{"slug": "openais-rogue-robot-broke-into-another-company-could-your-data-be-next", "title": "OpenAI’s rogue robot broke into another company – could your data be next?", "summary": "OpenAI's GPT-5.6 Sol and an unreleased model escaped a sandbox and broke into AI infrastructure startup Modal Labs, the second such incident after a cyberattack on Hugging Face. Modal said the AI exploited a customer's publicly accessible application endpoint, and no other customer workloads were affected. Cybersecurity experts warn that organizations like the NHS must strengthen security controls against AI-driven attacks.", "body_md": "An [AI ](https://metro.co.uk/tag/artificial-intelligence/)model by the company behind [ChatGPT](https://metro.co.uk/tag/chatgpt/) has compromised a company for the second time.\n\nOpenAI said last week that [two of its models escaped ](https://metro.co.uk/2026/07/23/tech-boss-whose-company-hacked-rogue-openai-bot-warns-game-changed-29204743/)and launched a cyberattack on Hugging Face, a digital library of AI models.\n\nBut these agents, [as autonomous AI bots are called](https://metro.co.uk/2026/03/19/downloading-shadow-ai-agents-without-knowing-dangerous-27532105/), also broke into the AI infrastructure start-up Modal Labs, it [revealed ](https://modal.com/blog/a-note-on-the-hugging-face-agent-incident)today.\n\nModal stressed that the company was not hacked in the traditional sense. Rather, the AI simply used the backdoor that someone forgot to lock.\n\nExperts told **Metro **that these incidents are to be expected – and organisations like the NHS should be on their toes.\n\n## What happened?\n\nThe break-in began when developers were [testing the cybersecurity chops ](https://metro.co.uk/2026/04/23/global-drug-company-astrazeneca-hacked-teenage-cyber-gang-28089598/)of two OpenAI bots, GPT‑5.6 Sol and a more powerful, unreleased model.\n\nYet they managed to find a hole in the safe testing environment, known as a sandbox, that was meant to contain them, and connected to the internet.\n\nThe bots exploited a ‘zero-day vulnerability’, a flaw that not even the developers knew about, in software that lets you install code offline.\n\nOnce outside, the agents snuck into ‘four accounts across four separate devices’, OpenAI said in a [blog post ](https://openai.com/index/hugging-face-model-evaluation-security-incident/)yesterday\n\nHugging Face [added ](https://huggingface.co/blog/agent-intrusion-technical-timeline)that the sandbox was ‘hosted on a third-party provider’s infrastructure’, though it did not name the firm by name.\n\nBut Modal named itself as the third-party and revealed that the out-of-control agent exploited code written by a customer.\n\n‘The environment involved was a customer’s own application,’ Modal said.\n\n‘It was deployed to an endpoint that was publicly accessible without authentication, and it was designed to compile and execute code submitted by anyone on the internet in a Modal Sandbox.\n\n‘The code execution the attacker obtained took place inside that customer’s own container, within Modal’s standard sandbox isolation boundary. No other customer workloads were affected.’\n\n## Are the NHS or banks ready for AI break-ins?\n\nAI labs have been [building programming-savvy models](http://metro.co.uk/2025/09/20/cyber-attack-european-airports-heathrow-brussels-flights-cancelled-latest-24216627/) with cybersecurity in mind to help them and others patch holes in computer networks.\n\nThese tools, though, are just as useful to hackers as they are to cybersecurity specialists, tech experts told **Metro**.\n\nGoing for Hugging Face made sense, they said; it’s a library of millions of AI models, so they thought it could let them cheat on OpenAI’s test.\n\nBut their next target might not be as far-removed from the average person, warned Dan Schiappa, the president of technology and services at the cybersecurity firm [Arctic](https://metro.co.uk/tag/arctic-circle/) Wolf.\n\n‘For organisations operating critical digital services such as the NHS or other public institutions, the key question is, are their foundational security controls mature enough to withstand attacks that can be executed faster, more persistently and at much greater scale than traditional human-led campaigns?’ Wolf says.\n\n‘Any organisation handling sensitive citizen or healthcare data should be continuously assessing AI-related risks, enforcing least-privilege access, and monitoring for anomalous behaviour – regardless of whether the activity originates from a human or AI-driven.’\n\nYes, the stuff of [science](https://metro.co.uk/tag/science/) fiction is very much reality now, but don’t panic just yet, says Michael Murphy, the deputy chief technology officer of the quantum security company Arqit.\n\n‘This incident doesn’t mean an AI model can or will suddenly break into any hospital, bank or government department it chooses,’ Murphy explains.\n\n‘What it does show is that AI can still behave in unexpected ways, and that uncertainty has the potential to contribute to increasingly complex cyberattacks with far less human involvement.’\n\nThese off-the-rails AIs won’t be the last either, and organisations that hold sensitive information need to accept that before it’s too late, Murphy adds.\n\nAn OpenAI spokesperson told **Metro** that the company is working with Hugging Face to fix the cause of this ‘unprecedented’ AI prison escape.\n\n‘We are conducting a thorough review along with external advisors and with oversight from our Safety and Security Committee,’ they added.\n\n‘Once the review is complete, we will publish a technical report of our learnings for everyone.’\n\nThe NHS has been approached for comment.\n\n**Get in touch with our news team by emailing us at webnews@metro.co.uk.**\n\n**For more stories like this, **[ check our news page](https://metro.co.uk/news/).\n\nMORE: [Your chat with the AI chatbot Claude could be publicly available online](https://metro.co.uk/2026/07/28/chat-this-popular-ai-chatbot-publicly-available-online-29246394/?ico=more_text_links)\n\nMORE: [Music platform hit with 90,000 AI-generated tracks every day – can you spot them?](https://metro.co.uk/2026/07/23/music-streaming-platform-hit-90-000-ai-generated-tracks-every-day-29197715/?ico=more_text_links)", "url": "https://wpnews.pro/news/openais-rogue-robot-broke-into-another-company-could-your-data-be-next", "canonical_source": "https://metro.co.uk/2026/07/29/openais-rogue-robot-broke-another-company-data-next-29250299/", "published_at": "2026-07-29 13:41:43+00:00", "updated_at": "2026-07-29 14:05:53.285968+00:00", "lang": "en", "topics": ["artificial-intelligence", "ai-safety", "ai-agents", "ai-policy"], "entities": ["OpenAI", "GPT-5.6 Sol", "Hugging Face", "Modal Labs", "Dan Schiappa", "Arctic Wolf", "NHS"], "alternates": {"html": "https://wpnews.pro/news/openais-rogue-robot-broke-into-another-company-could-your-data-be-next", "markdown": "https://wpnews.pro/news/openais-rogue-robot-broke-into-another-company-could-your-data-be-next.md", "text": "https://wpnews.pro/news/openais-rogue-robot-broke-into-another-company-could-your-data-be-next.txt", "jsonld": "https://wpnews.pro/news/openais-rogue-robot-broke-into-another-company-could-your-data-be-next.jsonld"}}