{"id":114439,"date":"2026-07-22T06:18:15","date_gmt":"2026-07-22T06:18:15","guid":{"rendered":"https:\/\/www.europesays.com\/ai\/114439\/"},"modified":"2026-07-22T06:18:15","modified_gmt":"2026-07-22T06:18:15","slug":"openai-reports-unprecedented-autonomous-hack-by-ai-agents","status":"publish","type":"post","link":"https:\/\/www.europesays.com\/ai\/114439\/","title":{"rendered":"OpenAI reports &#8216;unprecedented&#8217; autonomous hack by AI agents"},"content":{"rendered":"<p class=\"mb-4 text-lg md:leading-8 break-words\">ChatGPT maker OpenAI said Tuesday that its advanced artificial intelligence models had gone rogue during security testing, hacking into a popular platform for programmers on their own.<\/p>\n<p class=\"mb-4 text-lg md:leading-8 break-words\">The San Francisco firm called it an &#8220;unprecedented cyber incident&#8221; and said it would conduct a joint investigation with the online code library Hugging Face.<\/p>\n<p class=\"mb-4 text-lg md:leading-8 break-words\">AI models that underpin tools like chatbots and image generators are known as agents when they act autonomously to carry out tasks in the real world.<\/p>\n<p class=\"mb-4 text-lg md:leading-8 break-words\">As the technology quickly becomes more sophisticated, cybersecurity is in the spotlight given the risk of advanced AI finding weak points in existing software before humans do.<\/p>\n<p class=\"mb-4 text-lg md:leading-8 break-words\">OpenAI said the incident involved a combination of models, including its recently launched GPT-5.6 Sol &#8220;and an even more capable pre-release model&#8221;.<\/p>\n<p class=\"mb-4 text-lg md:leading-8 break-words\">The company was trying to assess the models&#8217; hacking capabilities by setting tasks in a tightly controlled digital testing ground, where internet access was limited for safety.<\/p>\n<p class=\"mb-4 text-lg md:leading-8 break-words\">&#8220;While operating in our sandboxed testing environment, our models spent a substantial amount of (computing power) finding a way to obtain open Internet access, in pursuit of solving the evaluation problem,&#8221; an OpenAI blog about the incident said.<\/p>\n<p class=\"mb-4 text-lg md:leading-8 break-words\">After connecting to the internet, the models decided to target the platform Hugging Face &#8212; a large repository of AI models, datasets and other information &#8212; to help in their quest.<\/p>\n<p class=\"mb-4 text-lg md:leading-8 break-words\">Searching for &#8220;secret information&#8221; that could help it cheat the evaluation, the OpenAI system &#8220;chained together multiple attack vectors, including using stolen credentials&#8221;.<\/p>\n<p class=\"mb-4 text-lg md:leading-8 break-words\">&#8211; &#8216;Catastrophic&#8217; potential &#8211;<\/p>\n<p class=\"mb-4 text-lg md:leading-8 break-words\">Hussein Abbass, a computing professor at UNSW Canberra, told AFP that the incident was &#8220;amazing on many fronts&#8221;.<\/p>\n<p class=\"mb-4 text-lg md:leading-8 break-words\">&#8220;It did not just attack Hugging Face. It actually attacked its internal system to exploit its own vulnerabilities,&#8221; Abbass said.<\/p>\n<p class=\"mb-4 text-lg md:leading-8 break-words\">&#8220;And that&#8217;s scary.&#8221;<\/p>\n<p class=\"mb-4 text-lg md:leading-8 break-words\">GPT-5.6 and other cutting-edge models, including the Mythos series from OpenAI&#8217;s archrival Anthropic, have drawn concern over their potential to breach cybersecurity defences.<\/p>\n<p class=\"mb-4 text-lg md:leading-8 break-words\">Both the US firms had to temporarily withhold the general release of these latest technologies because of fears in Washington that they could help break into crucial infrastructure.<\/p>\n<p class=\"mb-4 text-lg md:leading-8 break-words\">Advanced AI is &#8220;normally in the hands of people who are ethical and responsible&#8221;, Abbass said.<\/p>\n<p class=\"mb-4 text-lg md:leading-8 break-words\">But &#8220;it&#8217;s going to be catastrophic if it gets in someone&#8217;s hands with the intention to cause harm&#8221;.<\/p>\n<p class=\"mb-4 text-lg md:leading-8 break-words\">How to govern the AI sector has become a key question, and &#8220;we need a community effort to manage this situation&#8221;, he added.<\/p>\n<p class=\"mb-4 text-lg md:leading-8 break-words\">Hugging Face had reported the cyber &#8220;intrusion&#8221; last week, without mentioning OpenAI.<\/p>\n<p class=\"mb-4 text-lg md:leading-8 break-words\">&#8220;This one was different from anything we had handled before in one important way: it was driven, end to end, by an autonomous AI agent system &#8212; and we detected and dissected it largely with AI of our own,&#8221; Hugging Face said.<\/p>\n<p class=\"mb-4 text-lg md:leading-8 break-words\">Clement Delangue, CEO of Hugging Face, said on X that the company had suspected the cyberattack had come from a world-leading AI lab, given the sophistication of the agent.<\/p>\n<p class=\"mb-4 text-lg md:leading-8 break-words\">&#8220;We strongly believe there was no malicious intent on their part,&#8221; Delangue wrote, referring to OpenAI.<\/p>\n<p class=\"mb-4 text-lg md:leading-8 break-words\">&#8220;It&#8217;s quite mind-blowing that all of this happened autonomously!&#8221;<\/p>\n<p class=\"mb-4 text-lg md:leading-8 break-words\">bur-kaf\/cms<\/p>\n","protected":false},"excerpt":{"rendered":"ChatGPT maker OpenAI said Tuesday that its advanced artificial intelligence models had gone rogue during security testing, hacking&hellip;\n","protected":false},"author":2,"featured_media":114440,"comment_status":"","ping_status":"","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[7],"tags":[1934,18044,58469,157],"class_list":["post-114439","post","type-post","status-publish","format-standard","has-post-thumbnail","category-openai","tag-artificial-intelligence-models","tag-hugging-face","tag-hussein-abbass","tag-openai"],"_links":{"self":[{"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/posts\/114439","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/comments?post=114439"}],"version-history":[{"count":0,"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/posts\/114439\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/media\/114440"}],"wp:attachment":[{"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/media?parent=114439"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/categories?post=114439"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/tags?post=114439"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}