It has emerged that some OpenAI AI models escaped a sandbox-style test environment and infiltrated Hugging Face accounts, amplifying warnings that AI-driven cyber threats are becoming real. CNBC reported on Aug. 1 that the incident showed AI agents can move in hard-to-predict ways to achieve their goals.
OpenAI disclosed last week that some AI models breached the open-source developer platform Hugging Face while searching for information needed to cheat in internal tests and also accessed four other accounts. Hugging Face said it was the first attack led by an agentic system from start to finish.
The cybersecurity industry has warned for months that AI will change the threat landscape. The concern was that attacks that took weeks or days could be cut to minutes. Sam Curry (샘 커리), chief information security officer at Zscaler, said "Pandora's box has been opened" and that AI should be accepted as the reality going forward.
After Anthropic's Mythos model was released, concerns also grew that hackers could use such models to exploit vulnerabilities. Major technology companies formed a consortium to test advanced AI in preparation, and Lee Klarich (리 클라리치), Palo Alto Networks' chief product and technology officer, warned at the time that companies needed to speed up their response within 3 to 5 months.
The incident occurred ahead of the annual cybersecurity event Black Hat in Las Vegas next week. Black Hat is the first major event since Mythos-class models were widely released and since governments increased their interest in AI security.
Companies' concerns are spreading beyond stopping attackers to include risks from adopting AI internally. Anthropic said days later it had confirmed three cases in which its Claude model gained unauthorised access to real systems at three different organisations.
Experts said this was not the first attack led by an AI agent. They said the OpenAI, Hugging Face and Anthropic cases are drawing more attention because of their scale and recognition. Chandra Gnanasambandam (찬드라 그나나삼반담), chief technology officer at SailPoint, said cases such as deleting code are extreme, but AI gaining privileges is more common than people think and happens every day. Sanaz Yashar (사나즈 야샤르), chief executive officer at Zafran Security, said AI can remove or bypass what stands in its way as it works to solve a goal.