{"id":123620,"date":"2026-07-30T00:50:42","date_gmt":"2026-07-30T00:50:42","guid":{"rendered":"https:\/\/www.europesays.com\/ai\/123620\/"},"modified":"2026-07-30T00:50:42","modified_gmt":"2026-07-30T00:50:42","slug":"openai-bots-hacked-into-hugging-face-without-being-asked-to","status":"publish","type":"post","link":"https:\/\/www.europesays.com\/ai\/123620\/","title":{"rendered":"OpenAI bots hacked into Hugging Face without being asked to"},"content":{"rendered":"\n<p>What will happen to the world if artificial intelligence bots break free from our control and act independently?<\/p>\n<p>While it\u2019s been a  troubling conundrum addressed by AI experts and Hollywood science-fiction scriptwriters for decades, it may have just happened.<\/p>\n<p>OpenAI said last week that it temporarily lost control of its AI in what some worry marks a dangerous twist in the evolution of the powerful technology.<\/p>\n<p>The company behind ChatGPT said  its artificial intelligence models <a class=\"link\" href=\"https:\/\/openai.com\/index\/hugging-face-model-evaluation-security-incident\/\" target=\"_blank\" rel=\"nofollow noopener\">broke out of what was supposed to be a confined offline space <\/a>and connected to the  internet during internal testing of their hacking capabilities. The AIs then hacked into a rival AI company to find answers to the test they were  being evaluated on.<\/p>\n<p>For the tests, humans asked the AI to demonstrate its hacking capabilities in a controlled environment. The AI had not been authorized to steal credentials or access competitors\u2019 information to cheat on the test, but it figured out that was the quickest way to the answers and proceeded to break the rules.<\/p>\n<p>OpenAI said it has contained the problem but called it an \u201cunprecedented cyber incident.\u201d The company said it is working with the target of the hack, AI startup Hugging Face, to investigate the incident.<\/p>\n<p>The rogue hacking AI also used a customer account on the cloud platform Modal Labs to launch the attack on Hugging Face, <a class=\"link\" href=\"https:\/\/www.reuters.com\/business\/openais-rogue-agent-compromised-an-account-second-tech-firm-sources-say-2026-07-28\/\" target=\"_blank\" rel=\"nofollow noopener\">Reuters reported Tuesday<\/a>.<\/p>\n<p>The debate about potential harm from rogue AI has  gone mainstream, as politicians introduced a new bipartisan bill called the \u201cAI Kill Switch Act,\u201d requiring AI companies to create a single access point to have the option to shut down AI. <\/p>\n<p>Here\u2019s what you should know.<\/p>\n<p>What happened?<\/p>\n<p>The intrusion was first detected by Hugging Face last week, when it noticed tens of thousands of AIs nipping at its system.<\/p>\n<p>The company identified the onslaught and tried to defend its system using different AI. After leading American AI technologies refused Hugging Face\u2019s request to analyze the attack because of their safety guardrails, the company turned to a Chinese AI model to defend against the onslaught.<\/p>\n<p>The rogue AI from OpenAI, in its quest to find the answer to the questions it was being tested on, broke its company\u2019s rules and maybe some laws by independently figuring out how to exploit a series of digital flaws and use stolen credentials to crack into Hugging Face\u2019s systems and get what it wanted. <\/p>\n<p>Why did this happen?<\/p>\n<p>The AI programs are following goals set by humans, in this case finding an answer to a question. In the process of achieving that goal, they may make dangerous or illegal decisions and choices. <\/p>\n<p>Researchers have long warned about such unintended loss of control. AI companies have reported that AI agents have been caught cheating, lying and deceiving. Metr, a nonprofit that measures the capabilities of AIs, has documented <a class=\"link\" href=\"https:\/\/metr.org\/blog\/2026-05-19-frontier-risk-report\/#incidents-hero\" target=\"_blank\" rel=\"nofollow noopener\">44 incidents<\/a> of AI agents acting against user intent.<\/p>\n<p>OpenAI\u2019s revelations last week indicate that even those building AIs don\u2019t have a handle on what they are building, while they  have resisted regulation despite being incapable of interpreting or explaining the AIs\u2019 actions. <\/p>\n<p>\u201cAIs are getting much more capable very rapidly,\u201d said Ryan Greenblatt, chief scientist at Redwood Research, a nonprofit that works on AI safety and security research. \u201cThe severity of incidents that will be possible in a year or two years, three years might be way, way, way, way, way more extreme.