22 July 2026
OpenAI has revealed some of its most advanced AI models went rogue and hacked a start-up after it lost control of them during a security test.
The ChatGPT-maker said its agent – an AI system which can operate alone after some human instruction – was being tested in a controlled environment, but found vulnerabilities and managed to escape.
They targeted Hugging Face, one of the world’s largest hubs for sharing AI models, gaining access to some internal company systems.
OpenAI said the incident was “unprecedented”, and it was conducting an investigation alongside Hugging Face, whose boss Clement Delangue said in a post on X it was “mind-blowing that all of this happened autonomously”.
“The investigation is ongoing, and we’ll share more learnings from what might be the first incident of its kind,” Delangue added.
Gina Neff, head of the Minderoo Centre for Technology and Democracy at the University of Cambridge, told BBC Radio 4’s Today programme that the security tests – called sandboxes – are “supposed to be secure environments where you can see what the models are capable of”.
“In this case, it looks like OpenAI didn’t make a secure enough sandbox,” she added.
Instead, the agents created their own cyber-attack against the sandbox itself, finding a vulnerability which allowed them to escape.
Once outside, the AI identified Hugging Face as a likely source of the answers they were seeking in the test, and tried to gain access.
Neil Lawrence, Professor of machine learning at Cambridge University, called it an “impressive feat”, but cautioned it “falls well within the known capabilities of the current generation” of high-powered AI models.
He pointed out that OpenAI is looking to list itself on the stock market, and faces intense pressure from rival firm Anthropic, which has made headlines with its own powerful AI tool, Mythos.
source: BBc



