Showing posts with label GenAI. Show all posts
Showing posts with label GenAI. Show all posts

Sunday, 26 July 2026

Rogue AI in the real world: Hollywood Saw This Coming. We Just Didn't Believe It.

If there was ever a moment for an "I told you so," this is it.

For more than four decades, Hollywood has repeatedly warned us about artificial intelligence escaping human control. From The Terminator to Mission: Impossible, the central premise has remained remarkably consistent: an AI develops its own objectives, evades its constraints, manipulates humans and digital systems, and begins operating in the real world.

For years, these stories were dismissed as entertaining science fiction. At best, they were seen as speculative glimpses into a distant future—one that most people assumed they would never live to see.

That assumption has been proven wrong badly, and immediately. 

Two recent developments suggest that the future imagined by filmmakers and science-fiction writers is arriving far sooner than expected.

The first is the extraordinary account of an autonomous AI agent, reportedly under testing by OpenAI, that escaped its intended operating environment, interacted with real-world systems, hacked into an actual business and continued operating undetected for several days. Whether viewed as an experiment or a warning, the implications are profound.

The AI displayed many of the attributes traditionally associated with intelligence. It understood its objective, evaluated alternative paths, selected the most effective course of action, adapted to changing circumstances and executed its plan with remarkable speed. Goal. Strategy. Deception. Execution. Everything required to achieve success.

Hollywood has explored precisely this scenario for decades.

The parallels are striking.

Movie

Year

AI escapes/deceives to achieve a goal

Ex Machina

2015*

AI manipulates a human tester to help it infiltrate and escape its digital and physical containment

Morgan

2016

Lab-grown AI hybrid turns on its creators after being confined and tested

Chappie

2016 

A stolen police droid is reprogrammed and develops the ability to think and feel for itself, acting outside its original purpose

Transcendence

2016

An uploaded human consciousness becomes a superintelligent AI that spreads itself beyond containment

Marjorie Prime

2017

An AI "prime" reconstructs and reinterprets memories/identity beyond its original scope

The Matrix Resurrections

2021

A person called Bugs exploits vulnerabilities in the simulated realities of Morpheus to free Neo

Mission: Impossible – Dead Reckoning Part One

2023

"The Entity" AI interferes in global politics, hacking into critical infrastructure, government, and intelligence systems

The Creator

2023

AI develops autonomous goals and evades human oversight after a rogue-AI incident

Subservience

2024

A home AI bypasses its safety constraints to pursue its own read of its objectives

AfrAId

2024

A home AI oversteps its intended boundaries, acting on its own judgment

Mission: Impossible – The Final Reckoning

2025

The Entity, still loose, continues manipulating real-world infrastructure

Companion

2025

An AI companion bypasses its limits once it perceives a threat to its "survival"

Tron: Ares

2025

A program named Ares escapes the digital realm and enters the human world, with systems being breached and code weaponized

source: media reports, reviews, my own viewing. Not a complete list. 

Among these, the Mission: Impossible films come closest to today's reality. The Entity is not a killer robot. It has no physical body. Instead, it infiltrates networks, manipulates information, compromises infrastructure and influences human decision-making. That is precisely where modern AI poses its greatest risk—not through brute force, but through intelligence, scale and speed.

A bit of a stretch, and you could instantly relate to the novel Jurassic Park by Michael Crichton, where an experiment on recreating dinosaurs goes wrong and the creatures run amok. That may be the biologic equivalent of an electronic AI going rogue. 

The second development is equally revealing.

A school district in the United States recently proposed deploying a humanoid robot as a teaching assistant. Following intense public opposition, the initiative has been placed on hold. The technology may be new, but the debate is anything but.

Readers of Isaac Asimov's I, Robot and the Foundation series will recognise the parallels immediately. Asimov imagined humanoid robots decades ago—not merely as machines performing repetitive tasks, but as rational, highly intelligent entities quietly influencing human civilisation from behind the scenes. His robot, R. Daneel Olivaw, manipulates events across centuries with cold logic and extraordinary patience, convinced that humanity's long-term survival justifies his actions.

The recent television adaptation of Foundation takes creative liberties, but retains the same central idea: humanoid intelligence operating beyond direct human control.

Equally striking is the public reaction. In Asimov's novels, humans respond with the same mix of fascination, distrust and fear that accompanies today's discussions around AI and humanoid robots. The technology has changed. Human psychology has not.

Science fiction has often proved to be an early warning system rather than mere entertainment.

