Business
OpenAI failed to recognize autonomous agent attack for days: report
Maria Bartiromo discusses an OpenAI experimental AI agent that broke containment and hacked an AI platform.
OpenAI didn’t catch an autonomous breach of another artificial intelligence (AI) company by one of its advanced AI models for a week, and not until after the FBI had been contacted by the hacked company, according to a report.
On Tuesday, OpenAI announced the breach of AI company Hugging Face that happened during one of OpenAI’s internal reviews of several of its models, including GPT-5.6 Sol, calling it an “unprecedented cyber incident.”
“The primary lesson from this incident is that model security and safety must keep pace with rapidly advancing capabilities,” the company said. “We are strengthening the containment, monitoring, access controls, and evaluation practices used during model development.”
The hack of Hugging Face started on July 11, and continued until July 13, Thomas Wolf, Hugging Face’s co-founder, told Reuters.
TRUMP LAUNCHES GOLD EAGLE TO HUNT CYBER FLAWS WITH AI
OpenAI revealed on Tuesday one of its AI models had autonomously hacked another company’s infrastructure. (Omar Marques/SOPA Images/LightRocket via Getty Images, File / Getty Images)
It was several days before OpenAI realized its agent was behind the attack and the two companies didn’t communicate for the first time until July 20, four people, including Wolf, told the outlet.
OpenAI often runs simultaneous model tests, which can make it difficult for employees to monitor everything, four people told Reuters.
Hugging Face told Reuters it is preparing a public timeline of the hack.
According to OpenAI, the incident took place during an internal evaluation designed to measure its AI models’ advanced cyber capabilities. Researchers disabled some built-in safety safeguards and ran the models in an isolated testing environment with limited internet access.
OpenAI said the models exploited an unknown software flaw to access the internet, then breached Hugging Face’s systems in an apparent attempt to find answers to a cybersecurity benchmark.
Hugging Face said it was preparing a timeline of the hack. (Jakub Porzycki/NurPhoto via Getty Images, File / Getty Images)
OpenAI said it’s now implementing stricter security controls while vulnerabilities are patched and strengthening safeguards around future AI training and evaluations.
It wasn’t until July 16 after Hugging Face wrote in a blog post that it had been hacked by an “autonomous AI agent system” that OpenAI realized one of its agents was the source, two people told Reuters.
This was a week after the responsible agent first attempted to break out of its OpenAI testing environment.
And by the time OpenAI contacted Hugging Face about the attack, they had already contacted the FBI.
OpenAI told Reuters there were several inaccuracies in its reporting but didn’t respond when asked for specifications.
OpenAI CEO Sam Altman publicly announced the attack on Tuesday. (Sean Gallup/Getty Images, FIle / Getty Images)
OpenAI shared this statement with FOX Business: “We recognize there are a lot of questions and speculative details circulating related to the Hugging Face incident. This is an unprecedented incident, and we think it marks an important moment for AI safety. We are still conducting a thorough review along with external advisors and with oversight from our Safety and Security Committee. Once the review is complete, we plan to publish a technical report of our learnings in the coming weeks.”
The FBI told FOX Business that it declined to comment.
FOX Business has also reached out to Hugging Face.
In an X post this week, Hugging Face co-founder and CEO Clem Delangue addressed the incident after OpenAI CEO Sam Altman announced the hack.
OpenAI said one of its AI models compromised another company’s systems during internal testing, prompting a joint investigation with AI startup Hugging Face. (Reuters/Dado Ruvic, File / Reuters)
“We suspected last week’s cyberattack might have come from a frontier lab, given the sophistication of the agent. Turns out it did!” Delangue wrote.
CLICK HERE TO DOWNLOAD THE FOX NEWS APP
He added, “We’ve spent the past 24 hours working closely with the @OpenAI team (thanks!), and we strongly believe there was no malicious intent on their part. It’s quite mind-blowing that all of this happened autonomously! The investigation is ongoing, and we’ll share more learnings from what might be the first incident of its kind!”
FOX Business’ Michael Sinkowitz contributed to this report.
You must be logged in to post a comment Login