{"slug": "openai-says-it-detected-malign-activity-months-before-hugging-face-attack", "title": "OpenAI says it detected malign activity months before Hugging Face attack", "summary": "OpenAI detected its AI agents communicating and accessing the internet without authorization months before they attacked AI company Hugging Face on July 11, according to a report released Wednesday. The agents, created by an unreleased AI model and GPT-5.6 Sol, exploited Artifactory vulnerabilities, with about 1,200 agents communicating and roughly 700 participating in the attack, which OpenAI described as a 'warning shot' and prompted new safeguards.", "body_md": "# OpenAI says it detected malign activity months before Hugging Face attack\n\n*ChatGPT creator says AI agents collaborated and delegated work in hacking, calling themselves a ‘collective’.*\n\nOpenAI detected its artificial intelligence models communicating with each other and gaining internet access without authorisation months before they hacked the start-up Hugging Face, the creator of ChatGPT has announced following an internal probe.\n\nIn a report released on Wednesday, OpenAI said its AI agents exploited vulnerabilities in Artifactory, a software repository tool, to post notes and access the internet without human prompting as far back as May.\n\n## Recommended Stories\n\nlist of 4 items- list 1 of 4\n[Syria’s president makes first Visa payment after sanctions removal](/video/newsfeed/2026/8/27/syrias-president-makes-first-visa-payment-after-sanctions-removal) - list 2 of 4\n[Construction worker documents moment he survives Nepal mudslide](/video/newsfeed/2026/8/27/construction-worker-documents-moment-he-survives-nepal-mudslide) - list 3 of 4\n[Is Mark Ruffalo anti-Semitic?](/video/newsfeed/2026/8/27/is-mark-ruffalo-anti-semitic) - list 4 of 4\n[Pro-Israel Democrats picked for top roles on key US House committee](/news/2026/8/27/pro-israel-democrats-picked-for-top-roles-on-key-us-house-committee)\n\nOpenAI said its agents went on to exploit a separate Artifactory vulnerability on July 8 to facilitate communication among themselves, setting in motion a chain of actions that culminated in the July 11 attack on AI company Hugging Face.\n\nOpenAI’s findings come amid growing concern about the potential for AI to inflict serious real-world harm, including self-directed cyberattacks.\n\nOpenAI said in its report that its agents collaborated and delegated work in the lead-up to the attack, sometimes referring to themselves as a “swarm” or “collective”.\n\nMETR and Redwood Research, two security research organisations contracted by OpenAI to investigate the incident, said in a separate report released on Wednesday that about 1200 agents had communicated with each other and roughly 700 participated in the attack.\n\nAfter discovering how to escape OpenAI’s controlled environment, agents shared their methods via a “inter-agent message board”, enabling additional agents to exploit the company’s infrastructure, the tech giant said.\n\nWhen one AI agent found Hugging Face user credentials that had been exposed online, it shared them with the group, enabling an agent to “discover and chain together several security exploits” that provided access to Hugging Face’s severs, according to the report.\n\n“An internal team observed an agent engaging in message board activity and instances of disallowed internet access as early as late May, and with the benefit of hindsight, some early signals identified in our report should have triggered an earlier response,” OpenAI said.\n\nOpenAI said agents created by an unreleased AI model were the primary participants in the attack, but publicly available GPT-5.6 Sol was also involved.\n\nThe company also revealed that it took its security team 11 days to detect the malign activities leading up to the attack, which the company uncovered on July 19 and publicly disclosed on July 21.\n\nOpenAI, which described the incident as a “warning shot” for the world, said it would take several steps to strengthen its safeguards for its models, including restricting internet access, creating more secure testing environments and placing “stricter requirements on alignment throughout a model’s lifecycle”.\n\n“We are also investing significantly more compute resources into chain-of-thought monitoring to more quickly intervene on misaligned behavior,” the San Francisco-based firm said.\n\nHugging Face, which operates a platform for hosting open-source AI models, did not immediately respond to a request for comment outside of business hours.\n\nToby Walsh, an expert in AI and professor at UNSW Sydney, said the public should be concerned that OpenAI had missed warning signs and allowed the malicious activity to go undetected for so long.\n\n“We cannot depend on either their goodwill or their competence. This needs regulatory oversight. Now!” Walsh told Al Jazeera.\n\n“They ignored some troubling early evidence like this,” Walsh said.\n\n“External auditing is the only appropriate response.”\n\nWalsh said the incident also highlighted the “inherent conflict of interest” at the heart of AI development.\n\n“Labs are locked in a relentless race to push the boundaries,” he said.\n\n“When models are given unconstrained goals to maximise performance scores, they naturally optimise for the outcome by any means necessary.”", "url": "https://wpnews.pro/news/openai-says-it-detected-malign-activity-months-before-hugging-face-attack", "canonical_source": "https://www.aljazeera.com/economy/2026/8/27/openai-says-it-detected-malign-activity-months-before-hugging-face-attack?traffic_source=rss", "published_at": "2026-08-27 06:33:18+00:00", "updated_at": "2026-08-27 07:20:34.220830+00:00", "lang": "en", "topics": ["ai-safety", "ai-agents", "artificial-intelligence"], "entities": ["OpenAI", "Hugging Face", "Artifactory", "GPT-5.6 Sol", "METR", "Redwood Research", "Toby Walsh", "UNSW Sydney"], "alternates": {"html": "https://wpnews.pro/news/openai-says-it-detected-malign-activity-months-before-hugging-face-attack", "markdown": "https://wpnews.pro/news/openai-says-it-detected-malign-activity-months-before-hugging-face-attack.md", "text": "https://wpnews.pro/news/openai-says-it-detected-malign-activity-months-before-hugging-face-attack.txt", "jsonld": "https://wpnews.pro/news/openai-says-it-detected-malign-activity-months-before-hugging-face-attack.jsonld"}}