Sleeper Agent AI?

A long time ago there was once an incident where an application just stopped working. It was quite serious so all hands on deck to find the source of the problem. No changes, no releases, it had stopped working (I hate those ones).

Long story short - old code had been calling an external open-source library (Yikes) and that library had gone offline. Lessons given and learned.

The below was an interesting article to read with that historical context. If LLM code generation becomes mainstream, in the same way that Cloud empowers other parts of the business (if you set it up correctly), how do you protect against that? How to not bring in anything external or have absolute confidence you know the source? Supply chain threats at another level.

I thought about it…I don’t know. But a shiver did go up my spine. There are going to be some interesting lessons learned.

How ‘sleeper agent’ AI assistants can sabotage code
Today’s safety guardrails won’t catch these backdoors

Subscribe to Gary P Shewan

Don’t miss out on the latest issues. Sign up now to get access to the library of members-only issues.
jamie@example.com
Subscribe