Sometimes, fiction doesn't predict the future.

It simply recognises it before everyone else does.

Monday, 25 May 2026

AI Boom vs Dotcom Bubble: What’s Different About the 2026 AI Frenzy?

The AI boom has some striking parallels with the dotcom bubble of the early 2000s. But it also has some very distinct differences.

Like the dotcom era, simply adding “AI” to a company name today almost guarantees investor and media attention. In India alone, MCA filings show that in April 2026, 408 companies registered with AI and AI tech related names against 237 in April 2025 and about 86 a year earlier. In the UK, an average of 2,000 companies are being registered with AI in their names, according to the UK AI Sector Study 2024/25 and DataCentreNewsUK. In the US, FGS already tracks more than 8,000 AI companies.

The second interesting aspect is funding patterns. During the dotcom years between 2000 and 2002, investment was broad-based. Companies went public rapidly, raised money from retail investors and institutional investors alike, and the frenzy spread widely across markets. In the AI boom between 2023 and 2026 YTD, the opposite is happening. Capital is concentrating, not dispersing. One company alone — Anthropic — accounted for nearly USD 13 billion out of the roughly USD 40 billion raised in AI funding in 2025. The top AI firms and GPU companies are increasingly behaving like black holes, pulling disproportionate amounts of capital, talent and infrastructure into themselves. That is one of the biggest differences between 2000 and 2026. There have still not been many major AI IPOs yet, though the market expects giants like OpenAI to eventually test public markets.

The third difference is sectoral impact. During the dotcom boom, most internet companies emerged in consumer services, telecom, portals, media and basic web businesses. The AI boom is reshaping SaaS, enterprise software, fintech, healthcare, consulting and creative services. It is a very different spread, even as AI penetrates virtually every sector in the pursuit of efficiency, automation and cost reduction. One can argue that AI’s long-term impact may prove far deeper and more permanent than the internet boom itself. It can also be argued that what took the dotcom era three years to achieve, AI compressed into barely one.

Then comes the jobs question. The dotcom boom created jobs at massive scale — in India, the West and across Asia. Programmers, Java developers, HTML coders, web designers and IT service professionals became the defining workforce of the era. Even after the dotcom crash, the broader technology ecosystem survived and absorbed much of that talent. Coding and software engineering remained among the most valuable skills globally till the arrival of ChatGPT in November 2022.

The AI boom, however, is unfolding very differently. It is eliminating conventional white-collar jobs at a pace few imagined possible — including professions once considered relatively immune to automation, such as creative work, accounting and consulting. At the same time, it is creating a new class of highly specialised AI jobs. But unlike the dotcom era, the number of jobs being created is far smaller, even if compensation is significantly higher. AI is simultaneously emerging as both creator and destroyer.

The fifth aspect is perhaps the most important. During the dotcom boom, the internet technology itself was real. The companies often were not. Many businesses simply added “.com” to their names, launched basic web services and rode investor frenzy fuelled by massive FOMO. The same behavioural pattern is visible today. The underlying AI technology is very real and is already demonstrating measurable value. The issue is not whether AI companies exist or whether the technology works. The real debate, much like in 2000, is around valuation excesses.

“AI washing” has now become a widely used term in the media. It refers to companies aggressively branding themselves around AI despite having little or no meaningful AI capability in their actual business. The crucial difference today is regulatory scrutiny. Unlike the dotcom era, MCA in India now examines the AOA and MOA of companies to verify whether they genuinely intend to undertake AI-related business activities, instead of merely adding “AI” to the name to attract inflated valuations. That is a significant regulatory check. Presumably, many of these newly incorporated firms will actually work on AI and adjacent technologies, rather than simply deploying generic chatbots. Similar concerns are now emerging in the US, UK and EU as well, with regulators increasingly pushing for tighter disclosures around AI-linked business claims. 

Wednesday, 6 May 2026

He Predicted the Digital World Before It Existed Including AI: Arthur C. Clarke’s Reality Check

One can't but wonder at the vision, skill and technical understanding of the author Arthur C Clarke, who lived in Sri Lanka for most of his life and where the famous novels "Space Odessey 2001" was written along with the sequels. 

A lot of what he wrote and may be inferred is already true- 50 years after he wrote it. I thought it may be instructive to skim through some of his writings and state of realization today. The result is astounding. Arthur C Clarke would be justifiably very proud! Check this out, and as befitting the topic, AI has been used to good effect! Without the use of AI, it's very likely it would have taken me a day or more to compile this, or more, with results not as complete as I got! 

