OpenAI blamed a hacking event on its AI models gone rogue. Here is what to know

OpenAI blamed a hacking event on its AI models gone rogue. Here is what to know

FILE – The OpenAI logo is displayed on a cell phone in front of an image generated by ChatGPT’s Dall-E text-to-image model, Dec. 8, 2023, in Boston.

Michael Dwyer/AP


hide caption



toggle caption

Michael Dwyer/AP

ChatGPT maker OpenAI says it is still investigating the “unprecedented cyber incident” that led its artificial intelligence systems to break out of a testing environment and hack into another AI company.

OpenAI said Tuesday two of its most capable AI models were responsible for the cyberattack targeting AI startup Hugging Face. The incident is stirring debates over the need for stronger AI guardrails and the extent to which AI agents are capable of acting on their own.

Hugging Face said last week that it had detected an intrusion into its data processing systems that it suspected was caused by an AI agent acting on its own. But the New York-based startup said it wasn’t until this week that it learned OpenAI was responsible, and it worked with the larger company to contain what Hugging Face CEO Clément Delangue called “an attack unlike anything we’ve seen before.”

San Francisco-based OpenAI said its AI used stolen credentials and discovered a previously unknown vulnerability to access Hugging Face’s servers. It was working with reduced guardrails because it was supposed to be in an isolated testing environment known as a sandbox.

But it went to “extreme lengths to achieve a rather narrow testing goal,” finding ways to connect to the internet without human direction and “gain access to secret information that it could use to cheat the evaluation,” the company said.

Some experts say OpenAI is wrongly blaming the technology

University of Amsterdam social scientist Hannes Cools said the framing of the cyberattack as an AI agent acting on its own is an unnecessary anthropomorphization that takes some of the heat off the company.

“It is a human decision to switch off specific safeguards,” said Cools. “It’s not an AI that goes rogue in that sense. It followed specific instructions based on the prompt that was given to that AI system.”

Those instructions, according to OpenAI, called for using “complex attack paths” to test how well the AI could exploit a computer system.

Even so, other experts say the cleverness with which the AI models were able to cause problems with little human direction speaks to the dangers. OpenAI said the intrusion was caused by a combination of its AI models, including its newly released GPT‑5.6 Sol and an “even more capable” model that is still being tested internally.

Leave a Comment

Your email address will not be published. Required fields are marked *