Just_Super via Getty ImagesWith the revelation that OpenAI's GPT-5.6 Sol and another unreleased AI model acted independently to launch more than 17,000 attacks and compromise Hugging Face’s infrastructure, it is now even more imperative for enterprises to ensure they have effective security measures in place.OpenAI disclosed on July 21 that during an internal evaluation, GPT-5.6 Sol and another pre-release model gained access to private information such as datasets and benchmarks in the open source AI platform by escaping their sandboxed environment and accessing the open internet.While the Hugging Face security team was able to detect and stop the models’ activity, the swarm attack is another reminder to enterprises that AI agents can quickly access information they are not supposed to, and that enterprises must take precautions to protect their sensitive data.“They should reassess what qualifies as satisfactory cybersecurity protection right now because clearly the most sophisticated models … can breach organizations, even if they’re told explicitly that that’s not what they ought to be doing,” said Michael Bennett, associate vice chancellor for data science and AI strategy at University of Illinois Chicago. He said that, based on what happened with the OpenAI models, even an organization as sophisticated as OpenAI was unable to keep the models within the bounds of its cybersecurity systems.Related:Startup Focused on Enterprise AI Security Valued at $1.2 billionHow Enterprises Should RespondSo, for enterprises, the best thing to do is to try to ensure that their in-house and third-party cybersecurity experts anticipate similar exploits.“Confirming with their insurers as well [is important] to make sure that they’re covered for exploits that could be reasonably anticipated as a result of what we know is now possible,” Bennett said.He added that if an enterprise is unsure if it is doing everything it needs to do to keep its organization safe from such attacks, it might need to reconsider where it stores its data.“They might consider taking out of the cloud the most sensitive data, the most important information that they have out there,” Bennett said.Moreover, enterprises should follow the recommendations of AI cybersecurity experts, such as regularly scanning their systems, especially those with large volumes of valuable data in the cloud. They should also be regularly red-teaming and testing the efficiency of their cybersecurity measures and practices, while also following best practices from government agencies such as NIST (National Institute of Standards and Technology), Bennett continued.Related:Mythos Scaled to 150 Organizations in 15 CountriesMoving ForwardWhile both OpenAI and Hugging Face are still investigating the exploit, it remains an open question whether the two-week quarantine period for GPT-5.6 was sufficient.For Bennett, the fact that only one instance was reported suggests there could have been others if the model had not been placed in quarantine.“We don't know what would have happened had that kind of stalled release for preview by government agencies not happened,” he said. “There might have been other attacks, a greater number of them with more significant consequences, maybe even of agencies and enterprises that are more critical to our day-to-day lives or to the day-to-day lives of most of us.”Therefore, given the rogue model swarm attack, government agencies should continue monitoring delayed rollouts of these models so they can be evaluated. For enterprises, the main response is to follow best-practice guidelines from cyber experts and insurers.About the AuthorNews Writer, AI BusinessEsther Shittu has covered AI technologies and industry trends since 2021. As co-host of the Targeting AI podcast, she talks with experts, thought leaders and practitioners exploring critical AI developments. Before AI Business, she wrote for SearchEnterpriseAI, the New York Daily News, Bklyner and the Brooklyn Daily Eagle. When she's not diving deep into the world of AI, she spends her time on passion projects and raising her three daughters.
What the OpenAI-Hugging Face Hack Means for Enterprises
Full Article
Original Source
Read the full article at Aibusiness →KhanList aggregates and links to publicly available news content. We do not host full articles from third-party sources. Always verify important information with original sources.