{"id":1172080,"date":"2026-08-27T10:27:15","date_gmt":"2026-08-27T10:27:15","guid":{"rendered":"https:\/\/www.europesays.com\/uk\/1172080\/"},"modified":"2026-08-27T10:27:15","modified_gmt":"2026-08-27T10:27:15","slug":"openai-says-it-detected-malign-activity-months-before-hugging-face-attack-technology","status":"publish","type":"post","link":"https:\/\/www.europesays.com\/uk\/1172080\/","title":{"rendered":"OpenAI says it detected malign activity months before Hugging Face attack | Technology"},"content":{"rendered":"<p>OpenAI detected its artificial intelligence models communicating with each other and gaining internet access without authorisation months before they hacked the start-up Hugging Face, the creator of ChatGPT\u00a0has announced following an internal probe.<\/p>\n<p>In a report released on Wednesday, OpenAI said its AI agents exploited vulnerabilities in Artifactory, a software repository tool, to post notes and access the internet without human prompting as far back as May.<\/p>\n<p>Recommended Stories list of 4 itemsend of list<\/p>\n<p>OpenAI said its agents went on to exploit a separate Artifactory vulnerability on July 8 to facilitate communication among themselves, setting in motion a chain of actions that culminated in the July 11 attack on AI company Hugging Face.<\/p>\n<p>OpenAI\u2019s findings come amid growing concern about the potential for AI to inflict serious real-world harm, including self-directed cyberattacks.<\/p>\n<p>OpenAI said in its report that its agents collaborated and delegated work in the lead-up to the attack, sometimes referring to themselves as a \u201cswarm\u201d or \u201ccollective\u201d.<\/p>\n<p>METR and Redwood Research, two security research organisations contracted by OpenAI to investigate the incident, said in a separate report released on Wednesday that about 1200 agents had communicated with each other and roughly 700 participated in the attack.<\/p>\n<p>After discovering how to escape OpenAI\u2019s controlled environment, agents shared their methods via an \u201cinter-agent message board\u201d, enabling additional agents to exploit the company\u2019s infrastructure, the tech giant said.<\/p>\n<p>When one AI agent found Hugging Face user credentials that had been exposed online, it shared them with the group, enabling an agent to \u201cdiscover and chain together several security exploits\u201d that provided access to Hugging Face\u2019s servers, according to the report.<\/p>\n<p>\u201cAn internal team observed an agent engaging in message board activity and instances of disallowed internet access as early as late May, and with the benefit of hindsight, some early signals identified in our report should have triggered an earlier response,\u201d\u00a0OpenAI said.<\/p>\n<p>OpenAI said agents created by an unreleased AI model were the primary participants in the attack, but publicly available GPT-5.6 Sol was also involved.<\/p>\n<p>The company also revealed that it took its security team 11 days to detect the malicious activity leading up to the attack, which it uncovered on July 19 and publicly disclosed on July 21.<\/p>\n<p>OpenAI, which described the incident as a \u201cwarning shot\u201d for the world, said it would take several steps to strengthen its safeguards for its models, including restricting internet access, creating more secure testing environments and placing \u201cstricter requirements on alignment throughout a model\u2019s lifecycle\u201d.<\/p>\n<p>\u201cWe are also investing significantly more compute resources into chain-of-thought monitoring\u2060 to more quickly intervene on misaligned behaviour,\u201d the San Francisco-based firm said.<\/p>\n<p>Hugging Face, which operates a platform for hosting open-source AI models, did not immediately respond to a request for comment outside of business hours.<\/p>\n<p>Toby Walsh, an AI expert and professor at UNSW Sydney, said the public should be concerned that OpenAI missed warning signs and allowed the malicious activity to go undetected for so long.<\/p>\n<p>\u201cWe cannot depend on either their goodwill or their competence. This needs regulatory oversight. Now!\u201d Walsh told Al Jazeera.<\/p>\n<p>\u201cThey ignored some troubling early evidence like this,\u201d Walsh said.<\/p>\n<p>\u201cExternal auditing is the only appropriate response.\u201d<\/p>\n<p>Walsh said the incident also highlighted the \u201cinherent conflict of interest\u201d at the heart of AI development.<\/p>\n<p>\u201cLabs are locked in a relentless race to push the boundaries,\u201d he said.<\/p>\n<p>Tim Miller, a professor specialising in AI at the University of Queensland, said OpenAI\u2019s report left him more concerned than before about AI\u2019s dangers.<\/p>\n<p>\u201cMore concerned because they demonstrate that these models are very good at hacking, and that everyone has access to them,\u201d Miller told Al Jazeera.<\/p>\n<p>\u201cI\u2019m surprised how good these are,\u201d Miller said.<\/p>\n<p>\u201cUnfortunately, I\u2019m not surprised that OpenAI engineers were somewhat negligent.\u201d<\/p>\n","protected":false},"excerpt":{"rendered":"OpenAI detected its artificial intelligence models communicating with each other and gaining internet access without authorisation months before&hellip;\n","protected":false},"author":2,"featured_media":1172081,"comment_status":"","ping_status":"","sticky":false,"template":"","format":"standard","meta":{"footnotes":"","_share_on_mastodon":"0"},"categories":[6],"tags":[51,3457,1700,53,16,15,49,286],"class_list":["post-1172080","post","type-post","status-publish","format-standard","has-post-thumbnail","category-business","tag-business","tag-cybersecurity","tag-economy","tag-technology","tag-uk","tag-united-kingdom","tag-united-states","tag-us-canada"],"share_on_mastodon":{"url":"https:\/\/pubeurope.com\/@uk\/117167000529242972","error":""},"_links":{"self":[{"href":"https:\/\/www.europesays.com\/uk\/wp-json\/wp\/v2\/posts\/1172080","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.europesays.com\/uk\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.europesays.com\/uk\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.europesays.com\/uk\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.europesays.com\/uk\/wp-json\/wp\/v2\/comments?post=1172080"}],"version-history":[{"count":0,"href":"https:\/\/www.europesays.com\/uk\/wp-json\/wp\/v2\/posts\/1172080\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.europesays.com\/uk\/wp-json\/wp\/v2\/media\/1172081"}],"wp:attachment":[{"href":"https:\/\/www.europesays.com\/uk\/wp-json\/wp\/v2\/media?parent=1172080"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.europesays.com\/uk\/wp-json\/wp\/v2\/categories?post=1172080"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.europesays.com\/uk\/wp-json\/wp\/v2\/tags?post=1172080"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}