| Updated:
Everything companies have done to prepare for a cyber attack is now “completely old world” following the OpenAI–Hugging Face hack over the summer, a top City lawyer has warned.
The “unpredecented” July hack, in which OpenAI’s model escaped a controlled test by itself and broke into the AI platform Hugging Face, prompted a probe from the UK government and set alight warnings around the pace of AI development.
Those concerns gathered pace last week when Jacob Coxon, an Anthropic researcher, quit his job and warned the people building AI “earnestly believe that it could kill us all by the end of the decade”.
Jonathan Kewley, Clifford Chance partner and chair of its tech group, told City AM that the pace of AI development now posed an immediate threat to financial services companies in Britain.
“It genuinely feels like an emergency for the City of London and for companies that have built up a very strong cyber posture,” he said.
“[Businesses] now have to think again about what this means for them, but also be alert to the fact that this new technology is going to make it 100 times harder to keep businesses cyber secure,” he added.
Firms have long been warned about cyberattack risks but, according to Kewley, attack volumes are rising from a handful to hundreds per week.
Boards now must become conversant in the world of AI literacy and cybersecurity, he said, adding that executives should now be reviewing everything from incident-response plans, supply-chain controls, vendor contracts, insurance coverage, and workforce training.
UK best placed to be leader on AI security
But the threat is also an opportunity for the UK, Kewley said, pointing out that Britain was among the early movers on AI security, hosting the first AI safety summit at Bletchley Park back in 2023 during Rishi Sunak’s premiership.
“We have GCHQ, MI5, MI6, our security services, and our relationships with other countries in terms of the Five Eyes [security alliance] are head and shoulders above other countries, so we’ve got a real leadership position to take here,” he added. The AI Security Institute, National Cyber Security Centre, the Financial Conduct Authority (FCA) and the Bank of England are also all ahead on AI safety concerns, Kewley said.
Prime Minister Andy Burnham used his first address to the United Nations to call for a single set of global standards governing frontier AI, including greater transparency and access to powerful models. He told the audience that governments, not tech companies, must make the biggest decisions about AI, as he pledged to put AI regulation at the heart of Britain’s G20 presidency.
According to Kewley, companies now need to get ahead of them.