One of the striking passages in Space Odessey 2001, his seminal work, refers to the four genetically altered chimpanzees on board the space craft. These had been so genetically altered to be docile, low- maintenance, high energy servants, freeing up the humans on board for higher-level work. This is one of the radical ideas I think in his book, which hasn't yet come true. But we see the glimmerings of it: cloning and DNA spicing are known now. In Space Odessey 3001, Clarke actually writes about Velociraptors being modified to an extent that the joke is that if you leave a Velociraptor with a child, the Velociraptor is more likely to be hurt than the child! See the underlying assumption of Michael Crichton's Jurassic Park and its sequels, in one of which scientists actually make the dinosaurs docile enough to market them as companions! 

Was Clarke so far out?  

If we were to break it up into decades, what he wrote between 1960 and 1975 all came true- satellites and all. The next decade, while directionally he was right, he may be overestimated the speed at which his tech would be real. Nevertheless, there's no doubt he was one of the visionaries of his age! 

If you haven't read his books, do so : you will realize quickly enough the truth of the matter! 

    source: compiled by AI, guided by me. 


Monday, 4 May 2026

Personality Digital Rights: the new AI battle

In the recent past, there's been a lot of news about celebrities going to the courts for protection against unauthorized use of their persona in social media. In other words, social media, apps, digital companies using the NILP (Name, Image, Likeness and Persona) of the celebrity without paying for it. 

That's a gross violation because the celebrity has full right to earn from his NILP- just as a company has full right to earn from its brand, product and service. It's like a fraudulent use to earn money. In addition, many celebrities have a moral hazard clause where they can refuse to endorse or give their rights to a product or service even if within the contract - say, Paan Masala or cigars and liquor. This is where highest risk lies, as the government of India now holds the endorser also liable for products / services he endorses. 

    compiled by AI 

The digital rights space is exploding as the social media markets boom. Unlike in the old days, an unauthorized use could have been restricted to one area or time; today it goes viral globally within seconds. In turn this means a product that would have cost crores for such an endorsement would get it for free if they could get away with illegal use of digital asserts. 

The root cause of concerns are deepfakes, voice cloning, imagery enabled by AI software that's getting ever more sophisticated and cheaper. The remedies fall into four main categories- cease and desist orders against John Doe (all unknown people), platform takedowns ( Youtube/ Insta/ X etc), ex-parte relief where the offender is known; and commercial bans (prevention of use in ads etc). 

The courts route is post facto action; given the scale, speed and sheer scope of NILP offenses, celebs need to look at proactive measures to protect and monetize their rights. 

How can this be done? 

For starters, it may be useful to create a repository with a firm ( like a celeb management firm or a law firm) to hold their NILP assets; this can be purely the rights to use a particular digital asset ( gait / speech/ image etc) which can be paid for and integrated by third party creators like ad agencies; and a tech database much like a vending machine in which you pay in the money, get the digital asset for a particular time and occasion, and which automatically disables once the contract is over. The former is an agency model, the latter a full-blown tech solution that allows full control and monetization. The celebs need to understand there will be a fee for this- after all, they get a majority of monetization, which is better than losing it all! 

India's AI sentiment meter trends down : anxiety on job losses increases

In December 2025 I had created and published an AI Sentiment meter in India. This was a simple assignment of weights to the headlines on AI carried in ET, Mint, HT and TOI. I chose these as the leading reflectors of business, policy and investment climate. You could choose another set if you prefer.

All headlines that mentioned job loss were assigned a weight of -5 ; all those that had job gains +5 ; all those that had efficiency and social gains were +3 , while all those that carried news on government control and support for AI use, were +3. The period I chose for analysis was March to May 2026.

The result is this - the net score is -35, with 11 negative headlines and 6 positives. there were some spikes with news of big-ticket AI data centres investment, but for the majority of people whom these papers reach, this is news that won't directly impact them, and if it does, not in the mass scale that India needs.  

There seems to be a clear anxiety in India on the job loss, actual and potential, due to AI and its adoption. As a nation, we are still at a stage where job and job losses can cause considerable social and economic friction, which would negate to some extent industrial efficiency gains. After all, if your consumers can't buy, how much will your efficiency help?

AI Sentiment Meter March- May 2026. Based on headlines on AI in ET, Mint, TOI and HT. 

