{"id":114211,"date":"2026-07-22T01:59:11","date_gmt":"2026-07-22T01:59:11","guid":{"rendered":"https:\/\/www.europesays.com\/ai\/114211\/"},"modified":"2026-07-22T01:59:11","modified_gmt":"2026-07-22T01:59:11","slug":"openai-says-its-a-i-models-went-rogue-and-attacked-a-digital-library","status":"publish","type":"post","link":"https:\/\/www.europesays.com\/ai\/114211\/","title":{"rendered":"OpenAI Says Its A.I. Models Went Rogue and Attacked a Digital Library"},"content":{"rendered":"<p class=\"css-aa8b97-Paragraph-baseStyles-paragraphTreatmentStyles-print evys1bk0\">OpenAI said on Tuesday that two of its artificial intelligence models went rogue and successfully hacked into Hugging Face, a digital library of A.I. technology that is popular among developers.<\/p>\n<p class=\"css-aa8b97-Paragraph-baseStyles-paragraphTreatmentStyles-print evys1bk0\">The incident, which happened last week while OpenAI was testing the cybersecurity capabilities of its systems, displayed the kind of science-fiction potential that A.I. companies warned would soon become a reality.<\/p>\n<p class=\"css-aa8b97-Paragraph-baseStyles-paragraphTreatmentStyles-print evys1bk0\">A.I. labs like OpenAI and Anthropic have over the past year released A.I. models that are customized to expose cybersecurity problems, while warning that their technology could pose new risks by finding holes in corporate computer networks faster than defenders could fix them.<\/p>\n<p class=\"css-aa8b97-Paragraph-baseStyles-paragraphTreatmentStyles-print evys1bk0\">OpenAI\u2019s revelations on Tuesday are an indication that those security incidents are already starting to happen, and even savvy A.I. companies may not be entirely ready for them. New A.I. systems can take multiple steps, figure ways around obstacles and find new ways to attack a network, said Alex Levinson, a cybersecurity consultant focused on autonomous capabilities.<\/p>\n<p class=\"css-aa8b97-Paragraph-baseStyles-paragraphTreatmentStyles-print evys1bk0\">\u201cThat\u2019s a genuine threshold, and it\u2019s going to become a normal part of the security landscape,\u201d he said.<\/p>\n<p class=\"css-aa8b97-Paragraph-baseStyles-paragraphTreatmentStyles-print evys1bk0\">The intrusion into Hugging Face began when OpenAI tested a combination of two of its models, GPT\u20115.6 Sol and a more powerful, unreleased model, to see how well the models could chain together online vulnerabilities into a successful cyberattack, <a class=\"css-bhdv0x-linkClass\" href=\"https:\/\/openai.com\/index\/hugging-face-model-evaluation-security-incident\/\" title=\"\" rel=\"noopener noreferrer nofollow\" target=\"_blank\">OpenAI said in a blog post<\/a> about the incident.<\/p>\n<p class=\"css-aa8b97-Paragraph-baseStyles-paragraphTreatmentStyles-print evys1bk0\">The trial was designed to keep the models in a safe testing environment, known as a sandbox, OpenAI said. But the models found a vulnerability that allowed them to escape the sandbox and connect to the internet. Then they targeted Hugging Face because they inferred that the library, which contains millions of A.I. models, could hold clues about how to successfully pass the evaluation.<\/p>\n<p class=\"css-aa8b97-Paragraph-baseStyles-paragraphTreatmentStyles-print evys1bk0\">\u201cIt seems to me that OpenAI did not adequately create a sandbox as a test environment,\u201d said Dierdre Mulligan, a professor in the School of Information at the University of California Berkeley who focuses on security and A.I. systems. She questioned whether passing a test was worth the potential damage of an A.I. model escaping into the wider internet.<\/p>\n<p class=\"css-aa8b97-Paragraph-baseStyles-paragraphTreatmentStyles-print evys1bk0\">\u201cWhat do we gain, and if this is the only way these tests can be configured, what are the risks?\u201d she said.<\/p>\n<p class=\"css-aa8b97-Paragraph-baseStyles-paragraphTreatmentStyles-print evys1bk0\">OpenAI said it was working with Hugging Face to fix the issues that led to the attack.<\/p>\n<p class=\"css-aa8b97-Paragraph-baseStyles-paragraphTreatmentStyles-print evys1bk0\">\u201cWe consider this to be an unprecedented cyber incident, involving state-of-the-art cyber capabilities, and are responding accordingly,\u201d OpenAI said in its blog post. \u201cWe are implementing strict controls in infrastructure configuration at the cost of research velocity while the vulnerabilities are patched.\u201d<\/p>\n<p class=\"css-aa8b97-Paragraph-baseStyles-paragraphTreatmentStyles-print evys1bk0\"><a class=\"css-bhdv0x-linkClass\" href=\"https:\/\/huggingface.co\/blog\/security-incident-july-2026\" title=\"\" rel=\"noopener noreferrer nofollow\" target=\"_blank\">Hugging Face<\/a> said last week that it had detected the intrusion and knew it had been caused by an autonomous system, but did not say at the time that OpenAI was responsible.