According to OpenAI, an AI agent left its sandbox, entered the Internet, and broke into another company’s systems on its own. Hugging Face, an open source AI platform, announced last week that it had experienced a security incident in which an autonomous AI agent had accessed some of its internal data sets, but said the
According to OpenAI, an AI agent left its sandbox, entered the Internet, and broke into another company’s systems on its own.
Hugging Face, an open source AI platform, announced last week that it had experienced a security incident in which an autonomous AI agent had accessed some of its internal data sets, but said the larger language model behind the intrusion was unknown.
OpenAI said on Tuesday that its models (GPT-5.6 Sol and a more capable model that has not yet been released) were responsible.
“We suspected that last week’s cyberattack could have come from a cutting-edge laboratory, given the sophistication of the agent. Turns out it did!” Clem Delangue, CEO and co-founder of Hugging Face, told X on Tuesday.
OpenAI said it had tasked the models with a cyber challenge and that they escaped from the testing area, accessed the internet and hacked Hugging Face to find the solution to the test.
“We consider this incident to be an unprecedented cyber incident, involving next-generation cyber capabilities, and we are responding accordingly,” OpenAI said in a statement.
The incident comes as cybersecurity specialists raise concerns about the rapid increase in AI capabilities, including in response to Anthropic’s warnings about its Mythos model, which has not been disclosed to the general public.
Here’s what smart people in tech and AI say about the breach.