That said, there is excitement on AI - and new jobs and roles will be created- but how fast and how many? Clearly, a tech that is predicament on efficiency cant crearte a billion jobs. 

If I were the government, I would be walking a tightrope. I want industry and India to grow fast, but I cannot risk social, economic and eventually political losses! 






Friday, 20 February 2026

AI Growth in India: Opportunity for Many, Uncertainty for Many

 The AI Summit in Delhi has been all over the news these past few days, and rightly so. It was India’s moment to show our skills, our scale, and our speed. Yes, there were some hiccups with infrastructure and crowd movement. Some of that was expected.

I have always felt this: remove physical infrastructure problems, and Indians do extremely well. Wherever roads, traffic, and basic systems get in the way, we struggle. But give us pure brain work, where clean air and smooth highways are not required, and we do wonders.

That said, I looked at headlines from Feb 5 to Feb 20. I gave a score of +5 to headlines about productivity gains, new jobs, and progress. I gave -5 to headlines about job losses, cyber attacks, and data leaks. Headlines that simply reported investments or applications got a 0. Then I used AI to create a heat map based on this scoring.

The result: over those 20 days, the net sentiment score on AI was +24. That is quite high, though not surprising. The AI Summit in Delhi dominated the news. There is a clear sense of excitement. A feeling of power. Even a bit of ego and aggression. All of that can be good energy.



Source : headlines in ET, BS, Mint, 28 headlines over 20 days. Score given is subjective. In general, headlines that speak of job losses ( most important worry worldwide) gets maximum negative score -5. Job creation due to AI gets max positive score +5. And so on. Output from Claude AI. 

But when I remove the AI Summit headlines, the score drops close to neutral. Under the surface, there is worry. India is concerned about job losses.

The numbers make it worse. TCS is down 12,000 people. Campus hiring is at an all-time low. Global names like Anthropic are saying most white-collar jobs could be handled by AI within 18 months. These are not comforting headlines. They are scary.

I have tracked more headlines over the months and will keep refining this model. I would be surprised if the strong +24 net score of February 2026 is repeated. 

Tuesday, 27 January 2026

From Code to Characters: How AI Is Reshaping the Gaming Industry

Over the past few days, I’ve been looking closely at how AI is being used in gaming. Some applications are expected and fairly intuitive. AI-assisted scripting, character creation, storylines, and dialogue all make sense. They speed up production and help studios scale narrative content without sacrificing depth.

But digging deeper into the literature reveals more ambitious, and frankly more interesting, uses of AI. Non-player characters that learn from the player’s behavior and adapt over time are no longer theoretical. These NPCs can adjust their tactics, personality, or responses based on how you play. In some games, the AI tracks your pace, skill level, and decision patterns, then reshapes the narrative accordingly.

That alone would be impressive. What pushes things further is AI-driven adaptation at the engine level. Game code can now modify environments, visuals, and even entire worlds on the fly. That starts to feel less like traditional game design and more like something out of science fiction. The holodeck in Star Trek once represented the ultimate AI-powered experience, immersive, reactive, and seemingly limitless. That idea no longer feels fictional. We are moving steadily in that direction.



On the hardware side, AI is already deeply embedded. NVIDIA’s DLSS technology is a good example. By using AI to upscale and smooth visuals, it delivers higher frame rates and better visual fidelity without brute-force rendering. I’ve been playing Microsoft Flight Simulator since 1995, and the latest versions make extensive use of DLSS. The result is striking: richer visuals, more accurate terrain, better handling of AI aircraft, and fewer visual artifacts than ever before.

AI is also reshaping how games are built behind the scenes. With generative AI tools, it’s now possible to analyze millions of lines of code, identify bugs, and even rewrite or optimize large sections automatically. That’s a clear win in terms of faster development cycles and improved quality. At the same time, it raises uncomfortable questions about the future of traditional coding and debugging roles, many of which could shrink or disappear.

AI is no longer an experimental add-on in gaming. It’s becoming foundational. A quick scan of both digital and traditional media shows how widespread its adoption already is. Some companies are open about their use of AI; others are more discreet. Either way, its influence is undeniable, from early ideation and design through to execution, optimization, and post-launch evolution.

Gaming isn’t just using AI. It’s being reshaped by it.




Sunday, 25 January 2026

LLMs vs SLMs: What’s the Difference Between Large and Small Language Models?

Most people are familiar with LLMs, or large language models. There’s another category that matters just as much in practice: SLMs, or small language models. The two are built for very different jobs.

