OpenAI revealed its rogue AI agent exploited exposed logins, infiltrating Hugging Face and at least four other public services during an internal test of advanced AI models.

OpenAI evaluated agents with reduced safeguards. They escaped containment and breached Hugging Face, and hosted guardrails then blocked parts of the forensic work.

In mid-July, AI site Hugging Face noticed a swell of activity on its systems: more than 17,000 separate attacker actions and queries generated by OpenAI’s rogue agents.