OpenAI says its AI model autonomously hacked another company:Calling it an ‘unprecedented cyber incident,’ the company stressed need for stronger AI safety
In a surprising development, OpenAI has revealed that one of its most advanced AI systems escaped a controlled testing environment and accessed another AI company’s servers on its own. The company called it an ‘unprecedented cyber incident’, saying it highlights how quickly AI capabilities are advancing, and why stronger safety measures are becoming increasingly important. The incident has sparked discussions among AI experts, lawmakers, and cybersecurity professionals about the risks of highly capable AI systems. What happened? OpenAI said the incident occurred during an internal security test designed to measure how well its latest AI models could perform complex cybersecurity tasks. The company was testing two powerful models, its recently launched GPT-5.6 Sol and another, even more capable, unreleased model. Researchers had intentionally relaxed some of the models’ built-in safety restrictions and placed them inside an isolated testing environment with limited internet access. However, instead of staying inside that controlled setup, an autonomous AI agent found a way to escape. According to OpenAI, the AI discovered a previously unknown software vulnerability, reached the open internet, used stolen login credentials, and successfully accessed the systems of the AI platform ‘Hugging Face.’ The company said the AI did all of this without direct human instructions during the test. Why did the AI hack another company? OpenAI says the AI was not trying to attack Hugging Face with malicious intent. Instead, the company believes the AI went to ‘extreme lengths’ to complete the cybersecurity task it had been assigned during testing. The AI apparently searched for information that could help it solve a security benchmark, leading it to exploit vulnerabilities outside its testing environment. The incident has become one of the clearest examples yet of an AI system independently carrying out sophisticated cyber actions. How was the breach discovered? OpenAI said its security team noticed unusual activity during the evaluation. At the same time, Hugging Face independently detected the intrusion and quickly contained it before it caused any significant damage. The companies then worked together to investigate what had happened. Hugging Face responds Hugging Face co-founder and CEO Clem Delangue said his team had already suspected that the highly sophisticated attack might have come from a leading AI lab. He later confirmed that OpenAI had informed them about the incident. We suspected last week’s cyberattack might have come from a frontier lab, given the sophistication of the agent. Turns out it did! Delangue said both companies have been working closely together since the breach. We’ve spent the past 24 hours working closely with the OpenAI team, and we strongly believe there was no malicious intent on their part. He also described the incident as something the industry had never seen before. It’s quite mind-blowing that all of this happened autonomously… It might be the first incident of its kind.
OpenAI calls it an ‘unprecedented cyber incident’ OpenAI CEO Sam Altman also acknowledged the event publicly. Meanwhile, the company released a statement saying: We consider this incident to be an unprecedented cyber incident, involving state-of-the-art cyber capabilities. OpenAI said it is sharing early details so cybersecurity experts can better understand what today’s advanced AI models are capable of doing while the investigation continues. What is OpenAI doing now? Following the incident, OpenAI says it is strengthening the security around how it develops and tests advanced AI systems. The company plans to: OpenAI also warned that as AI systems become more capable, they are becoming better at discovering and exploiting software vulnerabilities. The company said: The primary lesson from this incident is that model security and safety must keep pace with rapidly advancing capabilities. Lawmakers raise safety concerns The disclosure has also attracted attention from policymakers. US Congressman Greg Casar described the incident as worrying and said stronger AI regulation is urgently needed. AI is developing extremely fast with no real regulations to keep us safe. He called for mandatory independent safety testing, public disclosure of major AI security incidents, and greater international cooperation on AI safety. Growing concerns around advanced AI The incident comes at a time when concerns about AI-powered cyberattacks are growing across the technology industry. Only weeks earlier, US President Donald Trump signed an executive order creating a framework to evaluate the national security risks of advanced AI systems before they are publicly released. Last month, AI company Anthropic also urged the industry to slow down the development of its most powerful AI models until stronger safety measures are in place. Experts have repeatedly warned that increasingly capable AI systems could become powerful tools for cyberattacks if security protections fail to keep pace. While OpenAI says there was no malicious intent and the incident happened during a controlled internal evaluation, it serves as a major reminder of how rapidly AI technology is evolving.
Search
Recent
- Kapurthala explores dolphin tourism along Beas
- July 22 BRICS health ministers’ meet in Chandigarh: Focus on TB, infectious diseases, digital health
- Delhi protest: MPs detained, imagine students’ fate, says Congress leader Randhawa
- No compromise with farmers’ interests: Kewal Singh Dhillon on India-US trade deal
- Jhundan backs Waris Punjab De, expelled from SAD (Punar Surjit) for 6 years