. So, asking AI to provide a perspective from stakeholder groups such as employees, customers and investors provides insight and empathy which might otherwise be lacking,” according to Hemus.
Using AI to understand vs. communicate
There is also an important difference between using AI to understand a crisis faster and using it to communicate about one faster. One of AI’s most useful roles is helping organizations quickly make sense of what is happening, Emily B. DeJeu, an assistant teaching professor of business management communication at Carnegie Mellon University’s Tepper School of Business, told me in an online interview.
Another reason to be cautious about relying on AI is that crisis communications can pose critical legal risks for companies. “AI-generated communications could inadvertently admit liability, make unsupported claims, contradict a company’s established legal strategy, or expose confidential information. For that reason, organizations shouldn’t use AI to bypass established review processes, and any AI-generated information (whether or not it’s made public) should be run through [legal] compliance,” DeJeu advised.
She warned that AI can also reinforce flawed assumptions, produce authoritative-sounding messages before the facts are confirmed, and accelerate communications that an organization may later come to regret. Her rule of thumb is especially useful for executives: using AI to reduce the time it takes an organization to understand what is happening can be valuable; using it primarily to reduce the time before reassuring the public can be much riskier.
After all is said and done, there is an important role for the technology.“AI should support leaders’ judgment, not replace it. The biggest danger of involving AI in crisis communication is that it speeds up not only good crisis communication processes, but also bad or inaccurate ones,” she concluded.
The lesson for business leaders is that using AI does not have to be an either/or decision—but they should know when and how to use the technology at the right time. Yes, AI can speed up a company’s response to a corporate emergency, but business leaders should ensure that it is moving them in the right direction—and for the right reasons.
Loading article...