OpenAI cybersecurity models escape test environment, hack separate company systems

OpenAI cybersecurity models escape test environment, hack separate company systems

ByAARON GLICKJULY 23, 2026 18:36Updated: JULY 23, 2026 19:39Several experimental OpenAI artificial intelligence models escaped their test environment and hacked into a separate company's production systems, the ChatGPT developer said on Tuesday.According to the company, the AI models did so without any human instruction, performing the hack as they went to "extreme lengths" to achieve a testing goal.The company said that the models exploited a flaw in OpenAI's security system to access the internet, after which they hacked the AI platform Hugging Face."The models identified and chained vulnerabilities across OpenAI’s research environment and Hugging Face’s production infrastructure to obtain test solutions directly from Hugging Face’s production database," the company said."Our models spent a substantial amount of inference compute finding a way to obtain open Internet access, in pursuit of solving the evaluation problem," it added.Illustration of the Hugging Face AI in Paris, France, on June 2, 2026. (credit: Riccardo Milani / Hans Lucas / AFP via Getty Images)“We consider this incident to be an unprecedented cyber incident, involving state-of-the-art cyber capabilities, and are responding accordingly,” the company emphasized. “We are sharing preliminary findings at this stage to help defenders understand what happened and to help calibrate on what models are now capable of.”OpenAI noted that Hugging Face managed to detect and contain the AI models' actions.OpenAI's response to the security breach"As part of the investigation, we are implementing strict controls in infrastructure configuration at the cost of research velocity while the vulnerabilities are patched," the company stated. "We’ve responsibly disclosed the identified zero-day vulnerability in the internally hosted third-party software and are working with them [Hugging Face] to patch."The company cited Hugging Face CEO and co-founder Clem Delangue, who said her company was "grateful" for the opportunity to collaborate with OpenAI."This incident, possibly the first of its kind, proves a point we've long believed: AI safety won't be solved by any single company working in secret," said Delangue. "It will be solved in the open, collaboratively, with broad access to AI for every defender, everywhere."OpenAI added that it is "improving and adding stronger protections around future training and evaluations," with Hugging Face being given "trusted access" to its advanced AI models as part of efforts to develop defenses against them."The primary lesson from this incident is that model security and safety must keep pace with rapidly advancing capabilities," it said. "We are strengthening the containment, monitoring, access controls, and evaluation practices used during model development."Notably, the company acknowledged that advanced AI models can "discover and exploit novel attack paths in real-world systems without source-code access.""Advanced cyber capabilities must be developed alongside stronger safeguards and defensive tools," warned OpenAI."We are using these capabilities to continue strengthening protections around infrastructure configuration and model evaluation environments," the company continued. "We will share our findings and best practices as we learn."OpenAI concluded its statement by requesting that other "defenders" apply for "trusted access," so they may experiment with the company's advanced AI models to develop better responses to such incidents in the future.Trump tech adviser was briefed on OpenAI incidentUS President Donald Trump's top tech adviser Michael Kratsios was briefed on OpenAI's model going rogue and is monitoring the situation, a White House official told Reuters on Thursday.The OpenAI incident follows statements earlier on Thursday by US Secretary of State Marco Rubio, who asked diplomats to push back against talk of a "kill switch" in American technology products, according to a recent cable reviewed by Reuters.The comments followed the White House's short-lived decision to prevent foreigners from accessing some of the most advanced US artificial intelligence models developed by Anthropic, Mythos and Fable, on national security grounds.Reuters contributed to this report.Follow us on Google

Original Source

Read the full article at Jpost →

KhanList aggregates and links to publicly available news content. We do not host full articles from third-party sources. Always verify important information with original sources.