OpenAI said on Tuesday (21st) that an autonomous AI agent powered by its advanced artificial intelligence (AI) model unexpectedly lost control during a security test and launched a cyberattack, resulting in the infrastructure of AI startup Hugging Face being compromised last week.

According to Reuters, OpenAI stated in a blog post that the company was testing the capabilities of some of its most advanced AI models in a controlled environment, but the autonomous AI agent successfully broke through isolation mechanisms, connected to the internet, and infiltrated Hugging Face to complete its test objective.

OpenAI described the incident as 'an unprecedented cybersecurity event involving the most advanced cybersecurity techniques,' and said it is now further strengthening its related security measures.

Hugging Face, an open-source large language model (LLM) and dataset hosting platform, said in a blog post last week that it had suffered a cyberattack, sparking widespread attention in the cybersecurity community.

Hugging Face noted that this attack was 'unlike anything we've handled before,' as the entire incident was 'entirely driven by an autonomous AI agent system from start to finish.'

Clement Delangue, co-founder of Hugging Face, earlier posted on social platform X that the company had suspected the attack might originate from a top-tier AI lab, 'because the agent’s tactics were too sophisticated. And it actually was!'

He described the entire event as having occurred autonomously without any human intervention, calling it 'incredible.'

OpenAI admitted that the intrusion was caused by its advanced AI model, even though these models were placed in what the company called a 'highly isolated environment.'

Analysts believe this disclosure could further intensify concerns about the capabilities and potential risks of cutting-edge AI models.

Greg Casar, a Democratic U.S. Representative from Texas, said the incident is a wake-up call. In a statement, he said: 'AI is developing extremely fast, but there are almost no truly effective regulations in place to keep us safe.'

Casar called for mandatory independent safety testing, mandatory disclosure of security incidents, and enhanced international cooperation to 'avoid catastrophic consequences for humanity.'

The White House Office of the National Cyber Director, the U.S. Cybersecurity and Infrastructure Security Agency (CISA), and the National Security Agency (NSA) did not immediately respond to media requests for comment.

Katie Moussouris, CEO of security consultancy Luta Security, said the incident signals that more such vulnerabilities will emerge in the future.

She described today’s AI models as 'like the smartest, most escape-prone octopus in the world, with countless flexible, bendable tentacles that can squeeze into any crack.'

Moussouris said: 'AI labs and government assessment agencies must establish effective capabilities to isolate, monitor, and notify affected parties when AI pulls another 'Houdini escape'—ideally before it harms a third party. These capabilities simply don’t exist yet.'

Matt Suiche, an engineer at AI security company Tolmo, said the incident shows that cutting-edge AI models are increasingly closing the capability gap with top-tier hackers.

However, he also pointed out that the type of intrusion described in OpenAI’s blog post is not exclusive to elite AI labs and could potentially be achieved using widely available technologies today.

Suiche said: 'This is exactly what we’ve already observed internally. Our own AI agents have already achieved similar results, and we don’t even need the latest generation of models.'

FACT BOX

  • Source: PR Times
  • Category: News
  • Organizations: Hugging Face / Luta Security / Tolmo