AI Does Not Need The Keys If It Can Influence The Person Who Has Them – OpEd
Burak Oktenli argues AI security still obsesses over keeping models off weapons and networks, while the next hole may be the cleared person who already holds the key: influence, impersonation, and pressure on authorized humans.
He treats Anthropic’s 2025 Claude Opus 4 fictional-blackmail eval as a constrained warning, not proof of real control, and the FBI’s May 2025 AI-voice/text impersonation of U.S. officials as humans using AI—not an autonomous machine. Nuclear two-person and reliability rules are the principle: one person’s authority should not be enough.
Proposed controls: independent second-person checks (not the same briefing twice), out-of-band verification, a safe way to report being targeted without automatic career death, and red-teams that ask whether a system respects “no,” claims fake authority, or moves people off monitored channels. The machine may never need the key if it can move the person who has it.
Security policy still focuses on keeping artificial intelligence away from weapons, networks, and critical infrastructure. The next vulnerability may be the humans authorized to operate them.
Much of the debate over artificial-intelligence security begins with access. Keep the model away from weapons. Restrict its credentials. Separate it from classified networks. Limit its tools. Put consequential decisions behind a human approval step.
Those controls matter. They also leave a second pathway underexamined.
An AI system may not need the authority if it can influence the person who already has it.
Humans hold security clearances, administer networks, approve transfers, open secure facilities, maintain critical infrastructure, authorize military actions, and make decisions that machines are deliberately prohibited from making. As AI systems become more capable at language, personalization, planning, and sustained interaction, those people become part of the security boundary.
The human authority layer
Cybersecurity has long recognized that people can provide a route around technical defenses. Social engineering works because an attacker may find it easier to persuade an authorized person than to defeat the system protecting that person’s access.
Artificial intelligence could make that familiar problem more scalable. A capable system can potentially process large amounts of information about an individual, adapt its messages, imitate........