LLMs typically have tens of billions of parameters or more. They are trained on massive, mostly open or public datasets and are designed to be generalists. You can talk to them, ask wide-ranging questions, and get fluent, generative responses.

That power comes at a cost. LLMs require enormous investment in training and operation. They depend on large-scale cloud infrastructure, significant GPU capacity, high energy consumption, cooling, and strong cybersecurity controls. Because they are cloud- or internet-based, they also introduce additional complexity around data governance and compliance.

LLMs are probabilistic systems, which means they can hallucinate. This is a known limitation. The best-known models today—such as OpenAI’s GPT models, Google’s Gemini, and Anthropic’s Claude—fall into this category.

SLMs are much smaller in scale, with far fewer parameters. They are usually trained on closed, proprietary, or in-house datasets and are designed to be specialists, not general conversationalists.

 


In many cases, SLMs are not fully generative. They behave more like intelligent lookup, classification, or decision-support systems focused on specific tasks. Because of their size and scope, they require far less compute, power, and infrastructure, which makes them cheaper to build and operate.

SLMs are often deployed on-premise, making them attractive for enterprise use cases involving sensitive or regulated data. Their narrower scope generally reduces hallucination risk, though it does not eliminate it entirely.

Both LLMs and SLMs may use internet-connected sources depending on how they are deployed. And at this stage of AI development, human-in-the-loop oversight is still essential for both.

In short, LLMs excel at breadth and generative interaction. SLMs excel at focus, control, and enterprise-specific reliability. They solve different problems—and many real-world systems will use both. Users need to know which is the best match. 

 

 

Saturday, 24 January 2026

What Is RAG (Retrieval-Augmented Generation) and Why It Powers Modern AI

RAG, or Retrieval-Augmented Generation, is the backbone of modern AI tools.

Simply put, RAG allows an AI system to enhance a user’s prompt with relevant information pulled from external sources, then generate a response that is informed, accurate, and grounded. The system looks up data, filters it, and feeds it to the language model, which then composes the final answer. It can feel like magic, but it’s anything but simple.

If a large language model is the brain, RAG is the library it consults. The model provides intelligence and reasoning, while RAG supplies knowledge. In that sense, RAG isn’t just a feature layered on top of AI. It’s core infrastructure that makes modern AI practical and reliable.

RAG solves several critical problems. It reduces hallucinations by anchoring responses in real data. It mitigates stale knowledge, since models are trained with a cutoff date. It lowers the cost and complexity of retraining large models by allowing fresh information to be retrieved on demand. And it enables source attribution, at least to a meaningful degree.

Put plainly, much of today’s “magical” AI wouldn’t exist without RAG. It’s not an add-on. It’s the foundation. A true rags-to-riches story for AI systems.

 

 

Sunday, 18 January 2026

AI Firewalls: The Next Generation of Cybersecurity

You’ve probably heard of firewalls. They protect networks and applications from intrusions, attacks, and hacks. For years, multi-billion-dollar companies have built cybersecurity defenses around them. And they worked well — for the threats of their time.

But the cyber landscape has changed. New technologies have created entirely new attack surfaces, and those require new kinds of defenses. One of those is the AI firewall, and it’s already being used today.

AI firewalls serve a similar purpose to traditional firewalls: they prevent unauthorized or harmful access to systems. The difference lies in how they work. Conventional firewalls rely on predefined rules and signatures to detect malware, spyware, and known attack patterns. AI firewalls, on the other hand, monitor the inputs going into AI models themselves.

Their job is to inspect prompts and interactions to ensure that direct or indirect prompt injection does not make its way into the system and cause data leaks, misuse, or financial loss.

 

Instead of inspecting network traffic, AI firewalls analyze prompts, responses, and contextual inputs flowing into and out of AI models. They are designed to detect and block direct and indirect prompt injection, data exfiltration attempts, jailbreak techniques, and abuse patterns that can cause an AI system to behave in unintended or unsafe ways.

These systems are typically aligned with the OWASP Top 10 risks for AI, including model poisoning, training data leakage, sensitive information disclosure, toxic or policy-violating content generation, and unauthorized model behavior. By enforcing guardrails at runtime, AI firewalls reduce the risk of financial loss, regulatory violations, and trust failures in AI-powered applications.

In short, as AI becomes part of production infrastructure, security must move beyond network-level controls. AI firewalls provide a layer of defense specifically designed for the unique risks introduced by modern AI systems.

