Main moments
If there is one area of society that is critically important, yet barely crosses most people's minds, it is cybersecurity. It is our ability to protect digital infrastructure—whether it is the IT system at work, the signaling system on the railway, or your personal finances—against attacks from malicious actors.
Recently, there have been a series of major cyberattacks targeting Norwegian entities. The most tragic example was when hackers gained access to over 1,300 medical records containing sensitive personal information from Lørenskog municipality, which they released on the dark web when the municipality refused to pay the ransom.
And even though companies and public institutions understandably prefer not to talk openly about hacking attacks, I hear whispers from people of all backgrounds that it happens far more often than is reported.
I suspect that the latest attacks are turbocharged by AI—new models that are far better at hacking than any before them, and which can act autonomously.
What we are already seeing the beginnings of, and what I believe will hit Norway like a tidal wave over the next 12 months, is large-scale cyberattacks against Norwegian businesses of all sizes.
I wrote previously in Altinget about the imbalance between defense and offense in cybersecurity. As an attacker, you only need one successful attack to cause significant damage, while a defender must catch absolutely every single attack.
Until now, conducting data attacks has been expensive and demanding because it required human labor—for example, 100 North Korean hackers with IT expertise and a lot of patience. With AI, you no longer need as many people.
The rise of open AI models will make it easier for everyone to hack.
"Hackers can download the model and freely let it run wild to find weaknesses in the defense."
An open AI model is an AI that is available for everyone to download and run on their own computer systems. A closed model like ChatGPT and Claude cannot be downloaded and must be used through the organization itself. This allows companies to impose restrictions (or at least attempt to) on what the model will assist with. You cannot do that with open models.
In other words, hackers can download the model and let it run wild to find weaknesses in defenses.
Earlier this summer, the Chinese company Moonshot AI released a new version of its Kimi model. This turned out to be far better than anyone expected a Chinese model could be, even though it still lags behind the leading American models. The main difference is that Kimi is open.
We will now see what happens when hackers gain access to a powerful model that can run free. Personally, I believe this will trigger far more attacks in every direction, and not least attacks against targets that previously weren't worth the effort for hackers.
A good guy with a gun
To paraphrase an American expression, the only way to stop a bad actor with AI is a good actor with AI. The hope is that data companies can be given access to the best models before they are released to the public, allowing them to fix the code and make it hack-proof.
In the same way, self-driven AI models can patrol code and protect against intruders, much like the body's immune system continuously protects against disease.
This may well turn out to be true, but it could also turn out that it is simply much easier to attack than to defend, meaning the good models won't be able to keep up with the bad ones.
Alternatively, one could imagine that US authorities might deny companies in other countries access to the most advanced models. This is what happened when US authorities temporarily restricted access to Anthropic's Fable model, which caused great concern in Europe.
The cost of attacks has fallen
I am concerned about what will happen to small and medium-sized enterprises (SMEs). SMEs account for over half of all private sector employees, and over a million workers are employed in companies with fewer than 50 employees. Most SMEs cannot afford or do not have enough staff for dedicated IT departments.
If it becomes cheap enough, an individual could attack a workshop, a local car dealership, or a dental clinic.
Until now, it hasn't been profitable for hackers to attack architecture firms, fish farms, and regional businesses. They have been able to hide in the crowd of other companies, much like a zebra.
It is not even unthinkable that we will eventually start seeing attacks on small businesses. If it becomes cheap enough, an individual could attack a workshop, a local car dealership, or a dental clinic.
We need to toughen up
Our problem is that we still think of this as a private matter where companies take responsibility for their own systems. But at some point, the problem will become so large and widespread that the state must step in.
At some point, the problem becomes so significant and widespread that the state must step in.
It is time for tech experts in the private and public sectors to sit down and think seriously about what it takes to harden our infrastructure.
The logistics will be a total nightmare, but we simply need more muscle in Norway and Europe. We can no longer rely on American tech companies to do their best to ensure that the private data of Norwegians is protected.
More from Langsikt

Open-source AI makes us more vulnerable
Open-source AI models create as many problems as they solve, and some of them could have catastrophic consequences. The solution is coordinated governance of the pace of AI development.

Norway remains outside the AI safety collaboration
AI-driven cyberattacks threaten the Norwegian economy and infrastructure. Yet, we have no seat at the table where our allies collaborate on AI security.

What if the AI tidal wave arrives?
World-leading economists are warning of an AI revolution and demanding action. Other countries are already well underway with their preparations, but in Norway, very little is happening.

The Hidden Architect Behind Norway's Prosperity
… and what he can teach us about artificial intelligence.
