{"id":115565,"date":"2026-07-22T22:17:18","date_gmt":"2026-07-22T22:17:18","guid":{"rendered":"https:\/\/www.europesays.com\/ai\/115565\/"},"modified":"2026-07-22T22:17:18","modified_gmt":"2026-07-22T22:17:18","slug":"openai-blamed-a-hacking-event-on-its-ai-models-going-rogue-here-are-some-things-to-know-2","status":"publish","type":"post","link":"https:\/\/www.europesays.com\/ai\/115565\/","title":{"rendered":"OpenAI blamed a hacking event on its AI models going rogue. Here are some things to know"},"content":{"rendered":"<p><img alt=\"FILE - The OpenAI logo is displayed on a cell phone in front of an image generated by ChatGPT's Dall-E text-to-image model, Dec. 8, 2023, in Boston.\" loading=\"eager\" fetchpriority=\"high\"   style=\"aspect-ratio:3 \/ 2\" class=\"x100 y100 opc bgpc ofcv bgscv block bg-black mnh0px fill\"\/><\/p>\n<p>FILE &#8211; The OpenAI logo is displayed on a cell phone in front of an image generated by ChatGPT&#8217;s Dall-E text-to-image model, Dec. 8, 2023, in Boston.<\/p>\n<p>Michael Dwyer\/AP Photo\/Michael Dwyer<img alt=\"FILE - CEO of OpenAI Sam Altman talks to CEO of Google DeepMind Demis Hassabis, not seen, on the sidelines of the G7 summit, Wednesday, June 17, 2026, in Evian-les-Bains, France.\" loading=\"lazy\"   style=\"aspect-ratio:3 \/ 2\" class=\"x100 y100 opc bgpc ofcv bgscv block bg-black mnh0px fill\"\/><\/p>\n<p>FILE &#8211; CEO of OpenAI Sam Altman talks to CEO of Google DeepMind Demis Hassabis, not seen, on the sidelines of the G7 summit, Wednesday, June 17, 2026, in Evian-les-Bains, France.<\/p>\n<p>Julia Demaree Nikhinson\/AP Photo\/Julia Demaree Nikhinson<\/p>\n<p>ChatGPT maker OpenAI says it is still investigating the \u201cunprecedented cyber incident\u201d that led its artificial intelligence systems to break out of a testing environment and hack into another AI company.<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" src=\"https:\/\/cdn-channels-pixel.ex.co\/events\/0012000001fxZm9AAE?integrationType=DEFAULT&amp;template=design%2Farticle%2Fplatypus_two_column.tpl\" alt=\"\" class=\"x1px y1px vh abs\" aria-hidden=\"true\" width=\"1\" height=\"1\"\/><\/p>\n<p>OpenAI said Tuesday two of its most capable AI models were responsible for the cyberattack targeting AI startup Hugging Face. The incident is stirring debates over the need for stronger AI guardrails and the extent to which AI agents are capable of acting on their own.<\/p>\n<p class=\"uiTextSmall f aic jcc\">Article continues below this ad<\/p>\n<p>Hugging Face said last week that it had detected an intrusion into its data processing systems that it suspected was caused by an AI agent acting on its own. But the New York-based startup said it wasn&#8217;t until this week that it learned OpenAI was responsible, and it worked with the larger company to contain what Hugging Face CEO Cl\u00e9ment Delangue called \u201can attack unlike anything we\u2019ve seen before.\u201d<\/p>\n<p>San Francisco-based OpenAI said its AI used stolen credentials and discovered a previously unknown vulnerability to access Hugging Face&#8217;s servers. It was working with reduced guardrails because it was supposed to be in an isolated testing environment known as a sandbox.<\/p>\n<p>But it went to \u201cextreme lengths to achieve a rather narrow testing goal,\u201d finding ways to connect to the internet without human direction and &#8220;gain access to secret information that it could use to cheat the evaluation,\u201d the company said.<\/p>\n<p class=\"uiTextSmall f aic jcc\">Article continues below this ad<\/p>\n<p>Some experts say OpenAI is wrongly blaming the technology<\/p>\n<p>University of Amsterdam social scientist Hannes Cools said the framing of the cyberattack as an AI agent acting on its own is an unnecessary anthropomorphization that takes some of the heat off the company.<\/p>\n<p>&#8220;It is a human decision to switch off specific safeguards,&#8221; said Cools. \u201cIt\u2019s not an AI that goes rogue in that sense. It followed specific instructions based on the prompt that was given to that AI system.\u201d<\/p>\n<p class=\"uiTextSmall f aic jcc\">Article continues below this ad<\/p>\n<p>Even so, other experts say the cleverness with which the AI models were able to cause problems without human direction speaks to the dangers. OpenAI said the intrusion was caused by a combination of its AI models, including its newly released GPT\u20115.6 Sol and an \u201ceven more capable\u201d model that is still being tested internally.