Taiwan using AI to counter AI threats
NEW THREATS: Some AI models are able to scan software and identify vulnerabilities, which could be linked together for a ‘kill chain,’ digital affairs minister Lin Yi-ching said
By Shelley Shan / Staff reporter
Taiwan is working with major US technology firms to use advanced artificial intelligence (AI) models to scan government systems and critical infrastructure for vulnerabilities, the Ministry of Digital Affairs said yesterday.
Minister of Digital Affairs Lin Yi-ching (林宜敬) made the remarks when asked about the threats posed by agentic AI, following reports of OpenAI agents breaching Australia’s Medicare portal.
After being blocked from accessing medical data through a public portal, OpenAI agents used external URL-scanning services to infiltrate a Services Australia portal, execute commands and create unauthorized files.
Minister of Digital Affairs Lin Yi-jing, fourth right, poses for a photo with business representatives at the ministry in Taipei yesterday.
Photo: Chiu Chao-chen, Taipei Times
The incident could be the world’s first documented case of an AI agent hacking a government Web site.
While no personal patient data was compromised, the incident exposed a massive vulnerability in traditional defenses, which are ill-equipped to identify and tackle adaptive, multistep autonomous evasion tactics.
The fallout was worsened by a three-month delay in disclosure by OpenAI.
Asked if the government’s security measures were capable of defending against cybersecurity threats posed by AI agents, Lin said the government is countering AI cybersecurity threats with AI.
Some advanced AI models are able to scan software and identify vulnerabilities, which could be linked together to form a “killer chain,” he said, adding that the ministry is working with Anthropic, OpenAI, Google and Microsoft to obtain advanced AI models to scan critical infrastructure.
As for whether AI model operators would be obligated to report cybersecurity incidents and be subject to investigations, including turning over audit logs, Lin said the government is drafting laws to regulate agentic AI, but legislative progress might be unable to keep pace with the rapid advancement of AI.
New AI technologies could emerge by the time the government implements new laws, so it is more important to have the capability to quickly identify new cyberthreats and defend government systems, he said.
The ministry in July also launched a joint cybersecurity audit program for information technology (IT) service providers that have contracts with government agencies.
The Administration for Cyber Security said that it consolidated 121 audits scheduled for this year into 16 joint audits to establish consistent standards, bolster cybersecurity and reduce the administrative burden on government auditors and contractors.
The joint audits found several common cybersecurity risks, including inadequate vulnerability scanning, failure to regularly update firewall rules, and insufficient account reviews and enforcement of the principle of least privilege, the agency said.
The program covers 16 IT service providers that mainly work with agencies under the Executive Yuan, with audits covering six major areas.
Next year, the program is to expand to central and local government agencies, increasing the number of audited service providers to 30 while broadening and deepening the scope of the audits.
Regarding reports on the planning and licensing of 6G spectrum, the ministry said that spectrum policy is still under discussion, and that the licensing schedule, spectrum bands and licensing method have yet to be finalized.
KioskNews shows a cleaned-up reading view extracted from the publisher’s page — the original always lives on their site, not ours.