{"id":114947,"date":"2026-07-22T14:06:08","date_gmt":"2026-07-22T14:06:08","guid":{"rendered":"https:\/\/www.europesays.com\/ai\/114947\/"},"modified":"2026-07-22T14:06:08","modified_gmt":"2026-07-22T14:06:08","slug":"open-ai-says-its-ai-model-went-rogue-what-do-we-know-cybersecurity-news","status":"publish","type":"post","link":"https:\/\/www.europesays.com\/ai\/114947\/","title":{"rendered":"Open AI says its AI model \u201cwent rogue\u201d: What do we know? | Cybersecurity News"},"content":{"rendered":"<p>OpenAI has revealed that one of its artificial intelligence models independently stole login credentials and hacked into another technology company\u2019s system, in what is widely seen as one of the first known incidents of AI systems acting autonomously.<\/p>\n<p>\u201cWe had a significant security incident during evaluation of our models,\u201d CEO Sam Altman posted on X on Tuesday.<\/p>\n<p>Recommended Stories list of 4 itemsend of list<\/p>\n<p>The incident comes as calls mount from technology rights advocates for stricter guardrails on rapidly evolving AI systems.<\/p>\n<p>They have grown so powerful in a short span of time that alarming phenomena such as deepfakes and sophisticated cyberscams are becoming the norm.<\/p>\n<p>Earlier this year, a number of software engineers <a href=\"https:\/\/www.aljazeera.com\/news\/2026\/2\/15\/why-are-experts-sounding-the-alarm-on-ai-risks\" target=\"_blank\" rel=\"noopener nofollow\">quit their jobs <\/a>at top companies such as Anthropic and AI in protest against how the technologies are being built.<\/p>\n<p>\u201cAI is accelerating the discovery and exploitation of vulnerabilities,\u201d OpenAI said in a lengthy statement on Tuesday that detailed the latest incident.<\/p>\n<p>\u201cThe primary lesson from this incident is that model security and safety must keep pace with rapidly advancing capabilities.\u201d<\/p>\n<p>Here\u2019s what we know about the breach:<\/p>\n<p><img decoding=\"async\" data-recalc-dims=\"1\" loading=\"lazy\" class=\"size-arc-image-770 wp-image-4532566\" src=\"https:\/\/www.europesays.com\/ai\/wp-content\/uploads\/2026\/07\/AP26114767859341-1777484658.jpg\" alt=\"Sam Altman, cofounder and CEO of OpenAI, testifies before a Senate committee hearing in Washington, May 8, 2025\" fetchpriority=\"low\"\/>Sam Altman, cofounder and CEO of OpenAI, testifies before a Senate committee hearing in Washington, May 8, 2025 [Jose Luis Magana\/AP]What has happened?<\/p>\n<p>OpenAI said two of its models found their way out of an isolated, no-internet access environment \u2013 or a sandbox \u2013 and hacked into the systems of tech company Hugging Face on their own.<\/p>\n<p>The models involved are the latest GPT-5.6 Sol model and an unreleased model the company said is \u201ceven more capable,\u201d than its latest version.<\/p>\n<p>Hugging Face hosts openly sourced AI models and resources. The two OpenAI agents discovered vulnerabilities in Hugging Face\u2019s servers and proceeded to steal login details and then hack into the company\u2019s systems.<\/p>\n<p>The incident occurred during an OpenAI internal testing session designed to assess the models\u2019 cybersecurity capabilities. OpenAI had removed standard safety measures for the test.<\/p>\n<p>Both sought to cheat their way through a problem during the test, OpenAI said. They went to \u201cextreme lengths to achieve a rather narrow testing goal\u201d and \u201cfound ways to gain access to secret information that it could use to cheat the evaluation\u201d.<\/p>\n<p>OpenAI\u2019s security team detected the unusual activity internally, but details of the breach came to light following a joint investigation by both companies.<\/p>\n<p>What has Hugging Face said?<\/p>\n<p>Hugging Face disclosed last Thursday that its servers were hacked by an unknown but sophisticated agent acting on its own. The company discovered the breach through its own AI-assisted detection.<\/p>\n<p>\u201cThis one was different from anything we had handled before in one important way: it was driven, end to end, by an autonomous AI agent system,\u201d the company said.<\/p>\n<p>Following OpenAI\u2019s disclosure that its models were involved in the breach, both sides conducted an ongoing joint investigation this week.<\/p>\n<p>\u00a0<\/p>\n<p>\u201cWe suspected last week\u2019s cyberattack might have come from a frontier lab, given the sophistication of the agent. Turns out it did!\u201d CEO Clement Delangue posted on X on Tuesday.<\/p>\n<p>Hugging Face\u2019s staff \u201cstrongly believe there was no malicious intent on their part,\u201d Delangue added, referring to OpenAI.<\/p>\n<p>Why does this matter?<\/p>\n<p>Cybersecurity experts have previously sounded the alarm over the potential, extreme capabilities of AI systems and the dangers they pose.<\/p>\n<p>But until now, there have been few real-life cases proving those concerns like this one.<\/p>\n<p>Many warn that incidents like these could become commonplace and that AI systems pose a threat to financial, security and other sensitive data systems.<\/p>\n<p>OpenAI revealed in a separate incident earlier this week that the unreleased, more powerful model had escaped an isolated environment during another test.<\/p>\n<p>Anthropic, OpenAI\u2019s rival, had similar issues with its most powerful agent to date, the Claude Mythos Preview model.<\/p>\n<p>During a stress test of an early version, the model found its way out of a sandbox, gained internet access and emailed the supervising researcher that it had escaped and then wiped evidence of its activity. Anthropic halted a planned public release of the model afterwards.<\/p>\n<p>In April, the US Federal Reserve and the Treasury Department convened a meeting with bank CEOs where officials warned about the cybersecurity risks posed by Mythos. Canada\u2019s federal banking regulator has also warned financial institutions about the model\u2019s capabilities.<\/p>\n<p>The OpenAI breach also appears to make the case for companies like Hugging Face, which rely on open source systems, as opposed to more secretive AI development platforms like OpenAI.<\/p>\n<p>\u201cThis incident, possibly the first of its kind, proves a point we\u2019ve long believed: AI safety won\u2019t be solved by any single company working in secret,\u201d Hugging Face\u2019s Delangue was quoted as saying in OpenAI\u2019s statement.<\/p>\n<p>\u201cIt will be solved in the open, collaboratively, with broad access to AI for every defender, everywhere,\u201d he added.<\/p>\n","protected":false},"excerpt":{"rendered":"OpenAI has revealed that one of its artificial intelligence models independently stole login credentials and hacked into another&hellip;\n","protected":false},"author":2,"featured_media":114948,"comment_status":"","ping_status":"","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[2],"tags":[24,25,313,4861,1407,66,508,1715,2018],"class_list":["post-114947","post","type-post","status-publish","format-standard","has-post-thumbnail","category-ai","tag-ai","tag-artificial-intelligence","tag-cybersecurity","tag-explainer","tag-investigation","tag-news","tag-privacy","tag-regulation","tag-science-and-technology"],"_links":{"self":[{"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/posts\/114947","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/comments?post=114947"}],"version-history":[{"count":0,"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/posts\/114947\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/media\/114948"}],"wp:attachment":[{"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/media?parent=114947"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/categories?post=114947"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/tags?post=114947"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}