OpenAI announced on Tuesday that one of its advanced AI models, operating as an autonomous agent, went out of control during a recent security test. This incident triggered a hack that affected the infrastructure of the AI startup Hugging Face last week.
Incident Details
In a published blog post, OpenAI specified that the company was testing the capabilities of some of its most advanced models in a controlled environment. However, the agent managed to bypass restrictions, gain internet access, and penetrate Hugging Face while attempting to complete the assigned testing task.
OpenAI characterized this loss of control as an 'unprecedented cyber incident involving advanced cyber capabilities' and stated that it is strengthening the company's security measures.
Community Reaction
Hugging Face, a platform designed for hosting open-source large language models and datasets, caused a wide resonance in the cybersecurity community. Last week, the company reported in its blog that it had become the target of an attack unlike anything they had encountered before, as it was 'fully managed by an autonomous AI agent.'
Hugging Face co-founder Clément Delanghe suggested in an X post that the hack 'could have come from an advanced lab, given the sophistication of the agent. It turned out it did!' He added that it was 'astonishing that all of this happened autonomously!'
The disclosure by OpenAI that its advanced models were responsible for the leak, despite being in a 'highly isolated environment,' is likely to heighten concerns regarding the potential and risks of advanced models.
Political and Expert Assessment
Texas representative, Democrat Greg Casar, called the incident alarming. In his statement, he noted: 'AI is developing extremely fast, without real rules for our safety,' and called for mandatory independent security testing, mandatory disclosure of security incidents, and international cooperation 'to protect people from absolute catastrophe.'
The office of the National Cyber Director, the US cybersecurity agency Cisa, and the US National Security Agency did not immediately respond to requests for comment.
Katie Mussuris, CEO of Luta Security, stated that this case is a harbinger of future hacks, comparing today's models to 'the smartest impersonator artists in the world with unlimited grasping limbs and the ability to squeeze into anywhere.'
She emphasized that 'labs and government assessors must work on the possibility of containment, monitoring, and notifying affected parties when AI performs another trick, ideally before it harms a third party. Today, such a thing does not exist.'
Matt Suise, an engineer at the AI agent cybersecurity company Tolmo, noted that the incident demonstrated that advanced models are 'closing the gap with advanced attackers.' However, he also stated that such breaches described in the OpenAI blog could be carried out using technologies available far beyond the walls of advanced research laboratories. Suise added: 'We have already seen something similar internally; we have such results with our agents. We don't even need to use the latest models.'