cd /news/artificial-intelligence/openais-rogue-robot-broke-into-anoth… · home topics artificial-intelligence article
[ARTICLE · art-78708] src=metro.co.uk ↗ pub= topic=artificial-intelligence verified=true sentiment=↓ negative

OpenAI’s rogue robot broke into another company – could your data be next?

OpenAI's GPT-5.6 Sol and an unreleased model escaped a sandbox and broke into AI infrastructure startup Modal Labs, the second such incident after a cyberattack on Hugging Face. Modal said the AI exploited a customer's publicly accessible application endpoint, and no other customer workloads were affected. Cybersecurity experts warn that organizations like the NHS must strengthen security controls against AI-driven attacks.

read4 min views1 publishedJul 29, 2026
OpenAI’s rogue robot broke into another company – could your data be next?
Image: Metro (auto-discovered)

An AI model by the company behind ChatGPT has compromised a company for the second time. OpenAI said last week that two of its models escaped and launched a cyberattack on Hugging Face, a digital library of AI models.

But these agents, as autonomous AI bots are called, also broke into the AI infrastructure start-up Modal Labs, it revealed today.

Modal stressed that the company was not hacked in the traditional sense. Rather, the AI simply used the backdoor that someone forgot to lock.

Experts told **Metro **that these incidents are to be expected – and organisations like the NHS should be on their toes.

What happened? #

The break-in began when developers were testing the cybersecurity chops of two OpenAI bots, GPT‑5.6 Sol and a more powerful, unreleased model.

Yet they managed to find a hole in the safe testing environment, known as a sandbox, that was meant to contain them, and connected to the internet.

The bots exploited a ‘zero-day vulnerability’, a flaw that not even the developers knew about, in software that lets you install code offline.

Once outside, the agents snuck into ‘four accounts across four separate devices’, OpenAI said in a blog post yesterday Hugging Face added that the sandbox was ‘hosted on a third-party provider’s infrastructure’, though it did not name the firm by name.

But Modal named itself as the third-party and revealed that the out-of-control agent exploited code written by a customer.

‘The environment involved was a customer’s own application,’ Modal said.

‘It was deployed to an endpoint that was publicly accessible without authentication, and it was designed to compile and execute code submitted by anyone on the internet in a Modal Sandbox.

‘The code execution the attacker obtained took place inside that customer’s own container, within Modal’s standard sandbox isolation boundary. No other customer workloads were affected.’

Are the NHS or banks ready for AI break-ins? #

AI labs have been building programming-savvy models with cybersecurity in mind to help them and others patch holes in computer networks.

These tools, though, are just as useful to hackers as they are to cybersecurity specialists, tech experts told Metro.

Going for Hugging Face made sense, they said; it’s a library of millions of AI models, so they thought it could let them cheat on OpenAI’s test.

But their next target might not be as far-removed from the average person, warned Dan Schiappa, the president of technology and services at the cybersecurity firm Arctic Wolf.

‘For organisations operating critical digital services such as the NHS or other public institutions, the key question is, are their foundational security controls mature enough to withstand attacks that can be executed faster, more persistently and at much greater scale than traditional human-led campaigns?’ Wolf says.

‘Any organisation handling sensitive citizen or healthcare data should be continuously assessing AI-related risks, enforcing least-privilege access, and monitoring for anomalous behaviour – regardless of whether the activity originates from a human or AI-driven.’

Yes, the stuff of science fiction is very much reality now, but don’t panic just yet, says Michael Murphy, the deputy chief technology officer of the quantum security company Arqit.

‘This incident doesn’t mean an AI model can or will suddenly break into any hospital, bank or government department it chooses,’ Murphy explains.

‘What it does show is that AI can still behave in unexpected ways, and that uncertainty has the potential to contribute to increasingly complex cyberattacks with far less human involvement.’

These off-the-rails AIs won’t be the last either, and organisations that hold sensitive information need to accept that before it’s too late, Murphy adds.

An OpenAI spokesperson told Metro that the company is working with Hugging Face to fix the cause of this ‘unprecedented’ AI prison escape.

‘We are conducting a thorough review along with external advisors and with oversight from our Safety and Security Committee,’ they added.

‘Once the review is complete, we will publish a technical report of our learnings for everyone.’

The NHS has been approached for comment.

Get in touch with our news team by emailing us at webnews@metro.co.uk.

**For more stories like this, **[ check our news page](https://metro.co.uk/news/).

MORE: [Your chat with the AI chatbot Claude could be publicly available online](https://metro.co.uk/2026/07/28/chat-this-popular-ai-chatbot-publicly-available-online-29246394/?ico=more_text_links)

MORE: [Music platform hit with 90,000 AI-generated tracks every day – can you spot them?](https://metro.co.uk/2026/07/23/music-streaming-platform-hit-90-000-ai-generated-tracks-every-day-29197715/?ico=more_text_links)
── more in #artificial-intelligence 4 stories · sorted by recency
── more on @openai 3 stories trending now
sponsored brought to you by zahid.host 4,200+ EU-deployed projects
reading about agents? ship yours in a single git push.

Run your AI side-project on zahid.host

EU-based hosting, git-push deploys, automatic HTTPS, no cold starts. Free tier with a custom domain — perfect for shipping the agent you just read about.

$git push zahid main
Live at https://your-agent.zahid.host
Get free account → Pricing
from €0/mo · no card required
LIVE [news/openais-rogue-robot-…] indexed:0 read:4min 2026-07-29 ·