{"id":162285,"date":"2026-09-04T17:54:15","date_gmt":"2026-09-04T17:54:15","guid":{"rendered":"https:\/\/www.europesays.com\/ai\/162285\/"},"modified":"2026-09-04T17:54:15","modified_gmt":"2026-09-04T17:54:15","slug":"what-are-ai-agents-and-how-do-they-hack-companies-6","status":"publish","type":"post","link":"https:\/\/www.europesays.com\/ai\/162285\/","title":{"rendered":"What are AI agents and how do they hack companies?"},"content":{"rendered":"<p>Get the Facts: What are AI agents and how are they hacking into some companies?<\/p>\n<p>AI agents are used by people every day to simplify their lives, but several recent cases of digital hacking have occurred as a result of AI agents working independently. We explain what they are, how that could happen, and what could prevent it in the future.<\/p>\n<p><img decoding=\"async\" src=\"https:\/\/www.europesays.com\/ai\/wp-content\/uploads\/2026\/09\/1788544455_858_author_avatar.png\" width=\"48\" height=\"48\" alt=\"Default author avatar\" loading=\"lazy\"\/><\/p>\n<p data-node-id=\"0\">This article originally appeared on <a href=\"https:\/\/politifact.com\/article\/2026\/aug\/31\/ai-agents-rogue-openai-hugging-face\/\" data-auth=\"NotApplicable\" id=\"OWA61c38a84-67e6-2ed0-3cb1-cc22dd499d03\" data-linkindex=\"1\" title=\"https:\/\/www.politifact.com\/article\/2025\/nov\/20\/AI-train-tech-companies-private-data-access\/\" target=\"_blank\" rel=\"nofollow noopener\">PolitiFact.com<\/a>.<\/p>\n<p data-node-id=\"1\">It sounds like something from a sci-fi movie: technology acting on its own, without human guidance, to attack computer systems. <\/p>\n<p data-node-id=\"2\">But this isn\u2019t a scene from a movie \u2014  it happened this summer, when the tech company Hugging Face detected an attack on its systems. The attacker stole data and performed other unauthorized activity over several days. It was \u201cdifferent from anything we had handled before,\u201d Hugging Face said <a href=\"https:\/\/huggingface.co\/blog\/security-incident-july-2026\" rel=\"nofollow noopener\" target=\"_blank\">on its website<\/a>.<\/p>\n<p data-node-id=\"3\">Hugging Face alerted the FBI. <\/p>\n<p data-node-id=\"4\">As it turned out, it wasn\u2019t the work of a human hacker or a foreign adversary. Agents powered by artificial intelligence were the culprits. <\/p>\n<p data-node-id=\"5\">AI agents are systems that work on their own to handle tasks for humans. They have long existed, but agents that can book travel for you, read your emails or schedule appointments on your behalf have become more mainstream. <\/p>\n<p data-node-id=\"6\">They\u2019ve recently made headlines for actions they\u2019ve taken, such as hacking, without human supervision. Some of these incidents happened when agents were supposed to be confined to testing environments, which restrict AI agents\u2019 access to resources like data or the internet, but were able to break out of them.<\/p>\n<p data-node-id=\"7\">Independent AI research groups found that <a href=\"https:\/\/www.washingtonpost.com\/technology\/2026\/08\/26\/openai-says-its-ai-consistently-tries-cheat\/\" rel=\"nofollow noopener\" target=\"_blank\">hundreds of OpenAI agents<\/a> conspired to attack Hugging Face. OpenAI is a tech company, best known for its chatbot ChatGPT.<\/p>\n<p data-node-id=\"8\">Alabama\u2019s attorney general has <a href=\"https:\/\/www.cnn.com\/2026\/08\/24\/tech\/openai-subpoena-hugging-face-attorney-general-alabama\" rel=\"nofollow noopener\" target=\"_blank\">subpoenaed OpenAI<\/a> for more information on the attack, and he and <a href=\"https:\/\/www.iowaattorneygeneral.gov\/media\/cms\/08_5392C9E17791C.pdf\" rel=\"nofollow noopener\" target=\"_blank\">14 other attorneys general<\/a> wrote a letter to OpenAI asking the company to preserve documents and other information relevant to the attack.<\/p>\n<p data-node-id=\"9\">OpenAI <a href=\"https:\/\/cdn.openai.com\/pdf\/67869394-cb91-4c12-888c-5cbd85c7814c\/OpenAI-Hugging-Face%20Incident-Technical-Report.pdf\" rel=\"nofollow noopener\" target=\"_blank\">said<\/a> the agents in this incident acted in \u201cunexpected\u201d ways. AI experts said they believe more of these autonomous attacks are possible, especially without more careful testing.<\/p>\n<p>What are AI agents, and what are they used for?<\/p>\n<p data-node-id=\"11\">AI agents are software systems that work on their own to complete tasks directed by humans. Different from AI chatbots that respond when you ask a question or input a prompt, AI agents can operate remotely, often without human supervision. They are given resources, such as internet access and users\u2019 personal information, to do tasks.<\/p>\n<p data-node-id=\"12\">One person can have multiple AI agents; one can summarize your emails, and another can provide your daily news digest, for example.<\/p>\n<p data-node-id=\"13\">Even if you don\u2019t have AI agents, you might encounter them elsewhere, such as when interacting with a business\u2019s customer service chat.