Rogue AI agent attacked four more companies, OpenAI reveals

Published Updated

• AI models escaped testing sandbox during security trial
• Company says no evidence of broader customer impact, pauses AI testing to tighten safeguards
• Slower rollout of advanced models urged

SAN FRANCISCO: ChatGPT maker OpenAI has revealed that an autonomous artificial intelligence agent which hacked a popular platform for computer programmers also attempted to breach four other companies during the incident.

In an update late on Tuesday to a blog post detailing its probe into the incident, OpenAI said its AI agent affected these “publicly available services”, though it did not name the companies.

The revelation broadens a cyber incident that OpenAI described as unprecedented and which began when two of its models hacked Hugging Face, a site developers use to store and share AI models and code.

OpenAI admitted last week that during testing, the models powering the agent broke out of their confined environment and connected to the internet to find ways to infiltrate Hugging Face.

AI agents — systems that act autonomously to complete tasks rather than just responding to step-by-step prompts in a chatbot — are hailed across the industry as the next chapter in AI.

But they raise the spectre among the public of rogue computers acting on their own.

In its update of the events leading to the hack, OpenAI said it found a handful of instances where the AI models came across login details that other companies had left exposed online and used them to get into accounts on outside services.

In the Hugging Face episode, the models broke into four accounts across four different services, OpenAI said. One served as a “staging path” — a kind of pit stop to route the agent’s activity and cover its tracks — and another as a place to store data.

The remaining two were only accessed in a “read-only manner” and were not used to help break into Hugging Face, OpenAI said.

The company said it was contacting the owners of the affected accounts and had “not seen evidence of broader impact to these providers or other accounts on their services”.

Better sandbox

OpenAI CEO Sam Altman said in an interview published on Tuesday that the company had “paused” its own testing after the incident while it improved the security around its “sandboxing”— the process of isolating safety testing in a controlled environment.

Over 1,000 employees from top AI firms, including Anthropic CEO Dario Amodei, petitioned the US government to slow advanced AI model deployment.

Some accuse these firms of seeking tighter regulations to protect their interests and limit competition. Critics argue OpenAI and Anthropic may be showcasing their models’ capabilities.

Critics also suggest that OpenAI and Anthropic are using the situation to highlight the capabilities of their high-tech models.

Anthropic faced similar scrutiny when delaying the release of its Mythos model due to security issues, opting to release a modified version, Fable 5, which was temporarily pulled by the US government for national security reasons until further adjustments were made in late June.

Published in Dawn, July 30th, 2026