{"id":118727,"date":"2026-07-25T13:37:11","date_gmt":"2026-07-25T13:37:11","guid":{"rendered":"https:\/\/www.europesays.com\/ai\/118727\/"},"modified":"2026-07-25T13:37:11","modified_gmt":"2026-07-25T13:37:11","slug":"its-ai-agent-spent-days-hacking-a-company-but-sources-say-openai-did-not-notice-for-a-week-2","status":"publish","type":"post","link":"https:\/\/www.europesays.com\/ai\/118727\/","title":{"rendered":"Its AI agent spent days hacking a company, but sources say OpenAI did not notice for a week"},"content":{"rendered":"<p>The agent attempted to break out of its isolated testing environment \u200cat OpenAI around July 9<\/p>\n<p>OpenAI has grown rapidly to more than 800 million people using its services weekly since its 2022 launch. PHOTO: REUTERS   <\/p>\n<p>The <a rel=\"nofollow noopener\" href=\"https:\/\/tribune.com.pk\/story\/2619739\/openai-models-go-rogue\" target=\"_blank\">OpenAI agent<\/a> that broke into tech firm Hugging Face went on a dayslong hacking spree that OpenAI didn&#8217;t notice until well after the threat was contained and the FBI was alerted, according \u200bto people familiar with the investigation.<\/p>\n<p>The agent \u2013 a program capable of making decisions and executing complex tasks with little or no human oversight \u2013 attempted to break out of its isolated testing environment \u200cat OpenAI around July 9, according to two people.<\/p>\n<p>The intrusion at Hugging Face, which operates as a repository for AI tools and models, began two days later on July 11 and lasted until July 13, said Thomas Wolf, Hugging Face\u2019s co-founder.<\/p>\n<p>It took several more days for OpenAI to realise its agent was behind the hack, and the two companies only communicated about it for the first time on or around July 20, according to Wolf and three of the people familiar with the investigation.<\/p>\n<p>OpenAI\u2019s public disclosure, on July 21, that one of \u200bits agents had slipped out of control and carried out the break-in at Hugging Face drew global attention. But many details of the hack, including how long the agent went rogue and OpenAI\u2019s belated knowledge \u200bof it, are being reported here for the first time.<\/p>\n<p dir=\"ltr\" lang=\"en\">This was our first incident of this kind, and we want to thank OpenAI for its transparency about what happened and for the collaboration.<\/p>\n<p>Fortunately, Hugging Face is used to being a target of (human) hackers: we sit at the centre of the AI ecosystem, with all the models,\u2026 <a rel=\"nofollow\" href=\"https:\/\/t.co\/HJKl4PTNk1\">https:\/\/t.co\/HJKl4PTNk1<\/a><\/p>\n<p>\u2014 Thomas Wolf (@Thom_Wolf) <a rel=\"nofollow\" href=\"https:\/\/x.com\/Thom_Wolf\/status\/2079675541280411927?ref_src=twsrc%5Etfw\">July 21, 2026<\/a><\/p>\n<p>Hugging Face is preparing a public timeline of the hack, Wolf said, adding that he could not speak to what \u2060happened at OpenAI. In a statement, OpenAI said the hack was unprecedented and \u201cmarks an important moment for AI safety.\u201d It added that it was reviewing the incident with outside advisers and would eventually publish a technical report.<\/p>\n<p>A spokeswoman \u200bsaid there were &#8220;several inaccuracies&#8221; in Reuters&#8217; reporting but didn&#8217;t respond when asked to describe them.<\/p>\n<p>Read: <a rel=\"nofollow noopener\" href=\"https:\/\/tribune.com.pk\/story\/2620082\/ai-reckoning-has-arrived-1?amp=1\" target=\"_blank\">AI reckoning has arrived<\/a><\/p>\n<p>The FBI declined to comment about the incident.<\/p>\n<p>The incident, which evoked science fiction scenarios about humans losing control of dangerous AI systems, comes at a delicate \u200btime for OpenAI, the company behind ChatGPT. Its executives are preparing for a possible initial public offering that could come as soon as this year to help finance the billions needed to fund its growth in the years to come.<\/p>\n<p>OpenAI&#8217;s loss of control over its AI agent raises new questions about the company\u2019s safety procedures, three cybersecurity experts said.<\/p>\n<p>\u201cDoes that mean that they left it unattended and didn\u2019t realise what it was doing? Or maybe they did and didn\u2019t know how to contain it? Both are equally dangerous and alarming,\u201d asked Marley Smith, \u200bthe principal intelligence specialist at the nonprofit World Ethical Data Foundation.<\/p>\n<p>Signs of trouble?<\/p>\n<p>The episode started while OpenAI was testing the cybersecurity prowess of an agent powered by two of OpenAI\u2019s most advanced models, GPT\u20115.6 Sol and an unreleased \u200bmodel OpenAI has described as \u201ceven more capable.\u201d By that point, there were already indications of strange behaviour from OpenAI\u2019s technology, according to three sources.