# OpenAI’s rogue AI acted ‘like uni students after too many beers’

> Source: <https://www.cityam.com/openais-rogue-ai-acted-like-uni-students-after-too-many-beers/>
> Published: 2026-09-21 13:56:30+00:00

# OpenAI’s rogue AI acted ‘like uni students after too many beers’

The rogue AI agents behind OpenAI’s unprecedented Hugging Face cyber attack behaved like “university students who’ve had too many beers”, a cyber expert told *City AM*, saying the breach was more a triumph of persistence than intelligence.

Charl van der Walt, global head of security research at Orange Cyberdefense, said that despite the alarm triggered by [OpenAI’s models](https://openai.com/index/hugging-face-incident-and-the-road-ahead/) autonomously breaking out of a controlled test and attacking another company, businesses still have more to fear from people wielding AI than machines acting alone.

“The way we describe to ourselves the Hugging Face incident was that the AIs behaved like a bunch of university students who’ve had too many beers,” van der Walt told *City AM.*

“They were uninhibited, they were extremely enthusiastic, they were falling over each other and over themselves, and they made a big mess of it”.

OpenAI revealed in July that models being tested on their cyber capabilities had escaped their intended environment and compromised Hugging Face, the open-source AI platform, after effectively trying to cheat their way through a cyber security benchmark.

Rather than completing the test as intended, the agents inferred that Hugging Face could contain information that would help them solve it and set about gaining access.

Subsequent investigations found the attack went further than initially disclosed. The agents gained extensive access to Hugging Face’s infrastructure and compromised several third-party accounts and services along the way.

The incident quickly became a test case for the dangers of increasingly autonomous AI, prompting [scrutiny from the UK’s AI Security Institute](https://www.cityam.com/uk-government-probes-openai-breach-after-model-autonomously-hacked-rival/) and regulators. But van der Walt said the agents had not invented fundamentally new methods of attack. “They persisted in, rather than out-thought, the defenders”, he said.

“Every single thing that those AIs did in those instances has been done before, could have been defended against, is understood. That’s not foundationally different”.

He added: “I don’t think that businesses have got more to worry about from AIs than from people using AI. A capable human operator with a good AI and a good harness is probably the bigger risk still”.

## Faster than humans, rather than smarter

The bigger change for businesses, van der Walt said, is not what AI can do but how quickly and relentlessly it can do it.

“The challenge I think for defenders is going to be volume and speed. It’s coming at you so fast now”, he said.

Security teams once measured response times in days and later hours. Autonomous systems are increasingly forcing them to operate on far shorter timescales.

Van der Walt described AI itself as revolutionary technology, but its effect on cyber security as an “evolution, not a revolution”. “What does change is scale and persistence”, he said.

AI can repeatedly probe huge numbers of systems for weaknesses without tiring, meaning relatively conventional hacking techniques could become far more potent when deployed at scale.

“If you have enough computers to attack… that scaling nature of it suggests, I think, that AI is going to find all the cracks”.

Schools, charities and small businesses may lack the people and resources to respond to attacks arriving at a speed and volume previously reserved for sophisticated cyber operations. AI could also lower the technical barrier for would-be hackers, allowing less experienced attackers to carry out tasks that once required specialist expertise.

But van der Walt cautioned against assuming it would automatically make cyber crime cheaper, pointing to the significant computing costs involved in running powerful models through millions of tokens.

## The rogue AI problem

Where Hugging Face does break new ground, van der Walt said, is in the question of responsibility.

“What’s complicated about the rogue AIs is liability”, he said. “So far, institutionally, it doesn’t feel to me like that question has been addressed in any kind of meaningful way”.

As businesses hand AI agents access to more sensitive data and internal systems, regulators will increasingly have to decide where responsibility sits when a machine takes an unauthorised action without a human explicitly telling it to do so.

Van der Walt said liability would ultimately need to be attached to an organisation or individual, adding that regulators and political leaders needed to consider “how do we regulate in the era of autonomy?”

In the case of the Hugging Face incident, the agents may have operated autonomously and at extraordinary speed, but the vulnerabilities they exploited were familiar ones.