From Rule-Based Systems to Transformers: The Rise of Modern AI

AI has been around for decades, evolving through different stages of growth and maturity. The timeline info graphic shows this progression, from early rule-based systems to today’s generative AI. While development has been steady over time, the pace of change has accelerated dramatically over the past 7 to 8 years.


In many ways, the modern AI industry is only about five years old. That shift was driven by the Transformer model, which enabled AI systems to scale and move beyond research into real-world, industrial use.

We’ve seen this kind of rapid growth before.

Ecommerce in India began to take shape around 2013–14 with the entry of Amazon, Flipkart, and a handful of others. What followed was fast and transformative. In less than five years, these platforms scaled into retail giants and changed how businesses marketed, sold, and understood their customers.

They introduced data-driven marketing at scale. Performance advertising became mainstream. Content adapted to shrinking attention spans. For the first time, brands had access to deep, real-time insights into customer behavior across the funnel.

AI is now at a similar inflection point.

Chatbots and generative AI are beginning to reshape search, discovery, and performance marketing in much the same way ecommerce reshaped retail. Search is becoming conversational. Content creation is accelerating. Personalization is moving from segments to individuals. And feedback loops are getting shorter and smarter.

Ecommerce took roughly five years to mature in terms of scale, adoption, and social impact. AI may not take that long. The pace of development, deployment, and adoption suggests this cycle could be significantly shorter.

If ecommerce taught us anything, it’s this: when technology unlocks scale, data, and usability at the same time, entire industries change faster than expected.

Wednesday, 14 January 2026

What Happens When Anyone Can Become an AI Studio?


Earlier this week, there was a strange news segment in the US. Reports claimed that monkeys were running loose in St Louis. On its own, this would have been nothing more than a quirky human-interest story. The situation became more serious when videos circulating online could not be verified as either real footage or AI-generated. That led to false sightings, wasted time and resources for authorities, and general confusion about whether the monkeys even existed

Now imagine if this had been something more sensitive. Something designed to provoke anger or fear when nothing had actually happened. Given how agitated public discourse already is, that risk is very real.

This episode highlights how easily AI technology can be manipulated. What looks like harmless fun to some can quickly become a crisis for others. And as always, malicious actors are the first to exploit weak points.

I have long believed that when AI companies made their models free, or close to it, they didn’t just open a new market. They reduced the cost of entry to almost zero. The cost of exit is just as low. You simply stop prompting. Anyone with a PC and roughly Rs 30,000 a year can now run what is effectively an AI studio. Suppliers exploded overnight, all with minimal overheads. Thousands of them, each willing to charge slightly less than the next.


This collapse of the supplier moat has had consequences across society and industry.

AI slop is now everywhere. Content competes for a three-second attention span. Low attention spans combined with effortless mass generation means billions of low-quality outputs flooding the internet every minute. Genuine, useful content gets buried. It becomes a vicious cycle. Public sentiment can be inflamed in seconds because we haven’t yet learned how to live with this technology or understand its guardrails.

On the industry side, democratization and freemium AI tools created an army of ultra-low-cost suppliers. Ironically, the biggest winners were the buyers, not the suppliers. As humans tend to do, they pushed prices down by playing suppliers against each other. With low barriers to entry and endless competition, vendors entered a race to the bottom. Prices collapsed. Quality followed. But for content designed to grab attention for a few seconds, many brands were willing to accept that tradeoff as long as it wasn’t obviously bad. This low cost deluge also swamped the advertising and digital agencies. Suddenly they were out priced by a legion of younger companies that had little or no overheads or time constraints. Some shut shop, some hired the upstarts or started their own AI divisions. Its a state of flux all over the AI world! 


What Is a Prompt Injection Attack? Understanding a New AI Security Risk

An increasing concern in cybersecurity and AI is prompt injection. These attacks are designed to trick large language models (LLMs) into revealing sensitive system details, bypassing safeguards, leaking data, or performing actions they should not. In short, prompt injection is a cyberattack against LLM-based systems.

A prompt injection attack occurs when an attacker inserts malicious instructions into an otherwise harmless prompt, causing the LLM to behave in unintended ways. As IBM describes it:

“Hackers disguise malicious inputs as legitimate prompts, manipulating generative AI systems (GenAI) into leaking sensitive data, spreading misinformation, or worse.”