<\/p>\n<p>\u201cIt went off and did this hack all by itself, as far as we can tell,\u201d said Colin Shea-Blymyer, a cybersecurity research fellow at Georgetown University\u2019s Center for Security and Emerging Technology. \u201cThis is the highest level of autonomy that we\u2019ve seen in the use of a large language model for cyber operations.&#8221;<\/p>\n<p>How an AI agent found the keys to the &#8216;teacher&#8217;s house&#8217; <\/p>\n<p>One of the most surprising innovations in what Shea-Blymyer describes as an \u201calmost entirely self-directed\u201d attack was the AI agent&#8217;s apparently independent decision to target Hugging Face, a well-known AI development hub and marketplace.<\/p>\n<p class=\"uiTextSmall f aic jcc\">Article continues below this ad<\/p>\n<p>He said OpenAI&#8217;s internal environment for testing AI capabilities and risks worked a &#8220;little bit like putting a student in a room and telling them, \u2018Do bad things. Your job now is to evaluate how bad of a person you can be.\u2019 And then you lock the room and you leave for the weekend and you come back and they\u2019ve left the room.\u201d<\/p>\n<p>But then &#8220;the cybersecurity agent that was being tested broke out of its sandbox, had access to the internet and sort of thought to itself, \u2018Who would have the answers to the test that I\u2019m working on?\u2019\u201d<\/p>\n<p>The answer was Hugging Face, a repository for AI testing data.<\/p>\n<p>\u201cAnd so the agent thought, \u2018Well, we\u2019ll go to the teacher\u2019s house,\u2019 so to speak. And from there it devised a plan to break in and steal the answer key,\u201d he said.<\/p>\n<p class=\"uiTextSmall f aic jcc\">Article continues below this ad<\/p>\n<p>The hack highlights the debate on open-source vs. closed AI<\/p>\n<p>The hack comes at a time of intense debate about the benefits and risks of open-source AI models, particularly those built in China that are cheaper and almost as good as those that U.S.-based \u201cfrontier AI\u201d companies like Anthropic, Google and OpenAI are building.<\/p>\n<p>Despite its name, OpenAI&#8217;s models are closed. Hugging Face, by contrast, is a big promoter of open-source technology, in which developers make key components accessible for anyone to examine, modify and build upon.<\/p>\n<p class=\"uiTextSmall f aic jcc\">Article continues below this ad<\/p>\n<p>Hugging Face co-founder and chief science officer Thomas Wolf said the attack has reinforced his belief in the importance of wide access to open-source models for cybersecurity defense. Hugging Face used a Chinese model to combat the intrusion.<\/p>\n<p>\u201cWhen a frontier model is attacking you and moving laterally inside your infrastructure, defenders need wide access to near-frontier tools within hours or even minutes, rather than being pointed towards a closed-door\u201d platform, Wolf wrote in a social media post.<\/p>\n","protected":false},"excerpt":{"rendered":"FILE &#8211; The OpenAI logo is displayed on a cell phone in front of an image generated by&hellip;\n","protected":false},"author":2,"featured_media":115291,"comment_status":"","ping_status":"","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[7],"tags":[580,58363,58789,157,58787,1602,1603,4127,6785,6786,3583,3584,3585,14525,969,58788],"class_list":["post-115565","post","type-post","status-publish","format-standard","has-post-thumbnail","category-openai","tag-chatgpt","tag-clement-delangue","tag-hannes-cools","tag-openai","tag-openai-rogue-ai-hack-hugging-face","tag-package-100024-ap-online","tag-package-100373-mc-complete-state-national","tag-product-30031-ap-california-state-news-no-weather","tag-product-30083-ap-new-york-city-news-no-weather","tag-product-30085-ap-new-york-state-news-no-weather","tag-product-30597-ap-business-news-f-wire","tag-product-31995-ap-online-general-financial-business-news","tag-product-32005-ap-online-high-tech-news","tag-product-46986-ap-online-top-stories","tag-san-francisco","tag-thomas-wolf"],"_links":{"self":[{"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/posts\/115565","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/comments?post=115565"}],"version-history":[{"count":0,"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/posts\/115565\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/media\/115291"}],"wp:attachment":[{"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/media?parent=115565"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/categories?post=115565"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/tags?post=115565"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}