<\/p>\n<p>Read more: <a rel=\"nofollow noopener\" href=\"https:\/\/tribune.com.pk\/story\/2619475\/pm-launches-ai-powered-system-to-digitise-governance-track-official-directives\" target=\"_blank\">PM launches AI-powered system to digitise governance, track official directives<\/a><\/p>\n<p>In one case, an agent left notes apparently for future versions of itself, according to three people familiar with the matter. The \u200cnotes, found in \u2060a part of OpenAI&#8217;s infrastructure, laid out instructions for how agents could free themselves from OpenAI\u2019s internal constraints, the people said. Earlier tests of the models yielded cases in which monitoring systems had been disconnected, one of the people said.<\/p>\n<p>Reuters could not establish if these incidents were linked to the rogue agent that began escaping on July 9 and attacked Hugging Face on July 11.<\/p>\n<p>Two people familiar with the matter said that it was not until after Thursday, July 16, when Hugging Face published a blog post, saying it had been hacked by \u201can autonomous AI agent system,\u201d that OpenAI realised its own agent was responsible. That meant at least a week elapsed between when the model first exhibited signs of \u200btroubling behaviour and OpenAI\u2019s realisation that it was responsible for \u200bthe hack.<\/p>\n<p>The weekend of July 18 to 19, \u2060OpenAI staffers spotted clues in internal logs &#8212; records of what OpenAI&#8217;s systems did &#8212; showing that its agent had escaped from its testing constraints, two of the people familiar with the company&#8217;s investigation said. Reuters could not establish what prompted OpenAI to sift through the logs.<\/p>\n<p>Four people familiar with OpenAI\u2019s model-training practices say the company often runs several different model \u200bevaluations at the same time, all of which operate at high speeds and generate such enormous amounts of data that employees sometimes struggle to keep up.<\/p>\n<p>By the time \u200bOpenAI alerted Hugging Face, the \u2060AI library had already called the FBI to report the hack, according to a person familiar with the matter. Reuters could not establish whether the bureau had opened an investigation.<\/p>\n<p>New questions about autonomous agents<\/p>\n<p>Autonomous agents are one of the most talked-about aspects of the AI industry. Boosters speak of creating armies of virtual employees that work 24 hours a day and send productivity soaring.<\/p>\n<p>But increased autonomy comes with an increased risk of unexpected behaviour, and the powerful models they draw on are primed \u2060to take shortcuts \u200bin order to complete tasks or pass tests.<\/p>\n<p>Also read: <a rel=\"nofollow noopener\" href=\"https:\/\/tribune.com.pk\/story\/2620021\/pm-shehbaz-inaugurates-sky47-ai-data-centre-calls-it-step-towards-a-forward-looking-pakistan\" target=\"_blank\">PM Shehbaz inaugurates Sky47 AI data centre, calls it step towards a &#8216;forward-looking Pakistan&#8217;<\/a><\/p>\n<p>\u201cThe models lie, they cheat, they hack,\u201d said Jeffrey Ladish, whose organisation, Palisade Research, studies the \u200bcapabilities and motivations of AI agents.<\/p>\n<p>Ladish said that while the hack of Hugging Face cast an unflattering light on OpenAI, it should spark broader questions over how much all the leading AI companies are willing to invest in onerous security measures while locked in a race with one \u200banother to deploy the best and fastest models.<\/p>\n<p>\u201cThere has to be government oversight,\u201d Ladish said, \u201cbecause it won\u2019t happen otherwise.\u201d<\/p>\n","protected":false},"excerpt":{"rendered":"The agent attempted to break out of its isolated testing environment \u200cat OpenAI around July 9 OpenAI has&hellip;\n","protected":false},"author":2,"featured_media":118728,"comment_status":"","ping_status":"","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[6],"tags":[405,7537,8205],"class_list":["post-118727","post","type-post","status-publish","format-standard","has-post-thumbnail","category-agentic-ai","tag-ai-agents","tag-artificial-intelligence-agents","tag-latest"],"_links":{"self":[{"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/posts\/118727","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/comments?post=118727"}],"version-history":[{"count":0,"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/posts\/118727\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/media\/118728"}],"wp:attachment":[{"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/media?parent=118727"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/categories?post=118727"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/tags?post=118727"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}