news.mlab.sh
Back to the feed
threat-intel

Europe's Multilingual Reality Exposes AI Security Gaps

High
Summary

Europe faces a unique security challenge due to its multilingual landscape and the resulting inconsistencies in AI safety and security across numerous languages. While many AI models can process text in dozens of languages, performance and safety capabilities vary significantly, particularly when it comes to detecting malicious prompts and protecting against data loss. A growing number of organizations, especially those operating across multiple languages, are exposed to this risk, as attackers deliberately craft prompts in different languages to bypass filters designed primarily for English. European organizations must address this issue through rigorous testing, native language security controls, and specialized AI firewalls to mitigate the risks posed by multilingual threat actors.

Europe faces a unique security challenge due to its multilingual landscape and the resulting inconsistencies in AI safety and security across numerous languages. While many AI models can process text in dozens of languages, performance and safety capabilities vary significantly, particularly when it comes to detecting malicious prompts and protecting against data loss. A growing number of organizations, especially those operating across multiple languages, are exposed to this risk, as attackers deliberately craft prompts in different languages to bypass filters designed primarily for English. European organizations must address this issue through rigorous testing, native language security controls, and specialized AI firewalls to mitigate the risks posed by multilingual threat actors.

Leading AI models like OpenAI's GPT, Google's Gemini, and Anthropic's Claude demonstrate strong performance in around 30 to 40 languages, including English, Arabic, Spanish, French, German, Japanese, Simplified Chinese, and Hindi. However, less-supported languages, such as Welsh and Swahili, often provide only basic responses and may contain grammatical errors. The core problem is that the AI security layer and guardrails don't consistently protect against jailbreaking and unsafe actions equally across all supported languages.

DeepKeep, an AI security vendor, published a blog post highlighting this issue, noting that a multilingual enterprise is inherently more exposed to security gaps. The vendor’s benchmark testing revealed significant accuracy drops for translation-based personally identifiable information (PII) detection when analyzing German, Spanish, French, and Italian compared to native language analysis. This means that a security filter trained on English might fail to identify malicious prompts translated into these languages.

Attackers exploit this vulnerability by crafting prompts in different languages to bypass filters. Research from Brown University found that OpenAI's GPT-4 provided harmful and actionable responses to unsafe prompts 79% of the time when translated into low-resource languages, compared to less than 1% in English. This demonstrates that simply translating English prompts doesn't solve the problem – the underlying safety mechanisms aren't designed to handle diverse linguistic contexts.

Microsoft's AI Red Team has been testing its AI systems across multiple languages, mixing and combining languages to test systems and expose vulnerabilities. They emphasize that model safety and behavioral profile can change depending on the language it is prompted in, as well as which it responds in. A safe response for a user in a particular language may be unsafe in the same language if that user is in a different cultural context – for example an American in California speaking Korean versus a Korean in Seoul speaking Korean.

Addressing this challenge requires a multi-faceted approach. Organizations can use translation-first security filtering, but this method can introduce blind spots. A more effective strategy involves native language security controls, where the security layer evaluates prompts and meaning in the original language. Furthermore, AI firewalls and policy enforcement tools are increasingly being deployed to block suspicious tool calls, prevent sensitive data exfiltration, and log incidents for investigation.

Europe’s multilingual reality – with 24 official languages and numerous regional and minority languages – presents a unique operational challenge for AI governance. The EU AI Act recognizes this complexity, but doesn’t mandate identical safety performance across all supported languages. However, for high-risk systems, the Act requires continuous risk management and appropriate levels of accuracy, robustness, and cybersecurity throughout the system’s life cycle, including language-specific testing to demonstrate compliance.

Read the full article at Dark Reading