Op-ed
|
21.07.2026

Norway remains outside the AI safety collaboration

First published in:
Dagens Næringsliv

AI-driven cyberattacks threaten the Norwegian economy and infrastructure. Yet, we have no seat at the table where our allies collaborate on AI security.

Download

AI-generated illustration from Gemini.

Main moments

! 1

! 2

! 3

! 4

Content

Imagine a morning where hospitals from Kristiansand to Kirkenes are knocked offline. Surgeries are canceled, ambulances are grounded, and every screen displays the same demand: "Pay the ransom to restore your systems." The attack was carried out using AI, which identifies security vulnerabilities faster than any human expert. The countries hit hardest are those that received no early warning and are attempting to defend themselves without the most advanced AI tools.

The scenario is fictional, but it could become a real possibility in the near future. In June of this year, the security firm Sysdig documented what they believe to be the first ransomware attack carried out by an autonomous AI agent. A human selected the victim and gained access, but from there, the machine performed reconnaissance, corrected its own errors along the way, encrypted over a thousand configuration entries, and formulated the ransom demand.

If we are to defend ourselves against increasingly advanced attacks like this, we need access to the most advanced AI technology. However, this is being developed by a handful of companies over which we have no influence, primarily American and Chinese. Anyone who thought the most powerful AI would always be a keystroke away received a wake-up call in April. That was when Anthropic launched its most capable model, Mythos, without making it openly available. Only select partners were granted access through the security initiative Project Glasswing.

The same pattern repeated itself days after the launch of its successor, Claude Fable, when Anthropic customers lost access to Fable and Mythos overnight due to cyber-related concerns in Washington. A little over a week later, the cybersecurity agencies in the Five Eyes alliance (the US, UK, Canada, Australia, and New Zealand) issued a joint warning: advanced AI is changing the threat landscape itself at a pace measured in months, not years.

In this new reality, we won't have time to set up working groups every time something happens; we need a mechanism that is already in place.

A state-run AI security agency is the most obvious solution. Over the past three years, key allies such as the UK, Canada, and France have established government AI security institutes that test models, coordinate security efforts, and advise their governments. These collaborate through the International Network for Advanced AI Measurement, Evaluation and Science (NAAIMES).

The UK's AI Safety Institute is recognized as the world's leading institution for AI security and was the only European institution that was allowed to test Mythos before the model saw the light of day in April. In Estonia and the Netherlands, there are now discussions on how to set up their own security agencies to gain entry into NAAIMES. But no one has reacted faster than Germany. Before the "Mythos moment" in April, a German AI security agency was a niche topic. Two months later, the German Security Council decided to establish an institute modeled after the British one, and two weeks ago Germany and the UK announced that they will collaborate closely on AI-related cyber threats.

It is now urgent for Norway to get involved. In the recent report from the UN's scientific AI panel, the world's most cited AI researcher Yoshua Bengio and Nobel laureate Maria Ressa warn world leaders against assuming that the timelines for AI development are long. The window for action is open, they say, but perhaps not for long. Norway should establish its own AI safety body at a pace unprecedented in Norwegian public administration.

The technical function can be built upon the strong AI research communities we already have, but research environments cannot represent the state in international networks. Therefore, it is imperative that the body is given a clear political mandate. The price tag should not be daunting: a policy function within the administration and testing at research institutions will cost a fraction of the AI billion. We won't see the bill for staying outside the AI collaboration until it arrives, but by then, it will be too late to negotiate.

Download
We use cookies to provide you with a better user experience. By clicking “Accept”, you consent to our use of cookies. Read more in our Privacy Policy.