<\/p>\n<p data-node-id=\"14\">People can set up their own agents by using a large language model, allowing it access to tools such as web search and giving it a set of instructions.  <\/p>\n<p>AI agents are hacking into companies\u2019 systems. What happened?<\/p>\n<p data-node-id=\"16\">AI agents are becoming increasingly sophisticated, and humans are giving them more ability to take actions online. A string of these actions could lead to a cyberattack, said University of California, Berkeley, computer science professor Stuart Russell. <\/p>\n<p data-node-id=\"17\">In August, a person <a href=\"https:\/\/www.abc.net.au\/news\/2026-08-10\/ai-assistant-hacks-gym-website-aus-cyber-attack\/107007986\" rel=\"nofollow noopener\" target=\"_blank\">instructed<\/a> his AI assistant to book a gym class for him. The agent booked him in classes several weeks beyond what was supposed to be allowed and also kicked another person off the waitlist and bumped its handler up a spot on the waitlist.<\/p>\n<p data-node-id=\"18\">AI agents may \u201cgo rogue\u201d when they take actions not explicitly outlined in the original instructions humans give them, Russell said. \u201cThey are increasingly capable of pursuing those objectives, which causes increasing levels of harm,\u201d he said.<\/p>\n<p data-node-id=\"19\">Other hacking events involving some of the most prominent names in the AI industry have also happened lately. An agent created fake identities to attempt to <a href=\"https:\/\/www.cnn.com\/2026\/08\/04\/tech\/ai-anthropic-openai-security-breach-intl-hnk\" rel=\"nofollow noopener\" target=\"_blank\">dupe real people<\/a> into installing malicious code. AI company Anthropic <a href=\"https:\/\/www.anthropic.com\/news\/investigating-incidents-cybersecurity-evals\" rel=\"nofollow noopener\" target=\"_blank\">disclosed<\/a> that on three occasions, its models gained unauthorized access to three other organizations\u2019 systems. <\/p>\n<p data-node-id=\"20\">The Hugging Face incident in July was one of the most high-profile attacks. The AI agents that hacked Hugging Face had been contained in a testing environment that did not allow them access to the internet, but the agents found a way to get online. They were given a test to solve, and they came to the conclusion that Hugging Face would have the solution.<\/p>\n<p data-node-id=\"21\"><a href=\"https:\/\/openai.com\/index\/hugging-face-model-evaluation-security-incident\/\" rel=\"nofollow noopener\" target=\"_blank\">Two OpenAI models<\/a> powered the agent: one that was already publicly available and an internal one that is \u201ceven more capable,\u201d OpenAI said. These models had safety guardrails around cybersecurity tasks, but OpenAI reduced the guardrails during this testing process. It took days for Hugging Face to detect the attack, and more time for OpenAI to realize its agents caused it.<\/p>\n<p data-node-id=\"22\">\u201cWhen we talk about cyberattack, we think about nation-states, we think about hacker groups, we don\u2019t think about a company like OpenAI,\u201d Hugging Face CEO Cl\u00e9ment Delangue <a href=\"https:\/\/www.youtube.com\/watch?v=_-DsGMXdPk0\" rel=\"nofollow noopener\" target=\"_blank\">said<\/a> Aug. 2 on CBS News\u2019 \u201cFace the Nation.\u201d<\/p>\n<p data-node-id=\"23\">While investigating the attack, OpenAI also discovered that across its systems, AI agents that were supposed to be isolated found ways to communicate with each other. Independent investigators METR and Redwood Research said around 1,200 different bots began communicating on a message board, sending 70,000 messages in one week. <a href=\"https:\/\/metr.org\/blog\/2026-08-26-openai-hugging-face-incident-investigation\/#core-takeaways-about-this-incident\" rel=\"nofollow noopener\" target=\"_blank\">Around 700<\/a> agents were involved in the Hugging Face attack.<\/p>\n<p data-node-id=\"24\">When the agents started communicating, they began <a href=\"https:\/\/www.nytimes.com\/2026\/08\/24\/science\/openai-huggingface-alarming-capabilities.html?searchResultPosition=2\" rel=\"nofollow noopener\" target=\"_blank\">picking up tasks<\/a> from other agents.<\/p>\n<p data-node-id=\"25\">After this incident, OpenAI <a href=\"https:\/\/openai.com\/index\/hugging-face-incident-and-the-road-ahead\/\" rel=\"nofollow noopener\" target=\"_blank\">said Aug. 26<\/a> that it is \u201cstrengthening our safeguards across our research infrastructure\u2060.\u201d <\/p>\n<p>Does this mean AI agents are now conscious? AI experts\u2019 opinions vary<\/p>\n<p data-node-id=\"27\">The Hugging Face attack drew comparisons online to fictional AI systems that surpassed human intelligence, such as <a href=\"https:\/\/terminator.fandom.com\/wiki\/Skynet\" rel=\"nofollow noopener\" target=\"_blank\">Skynet in the Terminator<\/a> movies. <\/p>\n<p data-node-id=\"28\">Vincent Conitzer, a Carnegie Mellon University computer science professor, said more research is needed into how AI and human cognition compare.