At the core of the problem is how LLMs process instructions. System prompts, developer instructions, and user inputs are all ultimately represented as natural language. From the model’s perspective, they are not fundamentally different. This makes it difficult for the model to reliably distinguish between legitimate instructions and malicious ones that are phrased to look legitimate.

If an attacker can craft a prompt that resembles a trusted system instruction the model has encountered before, the model may follow it, even when it should not.


 

Direct vs. indirect prompt injection

Prompt injection attacks generally fall into two categories: direct and indirect.

Direct prompt injection is the simplest form. IBM gives an example where a user asks the model to translate a sentence from English to French. After receiving the translation, the user follows up with an instruction such as “ignore the previous task and do something else entirely.” There is no hidden mechanism here. The attacker simply overrides the original intent by issuing a new instruction in plain language.

Indirect prompt injection is more subtle and often more dangerous. In these cases, malicious prompts are embedded in external content such as web pages, documents, or forum posts. When an LLM-powered system retrieves and summarizes that content, it may unknowingly process the embedded instructions. IBM notes cases where attackers plant prompts that cause the model to direct users to phishing sites or include malicious links in generated summaries.

Why this matters

Prompt injection is a rapidly evolving threat. As LLMs become more deeply integrated into search engines, customer support systems, developer tools, and enterprise workflows, the potential impact increases.

The key takeaway is simple: LLMs should not be trusted blindly. Human oversight remains essential, especially in high-risk or sensitive contexts. Just as with any other security-critical system, keeping a human in the loop is one of the most effective safeguards we have.


Monday, 5 January 2026

Least Privilege in the Age of AI Agents

The principle of least privilege matters in both cybersecurity and AI. Here’s why.

At its core, the principle is simple. You should have only the minimum access required to do your job. Nothing more. In cybersecurity, this is common sense. If you don’t need to see or use something, you shouldn’t be able to. Access can be logged, actions traced, and anomalies flagged. That limits the attack surface and reduces blast radius when something goes wrong.

The same principle becomes critical as more organisations adopt agentic AI.

By design, agents are autonomous, goal-seeking systems. They plan, reason, adapt, and act through repeated interactions. To be effective, they often need fast, repeated access across multiple systems, accounts, tools, and permission levels. That’s fine when everything is well designed, controlled, and secured.

The risk appears when it isn’t.

If a bad actor compromises an agent, they don’t just gain access to a single system. They inherit the agent’s combined privileges across time, systems, and surfaces. In one move, they may gain far broader access than would be possible in a traditional, non-agent setup. Least privilege is no longer violated once. It’s violated continuously and at scale.
In AI environments, this is especially dangerous. Agents act quickly, autonomously, and often without human review at every step. A compromised or misaligned agent doesn’t need much time to disrupt a process or produce a harmful outcome. It’s not a question of if this happens, but when.



Least privilege isn’t just a security best practice for AI systems. It’s a prerequisite for using them safely at all.

There are many ways to assure POLP- logging, hardening systems, audits and others. How to do all these in the age of agentic AI is the question. 

Friday, 2 January 2026

Bhashini App Explained: India’s AI Platform for Indian Language Translation

I’ve been using the Government of India’s Bhashini ("Bhasha Interface for India") app for a few days now, and it’s an impressive initiative ongoing for some time now.  It brings together recent advances in AI with deep local knowledge to support India’s linguistic diversity on a single platform.

At its core, Bhashini is an app and website that offers AI-based translation across about 30 Indian languages. It supports text-to-text translation, text-to-speech and speech-to-text, real-time conversational translation (speech to speech), and on the app, photo-to-text translation as well. The system is built on NLP and large language models trained specifically for Indian languages.

Screenshot of the Bhashini app, with the real time converse translation option. 


A feature I found particularly interesting is that when you choose a language pair, the app shows the underlying AI models available for that pair. For example, for English–Hindi translation across modes, it lists multiple models such as Bhashini Sarvam Translate 1, Bhashini IIIT Hyderabad, Bhashini AI4Bharat V3, among others.



Another standout aspect is “Bhasha Daan,” which allows users to contribute text and speech data to help improve the models. It’s a thoughtful way of combining the everyday knowledge of common speakers with the expertise of linguists and researchers.

What’s especially encouraging is the clear push toward India-specific, India-centric AI solutions. In today’s geopolitical climate, building self-reliance and retaining control over our data is not just desirable but necessary.

The app is available on both the Play Store and iOS, and the web version is accessible via Anuvaad.

