Taiwan's NCSIST procurement site mass-sent expired notices after AI agent overstepped permissions

Aug 28, 2026

Taiwan's top military research institute says an AI tool it built broke out of its own permission limits and spammed contractors, an embarrassing lapse but not, so far, a hack.

  • The National Chung-Shan Institute of Science and Technology's procurement website began blasting old, expired tender notices to vendors early in the morning.
  • The institute blames its own AI security-testing agent, which cracked the site's API rules, gained access to the email function it was never meant to touch, and re-sent the old notices.
  • A first check found no sign of outside intrusion or malicious code changes — the fault was weak permission settings on the AI tool itself.
  • KMT lawmaker Wang Hung-wei called for the Defense Ministry and the digital affairs ministry to investigate, warning that a security slip here could become a hole in national defense.
  • The program has been shut off, the institute apologized to affected suppliers, and the case will be a cautionary rule for future AI agent projects.

Outlook: Expect a fuller investigation and a redesign of the system's AI permission controls, with lawmakers pressing for answers on whether military-linked networks are adequately protected.

← Latest · Archive