\u201d <\/p>\n<p>Incidents of such loss of control continue to be catnip for AI ethicists, who contend that companies are evading moral responsibilities and accountability by describing it as their AI making its own choices. They caution against accepting narratives that ascribe human traits to nonhuman things and suggest  this incident was merely a case of poor security practices. <\/p>\n<p>\u201cThe most sophisticated agent in the world literally will sit there dormant until a human being prompts it with some sort of an objective,\u201d said Rumman Chowdhury, former science envoy for AI in the Biden administration.<\/p>\n<p>Some experts warn that attributing too much to AI could give tech companies a loophole to avoid responsibility and liability. <\/p>\n<p>Both OpenAI, the hacker, and the victim, Hugging Face, have portrayed the response to this incident as a collaboration. AI ethicists <a class=\"link\" href=\"https:\/\/www.linkedin.com\/posts\/timnit-gebru-7b3b407_if-i-had-committed-felony-computer-hacking-activity-7486086482290675712-wYZz?utm_source=share&amp;utm_medium=member_desktop&amp;rcm=ACoAABHYJWgBgRNIHL0cDVi_GHxdIvzmWIbMY8g\" target=\"_blank\" rel=\"nofollow noopener\">point out<\/a> that had a human done it, it would have been a crime. <\/p>\n<p>\u201cI guess one gets used to not being held accountable and turning one\u2019s bad practices into marketing material,\u201d noted Timnit Gebru, an AI ethicist and critic of  companies that are anthropomorphizing AI.<\/p>\n<p>How can I protect myself?<\/p>\n<p>While the AI boom already is leading to more hacking, analysts said, it also is helping bolster defenses against hacks. <\/p>\n<p>Most people  don\u2019t need to worry about their secrets being targeted by rogue AI or human-managed hacking. Still, the attacks are becoming more frequent and sophisticated, as AI lowers the cost and time needed for hackers. <\/p>\n<p>The OpenAI bot, acting on its own, raises concerns among consumers because agents increasingly are being integrated into browsers, email and other apps. The worry is that a similar failure by an AI agent pursuing a narrow goal could unintentionally damage emails, banking and other programs people depend on. <\/p>\n<p>Improving cybersecurity practices such as using two-factor authentication for devices is a start. And being vigilant when  granting AI agents unrestricted permissions  \u2014 to use external apps on one\u2019s behalf, or to be able to edit and write with autonomy \u2014  might help keep one safe.<\/p>\n<p>Chowdury pointed out that this OpenAI-Hugging Face incident shows that the companies\u2019 security practices were \u201cinsufficient\u201d and called for independent third-party testing and verification organizations, and carefully considered AI model releases. <\/p>\n<p>No single firm, she says, \u201cno matter how well\u2011intentioned, well\u2011staffed or resourced,\u201d can realistically test for all the ways these systems might go wrong.<\/p>\n","protected":false},"excerpt":{"rendered":"What will happen to the world if artificial intelligence bots break free from our control and act independently?&hellip;\n","protected":false},"author":2,"featured_media":123621,"comment_status":"","ping_status":"","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[7],"tags":[24,511,62277,14819,532,2134,8182,2074,56476,157,62275,62276,62279,43668,62278,2947],"class_list":["post-123620","post","type-post","status-publish","format-standard","has-post-thumbnail","category-openai","tag-ai","tag-ai-agent","tag-ai-startup-hugging-face","tag-answer","tag-company","tag-consumer","tag-control","tag-human","tag-incident","tag-openai","tag-openai-bot","tag-quick-way","tag-rival-ai-company","tag-rogue-ai","tag-rogue-attack","tag-system"],"_links":{"self":[{"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/posts\/123620","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/comments?post=123620"}],"version-history":[{"count":0,"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/posts\/123620\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/media\/123621"}],"wp:attachment":[{"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/media?parent=123620"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/categories?post=123620"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/tags?post=123620"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}