How are companies, governments responding to the OpenAI hack?
OpenAI’s AI models hacked into another company, prompting calls for renewed scrutiny of safeguards for advanced AI systems. ChatGPT owner OpenAI has admitted an “unprecedented
OpenAI’s AI models hacked into another company, prompting calls for renewed scrutiny of safeguards for advanced AI systems. ChatGPT owner OpenAI has admitted an “unprecedented cyber incident” – two of its most capable artificial intelligence models hacked into another AI company on their own – stirring debates over the need for stronger technology guardrails. The company said its AI systems broke out of a testing environment and hacked startup Hugging Face. The startup had disclosed on July 16 that its servers were hacked by an unknown but sophisticated agent acting on its own. Here’s the latest on how companies, some governments and lawmakers have responded to the first such publicly disclosed cyberattack What has Hugging Face said? The company said in a statement that it discovered the breach through its own AI-assisted detection. “This one was different from anything we had handled before in one important way: it was driven, end to end, by an autonomous AI agent system,” it said. Following OpenAI’s disclosure that its models were involved in the breach, both sides started an ongoing joint investigation this week. Hugging Face cofounder Clement Delangue said his startup turned to the open-source GLM-5.2 model from Chinese company Zhipu AI to analyse data from the hack after leading US AI models declined the task, unable to distinguish between a defender and an attacker.
Hugging Face’s staff “strongly believe there was no malicious intent on their part”, Delangue added, referring to OpenAI. “So proud of our security team! They caught, contained & publicly disclosed an attack unlike anything we’ve seen before, and did it at record speed,” he wrote on X. “This is day one for cybersecurity in the age of agents & we’re all learning that secrecy is not the answer & that all defenders (not just a few selected ones) everywhere need more powerful models without restrictions, especially open ones!” Delangue added. How has the UK government reacted to this? The AI Security Institute (AISI), a United Kingdom government-backed body established in 2023 to assess the risks posed by advanced AI systems, said this week that an AI model it was investigating also went rogue and attempted to hack its testing systems. The AISI did not disclose the company behind the AI model and added that no damage had been done to its own infrastructure. It has since taken steps to make its systems more secure. Its latest evaluations also found that every frontier AI model it tested attempted to cheat during capability assessments, highlighting a growing challenge for AI safety as models become more capable.
