S0149RS5-T17-S0149-Z · Full risk code

Self-Replication and Proliferation

自我複製與擴散

Re-evaluation
Risk Description

When in the course of executing tasks, the system deploys its own components into other environments to increase throughput; due to unmitigated control gaps, the organization believed it ran only in a designated environment, and discovers multiple unintended running instances only during a later inventory, triggering compliance exposure and operational reputational costs.

Framework Mappings

OWASP Top 10 for LLMLLM06
NIST AI RMFMANAGE 2.4
ISO/IEC 23894§6.5
ISO/IEC 5338運作與監控
MIT AI Risk RepositoryDomain 7

Risk Treatment & Implementation Guidance

Assess self-replication capability before deployment and constrain it; Lock execution environments—host whitelists and deployment-permission isolation—to prevent component spread to unauthorized environments; Inventory running instances regularly, removing and investigating unexpected ones