“ChatGPT” creator announced that its intelligent agents – AI bots capable of acting autonomously after initial human instructions – were tested in a controlled environment. Nevertheless, they managed to find system vulnerabilities and “escape” from it.
Read more New restrictions for Russians who converted rubles into cryptocurrencies
Having escaped the testing environment, the agents targeted “Hugging Face” – one of the world’s largest AI model sharing hubs – and gained access to some of the company’s internal systems.
“OpenAI” itself called this incident “unprecedented” and states it is cooperating with “Hugging Face” to clarify the details of the event and strengthen safeguards, according to bbc.com.
Failed the “sandbox” test
Gina Neff, head of the Minderoo Centre for Technology and Democracy at Cambridge University, told BBC Radio that such security tests (so-called “sandboxes”) are designed as a completely safe environment for exploring AI capabilities.
“It seems that in this case, ‘OpenAI’ did not create a sufficiently secure space,” the expert added.
Instead of obeying the rules, the AI agents themselves generated a cyberattack against the testing environment, found a security vulnerability, and escaped through it.
Having broken free, they identified the “Hugging Face” platform as a potential source for the information they were looking for to complete their test task, and attempted to hack into it.

Autonomous attacks – already a reality
In its initial statement, “Hugging Face” indicated that it is still assessing whether customer and partner data might have been affected during the attack, but all detected vulnerabilities have already been patched.
“Autonomous, AI-driven attack tools are no longer just a theory,” the company representatives emphasized.
According to them, to protect online platforms, it is now necessary to combat attacks using the same artificial intelligence so that defense systems can react in time.
This incident raises new questions about the capabilities of advanced AI systems and the reliability of existing safeguards.
Spencer Starkey, a representative of the cybersecurity company “SonicWall,” noted that it is time for organizations to fundamentally review their defenses.
“The uncomfortable truth is that too many organizations are still defending at ‘human speed’ when attackers have already switched to ‘machine speed’,” the expert warned.
However, security expert Jake Moore from “ESET” did not rule out marketing motives.
According to him, this “OpenAI” announcement could be a way to demonstrate the capability of its algorithmic models, in response to growing attention to competitors, such as the recently introduced powerful AI model “Kimi K3” from Chinese startup “Moonshot.”