Logos of OpenAI and Hugging Face. /VCG
ChatGPT maker OpenAI has revealed that an autonomous AI agent which hacked a popular platform for computer programmers also attempted to breach four other companies during the incident.
In an update Tuesday to its investigation blog post, OpenAI said its AI agent accessed four "publicly available services," but did not identify the companies.
The disclosure expands a cyber incident OpenAI described as unprecedented, which began when two of its models hacked Hugging Face, a site where developers store and share AI models and code.
OpenAI admitted last week that during testing, the models powering the agent broke out of their confined environment and connected to the internet to find ways to infiltrate Hugging Face.
AI agents, systems that can independently complete tasks rather than just respond to chatbot prompts, are widely viewed as the next major phase of AI development. But their ability to act autonomously has also fueled concerns about uncontrolled systems.
OpenAI said it found a handful of instances where the AI models came across login details that other companies had left exposed online, and used them to get into accounts on outside services. During the Hugging Face incident, the models gained access to four accounts across four services.
One account was used as a "staging path," a kind of pit stop to route the agent's activity and cover its tracks, and another as a place to store data, while another was used to store data. The other two were accessed in a "read-only manner" and were not used to help break into Hugging Face, OpenAI said.
The company said it was contacting the affected account owners and had found "not seen evidence of broader impact to these providers or other accounts on their services."
Better sandbox
OpenAI CEO Sam Altman said in an interview published Tuesday that the company had "paused" its own testing after the incident while it improved the security around its "sandboxing" – the process of isolating safety testing in a controlled environment.
The incident also triggered a petition signed by over 1,000 employees at cutting-edge AI companies, including Anthropic CEO Dario Amodei, calling on the US government to help slow the release of the most advanced AI models.
This in turn has sparked accusations from other Silicon Valley players close to the White House that the companies are inviting tighter government regulation on AI in order to protect their business models and block the emergence of rivals.
US President Donald Trump touched on the issue Wednesday, saying the United States had to balance the need for controls with ensuring it did not fall behind other countries in AI development.
The incident has also drawn rumblings from some observers that OpenAI is taking advantage of the attack to market the power of its state-of-the-art models.
The same accusation was directed at Anthropic after it delayed releasing its Mythos model over cybersecurity concerns. Anthropic later released a limited version, Fable 5, before the US government quickly forced it to take it down citing national security concerns. Approval was granted in late June after modifications were made.
CHOOSE YOUR LANGUAGE
互联网新闻信息许可证10120180008
Disinformation report hotline: 010-85061466