UK AISI used AI to find its own cloud flaws
Archive item — written before sources were shown.
A two-week internal exercise combining AI agents with human red-teaming found a critical lateral-movement chain in AISI's own staging cloud environment.
The UK AI Security Institute’s engineering team ran a two-week internal cybersecurity exercise pointing frontier AI models at their own staging cloud environment, combining static code analysis, autonomous agent probing, and human-in-the-loop red-teaming, per a July 7 case study. The most capable models found previously unknown critical flaws, including a multi-step lateral-movement chain that let an ordinary user reach other users’ workloads and data, with human-guided AI methods outperforming fully automated approaches at low token cost.
- 01Finding Cloud Misconfigurations with Frontier AI: A Case Studyaisi.gov.uk · primary
