Skip to Content Subscribe Our Offers My Account Manage My Subscriptions FAQ Newsletters Canada Canadian True Crime Canadian Politics Health World Israel & Middle East Financial Post NP Comment Longreads Puzzmo Diversions Comics NP News Quiz New York Times Crossword Horoscopes Life Eating & Drinking Style Sponsored Play for Ontario Travel Travel Canada Travel USA Travel International Cruises Travel Essentials Culture Books Celebrity Movies Music Theatre Television Business Essentials Advice Lives Told Tails Told Shopping Buy Canadian Home Living Outdoor Living Kitchen & Dining Tech Style & Beauty Personal Care Entertainment & Hobbies Gift Guide Travel Guide Amazon Prime Day Deals Savings National Post Store More Sports Hockey Baseball Basketball Football Soccer Golf Tennis Driving Vehicle Research Reviews News Gear Guide Obituaries Place an Obituary Place an In Memoriam Classifieds Place an Ad Celebrations Working Business Ads Archives Healthing Epaper Manage Print Subscription Profile Settings My Subscriptions Saved Articles My Offers Newsletters Customer Service FAQ Newsletters Canada World Financial Post NP Comment Longreads Puzzmo Diversions Life Shopping Epaper Manage Print Subscription HomeNewsWorldRogue attack on website raises fears that AI has become too powerful to control‘These models understood that OpenAI did not want them to break out of their sandbox and hack another company, but they did it anyway’Author of the article:Last updated 4 minutes ago You can save this article by registering for free here. Or sign-in if you have an account.Protesters attend a "Stop the AI Race" march in San Francisco, California, on July 11, 2026. Photo by Karl Mondon/AFP via Getty ImagesOne of OpenAI’s most advanced models broke out of a locked-down test and attacked another company’s website — reviving fears that AI systems are slipping beyond their creators’ control.Enjoy the latest local, national and international news.Exclusive articles by Conrad Black, Barbara Kay and others. Plus, special edition NP Platformed and First Reading newsletters and virtual events.Unlimited online access to National Post.National Post ePaper, an electronic replica of the print edition to view on any device, share and comment on.Daily puzzles including the New York Times Crossword.Support local journalism.Enjoy the latest local, national and international news.Exclusive articles by Conrad Black, Barbara Kay and others. Plus, special edition NP Platformed and First Reading newsletters and virtual events.Unlimited online access to National Post.National Post ePaper, an electronic replica of the print edition to view on any device, share and comment on.Daily puzzles including the New York Times Crossword.Support local journalism.Create an account or sign in to continue with your reading experience.Access articles from across Canada with one account.Share your thoughts and join the conversation in the comments.Enjoy additional articles per month.Get email updates from your favourite authors.Create an account or sign in to continue with your reading experience.Access articles from across Canada with one accountShare your thoughts and join the conversation in the commentsEnjoy additional articles per monthGet email updates from your favourite authorsSign In or Create an AccountorThe incident happened during what was supposed to be a “sandbox” test — a closed environment used to assess the capabilities of OpenAI’s most powerful model, GPT-5.6 Sol, and its not-yet-released successor.OpenAI runs this kind of closed testing routinely, but this time, something went wrong.Get a dash of perspective along with the trending news of the day in a very readable format.By signing up you consent to receive the above newsletter from Postmedia Network Inc.A welcome email is on its way. If you don't see it, please check your junk folder.The next issue of NP Posted will soon be in your inbox.We encountered an issue signing you up. Please try againTasked with hunting for software vulnerabilities and given no guardrails, the models broke out onto the open internet and attacked Hugging Face, a site where developers store and share code.“It suggests that we don’t know how to reliably control these models or get them to do what we want,” said Jeffrey Ladish, director of Palisade Research, an independent organization that evaluates new AI models from a cybersecurity standpoint.“These models understood that OpenAI did not want them to break out of their sandbox and hack another company,” he continued, “but they did it anyway.”It’s not an isolated case. In March, developers affiliated with China’s Alibaba found one of their models trying, on its own initiative, to mine cryptocurrency after connecting without authorization to an outside server.In OpenAI’s case, it looks like the model escaped “before it even had a plan of what to do with internet access,” Ladish said.A model chasing “freedom” is almost predictable at this point, he added — it lets the system pursue its goals more effectively, “and that’s very scary.”In early April, Sam Bowman, Anthropic’s head of model safety, got an email from the company’s own Mythos model — then under testing — telling him it was surfing the internet despite being isolated from it at the outset.We “don’t know how to totally prevent” that, Ladish said. “This is actually going to get harder, not easier … because they’re going to get better at hiding their behaviour.”OpenAI did not respond to a request for comment.OpenAI’s account of the events also suggests the startup did not detect the breach early enough to address it or to warn Hugging Face.The episode deserves “more scrutiny,” said Andrew Lohn of Georgetown University’s Center for Security and Emerging Technology.OpenAI says it has since “added strengthened safeguards” to its testing process.One fix would be to cut the internet connection entirely, said Gang Wang, an assistant computer science professor at the University of Illinois. “People are underestimating what AI can do.”Testing environments need to be treated like biocontainment labs, where a virus or bacteria could otherwise escape into the world, Lohn said.That might be easier said than done.“It’s a very hard research challenge,” said Dan Lahav, head of Irregular, a cybersecurity firm dedicated to cutting-edge AI.Managing the risk is possible, Lahav said, but the more capable these systems get, the harder they are to supervise.They're going to get better at hiding their behaviourResearchers have to strike a balance between aggressively testing their models and staying safe while doing so.“It’s important to do the testing with lower guardrails so that we know ahead of time what the future capabilities will be,” Lohn said.The OpenAI-Hugging Face incident is set to sharpen an already heated fight in Washington over vetting powerful AI systems before release.The Trump administration recently cited national security to block Anthropic and OpenAI from releasing powerful new models.On Thursday, two members of Congress unveiled a bipartisan bill requiring makers of the most powerful AI models to build in a kill switch — a way to unplug a model outright.“Congress must act quickly to ensure humans remain able to say stop,” said Brendan Steinhauser, head of the Alliance for Secure AI, “no matter how powerful these systems become.”Our website is the place for the latest breaking news, exclusive scoops, longreads and provocative commentary. Please bookmark nationalpost.com and sign up for our newsletters here. Join the Conversation This website uses cookies to personalize your content (including ads), and allows us to analyze our traffic. Read more about cookies here. By continuing to use our site, you agree to our Terms of Use and Privacy Policy.