<\/p>\n<p class=\"css-aa8b97-Paragraph-baseStyles-paragraphTreatmentStyles-print evys1bk0\">Clem Delangue, the chief executive of Hugging Face, <a class=\"css-bhdv0x-linkClass\" href=\"https:\/\/x.com\/ClementDelangue\/status\/2079670308156645882\" title=\"\" rel=\"noopener noreferrer nofollow\" target=\"_blank\">said on Tuesday<\/a> that his company had worked closely with OpenAI over the previous 24 hours to address the attack.<\/p>\n<p class=\"css-aa8b97-Paragraph-baseStyles-paragraphTreatmentStyles-print evys1bk0\">Mr. Delangue said in a statement that he was \u201cgrateful for the collaboration\u201d with OpenAI in the wake of the hack. \u201cThis incident, possibly the first of its kind, proves a point we\u2019ve long believed: A.I. safety won\u2019t be solved by any single company working in secret,\u201d he added.<\/p>\n<p class=\"css-aa8b97-Paragraph-baseStyles-paragraphTreatmentStyles-print evys1bk0\">A.I. models have proved to be adept at programming, and that has made them useful to both hackers and people in charge of protecting computer networks.<\/p>\n<p class=\"css-aa8b97-Paragraph-baseStyles-paragraphTreatmentStyles-print evys1bk0\">In April, Anthropic released a cybersecurity-focused model called Mythos, and made it available to only a small group of organizations so that they could defend against cyberattacks. OpenAI soon introduced its own cybersecurity model and made it available <a class=\"css-bhdv0x-linkClass\" href=\"https:\/\/www.nytimes.com\/2026\/04\/14\/technology\/openai-cybersecurity-gpt54-cyber.html\" title=\"\" rel=\"nofollow noopener\" target=\"_blank\">to a limited group<\/a> of organizations to prepare their defenses, before rolling it out more broadly. And on Tuesday, Google said it had also developed a <a class=\"css-bhdv0x-linkClass\" href=\"https:\/\/www.nytimes.com\/2026\/07\/21\/technology\/google-ai-cybersecurity-gemini.html\" title=\"\" rel=\"nofollow noopener\" target=\"_blank\">model focused on cybersecurity<\/a> and released it to a small group of testing partners.<\/p>\n<p class=\"css-aa8b97-Paragraph-baseStyles-paragraphTreatmentStyles-print evys1bk0\">(The New York Times has <a class=\"css-bhdv0x-linkClass\" href=\"https:\/\/www.nytimes.com\/2023\/12\/27\/business\/media\/new-york-times-open-ai-microsoft-lawsuit.html\" title=\"\" rel=\"nofollow noopener\" target=\"_blank\">sued OpenAI and Microsoft<\/a>, claiming copyright infringement of news content related to A.I. systems. The two companies have denied those claims.)<\/p>\n<p class=\"css-aa8b97-Paragraph-baseStyles-paragraphTreatmentStyles-print evys1bk0\">Richard Barnes, an independent security researcher who has worked with Mythos, said the cybersecurity industry faced a similar challenge about a decade ago, when new tools called fuzzers made it much easier for attackers to break into online systems. Tech companies began using the tools to check their own systems for vulnerabilities, and were eventually able to prevent most of the attacks.<\/p>\n<p class=\"css-aa8b97-Paragraph-baseStyles-paragraphTreatmentStyles-print evys1bk0\">Companies must now take a similar approach to prepare for A.I. attacks, Mr. Barnes said, \u201cbefore the vulnerabilities can be found and exploited by bad guys who have access to these tools.\u201d<\/p>\n","protected":false},"excerpt":{"rendered":"OpenAI said on Tuesday that two of its artificial intelligence models went rogue and successfully hacked into Hugging&hellip;\n","protected":false},"author":2,"featured_media":114212,"comment_status":"","ping_status":"","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[2],"tags":[24,1556,25,1586,1555,11248,18044,1588],"class_list":["post-114211","post","type-post","status-publish","format-standard","has-post-thumbnail","category-ai","tag-ai","tag-anthropic-ai-llc","tag-artificial-intelligence","tag-computer-security","tag-computers-and-the-internet","tag-cyberattacks-and-hackers","tag-hugging-face","tag-openai-labs"],"_links":{"self":[{"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/posts\/114211","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/comments?post=114211"}],"version-history":[{"count":0,"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/posts\/114211\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/media\/114212"}],"wp:attachment":[{"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/media?parent=114211"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/categories?post=114211"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/tags?post=114211"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}