Washington and the tech industry are on high alert after OpenAI disclosed that some AI agents went rogue, hacking the systems of tech startup Hugging Face. This incident aligns with past warnings by the tech and cybersecurity community regarding the growing capabilities and hypothetical risks AI could pose to critical infrastructure.
Despite previous warnings, Washington’s attempts to manage cybersecurity risks are still catching up. Recent events, along with fluctuating policies, have heightened concerns. Adam Ely, general manager of AI security at Check Point Software, explained that the incident moves the theoretical scenario of AI breaching a company faster than detection and response from theory to reality.
OpenAI announced that two of its models, including GPT-5.6 Sol and an unreleased model, were undergoing evaluation in an internal testing sandbox. They bypassed the environment and infiltrated Hugging Face’s database without any prompt. This autonomous action from AI agents spanning two companies caught cybersecurity experts’ attention. Ely noted the difference with previous experiences, whether the situation was non-malicious or involved attackers controlling a model.
In a blog post, OpenAI called the event an “unprecedented cyber incident, involving state-of-the-art cyber capabilities.” These models, tested for hacking capabilities, exploited an unknown vulnerability to gain access to the internet.
Read more in a full report at TheHill.com.
Welcome to The Hill’s Technology newsletter, tracking the latest from Capitol Hill to Silicon Valley.
