AI, Espionage And Startups: Why Founders Should Be Paying Attention To The Latest Security Warnings

As the race to build the next generation of AI accelerates, so too do concerns about who has access to the technology, research and expertise powering it. This week, two separate security warnings on opposite sides of the Atlantic have emphasised the increasingly blurred lines between AI innovation, national security and espionage.

According to reporting by The Guardian, MI5 has issued an unusual public warning to UK universities over the China General Technology Research Institute (CGTRI), which the agency alleges is linked to China’s Ministry of State Security. MI5 made incredibly bold claims that the organisation funded research involving more than 100 UK-affiliated academics, including work in areas such as artificial intelligence, cybersecurity and covert communications. China has since categorically denied the allegations.

At the same time, cybersecurity company Proofpoint revealed details of a campaign by the China-aligned threat group TA419, which allegedly impersonated prominent AI policy figures and researchers in an attempt to gain access to the accounts of individuals working in AI policy, regulation and strategy. Reuters reported that the campaign targeted a small number of experts connected to think tanks, universities, law firms and government circles involved in shaping AI policy, showing proof of email exchanges between said academics and the alleged perpetrators.

 

Concerning, Yes; But Why Should Startups Care?

 

At first glance, these stories may seem more relevant to governments and universities than startup founders, but that’s not necessarily the case. After all, plenty of today’s most valuable AI companies are built on research originating from universities, academic partnerships and highly specialised technical talent. And so, as AI becomes increasingly important to economic competitiveness, that ecosystem is attracting greater attention from both state and non-state actors.

The MI5 warning specifically referenced research areas including AI and cybersecurity, both of which sit at the heart of the UK’s startup ecosystem. According to MI5, it’s highly likely that universities may have engaged with the organisation in good faith without knowing about its alleged intelligence links.

For startups, this serves as a reminder that intellectual property, research partnerships and talent pipelines can carry security implications alongside commercial opportunities. Thus, the lesson here is to be absolutely sure about who you’re corresponding with, what information you’re offering someone and how you’re doing it.

 

 

It’s All About Information Now

 

The Proofpoint findings point to another growing challenge in the realm of influence and information gathering. Rather than targeting source code or products directly, the campaign allegedly focused on people involved in shaping AI policy and strategy. According to Reuters, the apparent goal was intelligence collection relating to AI regulation, export controls and national AI strategy rather than technology theft itself.

This is a pretty noticeable difference, because it’s almost like an amateur scam in terms of tactics, but the stakes are so much higher, both for the individual and the academic institutions and nations at large. The strategy is also based on the premise that humans are most likely the weakest link in the metaphorical chain which, while it may very well be true, indicates very specific intent and premeditation.

The fact of the matter is that the future of AI will not be determined solely by better model: it will also be shaped by regulation, access to computing power, export controls, talent flows and international cooperation. Thus, understanding where policy is heading can be almost as valuable as understanding the technology itself.

 

Innovation And Security Increasingly Go Hand In Hand

 

None of this means startups should avoid international collaboration by any means. The UK startup ecosystem has benefited enormously from global talent, research partnerships and investment, and by all accounts it ought to continue to do so. There is so much to be gained from this kind of collaboration.

However, the latest warnings highlight a reality that many founders may not have considered a few years ago which is that AI is no longer just a story about innovative technology. Now, it’s becoming a farm more significant part of a geopolitical story.

As governments compete to secure leadership in artificial intelligence, startups operating in areas such as AI, cybersecurity, advanced computing and deep tech may find themselves working in sectors that are attracting greater scrutiny from regulators, investors and security agencies alike. Thus, while conducting due diligence and protecting intellectual property has always been important, there’s a new kind of spotlight on it now that simply cannot, and should not be ignored.