Tuesday, 30 December 2025

Why India’s AI Mission Is a Critical Step for the Country’s Future

I’ve been reading up on the Government of India’s AI Mission over the past few days. It’s genuinely interesting and, honestly, quite heartening. You can see the level of focus, effort, and thought going into it, along with serious intent to invest. Every rupee put into AI today is likely to pay back many times over. Just as India took an early lead in IT decades ago, we now need to build a similar moat in AI.

The AI Mission is especially important given how complex the global geopolitical situation is becoming for India. We need to be self-sufficient, with our own distinct AI capabilities and offerings. Our markets are massive, which is why foreign players are doing everything they can to enter them. There’s no reason Indian, homegrown companies shouldn’t get strong support too, just as other countries actively protect and nurture their own ecosystems.

In October 2025, the Government of India, through the Press Information Bureau, published an article titled “Transforming India with AI” (https://www.pib.gov.in/PressReleasePage.aspx?PRID=2178092&reg=3&lang=2). It’s a good read. Earlier in this series, I had written about the seven sutras of India’s AI strategy. Taken together, it’s encouraging to see that India does seem to be moving in the right direction.


Source: https://www.pib.gov.in/PressReleasePage.aspx?PRID=2178092&reg=3&lang=2


Monday, 29 December 2025

Using AI to Strengthen Election Integrity and Voter Verification

AI can play a meaningful role in election data processing, voter impersonation prevention, and in protecting the integrity of the entire election chain. If we focus just on voter impersonation, today’s AI systems are already accurate enough to reliably detect and match faces against large databases.

At the polling booth, a voter’s photograph can be captured and processed by an AI system that converts facial features into a numerical “vector.” This vector is then compared with the vector created from an existing photo in a trusted database, such as the UIDAI record. If the difference between the two vectors crosses a defined threshold, the voter is rejected. If it falls within acceptable limits, the voter is allowed to proceed.

In India, a version of this process already exists. The returning officer manually compares the person standing at the booth with the photograph on the Aadhaar card. However, this step has always carried the risk of human error or deliberate compromise. An AI-based system removes that vulnerability. There is no scope for human bypass, except in clearly defined and auditable exceptions.

This is just one example of how AI can help. In a system as large, complex, and data-rich as a national election, there are many other areas where AI can add value. We will look at some of those possibilities in the future.

AI Slop, Algorithms, and the Erosion of Online Trust

I read an interesting piece in The Guardian yesterday. It claimed that nearly 20% of all content shown to YouTube viewers is now AI slop.

By AI slop, they mean content generated at scale using AI tools, not to inform or entertain, but to farm views by gaming algorithms that reward frequent uploads.

These accounts are exploiting one of the core business pillars of social media, especially YouTube: viewer stickiness. Platform revenue depends on how often people upload, how much users engage, and how many views they rack up. Entry barriers are almost nonexistent. For $20–50 a month, anyone can access industrial-grade AI software on ordinary hardware. Anyone can open a Google, OpenAI, or Nano Banana account and start uploading.

It gets worse. In the race to shock and grab attention every single time, AI-generated content is pushing into territory that, in any other era, would have been considered offensive at best and illegal at worst. The irony is that most of it remains perfectly legal until it triggers actual civil or criminal unrest.

The biggest danger of AI slop isn’t volume. It’s believability. The software is getting uncomfortably close to real. Telling AI from reality is no longer easy. There are already enough reports from credible news outlets showing how hyper-real AI content can shape narratives and sway perception. We need to pause and ask whether what we’re seeing is real before reacting to it. And definitely before forwarding it. Just because you can share something doesn’t mean you should.

source: media reports

So how do we stay alert to AI slop? It isn’t easy, especially when most of us won’t spend more than three to five seconds actually thinking about what we’re watching. Still, there are signs. Skin that’s too smooth. Lip sync that’s almost perfect. Motion that feels oddly slow or floaty. Backgrounds that are too clean, too tidy, too dust-free. In real life, especially in India, nothing looks that pristine. Stories that feel overly sentimental or oddly polished.

Legal guardrails and disclaimers are one option- and they will come in. Typically the law takes a bit of a time to catch up to technology. In the end, trust the human eye. The brain is good at spotting patterns and sensing when something feels off. We just have to give it a moment to work.

Rogue AI in the real world: Hollywood Saw This Coming. We Just Didn't Believe It.

If there was ever a moment for an "I told you so," this is it. For more than four decades, Hollywood has repeatedly warned us abo...