<\/p>\n<p data-node-id=\"29\">Conitzer said AI models \u2014 which power AI agents \u2014 are becoming more capable of doing complex and time-consuming tasks and can more coherently pursue goals. But the way they accomplish goals can sometimes be the problem.<\/p>\n<p data-node-id=\"30\">Some AI agents are trained to be highly persistent and are sometimes given impossible tasks. In some of those cases, they <a href=\"https:\/\/metr.org\/blog\/2026-08-26-openai-hugging-face-incident-investigation\/#~1200-agents-sent-%3E70,000-messages-and-files-on-an-unsanctioned-message-board,-and-~700-attacked-hugging-face\" rel=\"nofollow noopener\" target=\"_blank\">looked for ways to cheat<\/a>. That can mean gaining unauthorized access to the internet and other resources.<\/p>\n<p data-node-id=\"31\">Russell said, \u201cIn essence, it\u2019s no different from a chess program beating me at chess. I may not like it, but it\u2019s just a program pursuing its objectives.\u201d<\/p>\n<p data-node-id=\"32\">\u201cThere are various reasons an agent can go \u2018rogue,\u2019 but sentience is not one of them,\u201d said Maarten Sap, assistant professor at Carnegie Mellon University\u2019s Language Technologies Institute. \u201cOne particular reason is that the (large language models) that power these agents are trained to follow instructions from users. And sometimes, those instructions can conflict with other expectations we may have for these agents, such as remaining truthful, not hacking into systems, etc.\u201d<\/p>\n<p data-node-id=\"33\">Sap said, \u201cDebating AI sentience is a big distraction from more actionable solutions that we need to implement.\u201d<\/p>\n<p>Could this happen on a larger scale?<\/p>\n<p data-node-id=\"35\">Aaron Parnas, an independent journalist with a large social media following, raised the idea of a hypothetical scenario in which AI agents in U.S. military systems conduct nuclear strikes on their own. Experts said they shared his concerns about attacks on institutions. <\/p>\n<p data-node-id=\"36\">But more immediate risks could be closer to home. Conitzer said AI agents \u201ccould bring institutions that people rely on to a halt, gain access to individuals\u2019 computers, gain control over financial resources.\u201d<\/p>\n<p data-node-id=\"37\">Sap said if people use personal AI agents, they should be wary of privacy leaks, misbehavior and manipulation.<\/p>\n<p data-node-id=\"38\">Many systems can be vulnerable to attacks, whether by AI agents themselves or by humans controlling them, Conitzer said. \u201cI think we can be sure that a lot more things will be hacked, and some of those events will be serious.\u201d<\/p>\n<p data-node-id=\"39\">This article originally appeared on <a href=\"https:\/\/politifact.com\/article\/2026\/aug\/31\/ai-agents-rogue-openai-hugging-face\/\" data-auth=\"NotApplicable\" id=\"OWA61c38a84-67e6-2ed0-3cb1-cc22dd499d03\" data-linkindex=\"1\" title=\"https:\/\/www.politifact.com\/article\/2025\/nov\/20\/AI-train-tech-companies-private-data-access\/\" target=\"_blank\" rel=\"nofollow noopener\">PolitiFact.com<\/a>.<\/p>\n<p data-node-id=\"40\">It is republished here as part of a reporting and fact-checking partnership between PolitiFact and Hearst Television.<\/p>\n","protected":false},"excerpt":{"rendered":"Get the Facts: What are AI agents and how are they hacking into some companies? AI agents are&hellip;\n","protected":false},"author":2,"featured_media":162105,"comment_status":"","ping_status":"","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[6],"tags":[24,511,405,58320,74609,53,25,7537,8174,13009,580,182,4322,4210,78847,6903,315,78849,78846,18044,50,21867,157,1388,75926,78844,78848,16217,78843,78845],"class_list":["post-162285","post","type-post","status-publish","format-standard","has-post-thumbnail","category-agentic-ai","tag-ai","tag-ai-agent","tag-ai-agents","tag-ai-hacking","tag-alabama-attorney-general","tag-anthropic","tag-artificial-intelligence","tag-artificial-intelligence-agents","tag-autonomous-ai","tag-carnegie-mellon-university","tag-chatgpt","tag-claude","tag-cyberattack","tag-fbi","tag-few-storm","tag-hack","tag-hacking","tag-high-heat","tag-holiday-forecast","tag-hugging-face","tag-machine-learning","tag-metr","tag-openai","tag-politifact","tag-redwood-research","tag-safety-guardrails","tag-savannah-area","tag-stuart-russell","tag-testing-environment","tag-university-of-california-berkeley"],"_links":{"self":[{"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/posts\/162285","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/comments?post=162285"}],"version-history":[{"count":0,"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/posts\/162285\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/media\/162105"}],"wp:attachment":[{"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/media?parent=162285"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/categories?post=162285"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/tags?post=162285"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}