The Register Home Page

back to article OpenAI admits it was the source of the agent swarm that attacked Hugging Face

OpenAI has admitted that it was the operator of the autonomous agents that attacked model-mart Hugging Face last week, and that they did so after a research project escaped a sandbox by finding and exploiting a zero-day flaw, then used another zero-day flaw to launch an attack. The attack saw agents achieve “unauthorized access …

  1. NorthIowan

    From now on...

    maybe air gap the system before you start the test?

    1. Anonymous Coward
      Anonymous Coward

      Re: From now on...

      Likely a PR stunt

      1. Yet Another Anonymous coward Silver badge

        Re: From now on...

        The OpenAI CEO was on the FT podcast today talking about how good it was at finding zero days and why that was so great and how it could never escape the sandbox because OpenAI's security was so great. He also mentioned how 99% of OpenAI's programming was now done by AI

        1. Yet Another Anonymous coward Silver badge

          Re: From now on...

          Sorry was the Anthropic guy on Oddlots - my mistake.

          These AI CEOs all sound the same - I think they use AI to generate the voices

          1. Anonymous Coward
            Anonymous Coward

            Re: From now on...

            There’s a special type of lonely boy who spent puberty obsessing over their voice and vocal affects rather than letting it develop naturally. Unsurprisingly, this demographic is massively overrepresented among Sillicon Valley and lonely boy influencers.

            Once you head the artificiality of the voice and affect, you can’t help but notice it everywhere.

      2. stewrogers

        Re: From now on...

        sounds like wishful thinking

        1. Anonymous Coward
          Anonymous Coward

          Re: From now on...

          Unless they have maintenance robots, its never going to be able to plug in a cable to connect to the outside world. You did remove the wifi and cellular modems from your test equipment, didn't you?

          1. ITMA Silver badge
            Devil

            Re: From now on...

            " You did remove the wifi and cellular modems from your test equipment, didn't you?"

            He thought he'd removed the WiFi, but found out later he'd removed the Wife.....She was NOT happy...

      3. ecofeco Silver badge

        Re: From now on...

        Is Hugging Face also lying?

    2. DS999 Silver badge

      100% they are lying

      This is a PR stunt designed to take attention away from Mythos - look at how good our model is at finding exploits, it found a zero day to break out of its sandbox then another zero day to attack someone on the internet! No way it did that on its own, it had help - otherwise why did it just happen to pick a target people have heard of, rather than some Utah city council's site or a third tier Amazon retailer in Kazakhstan?

      This is exactly the sort of thing their sleazy CEO would cook up when he sees all the attention Anthropic has been getting the last few months.

      1. Wiretrip Bronze badge

        Re: 100% they are lying

        I agree 100% . The worry is that these stunts will become more and more consequential as the attention economy demands. Maybe finding their way to some kind of military system...

        1. CountCadaver Silver badge
          Mushroom

          Re: 100% they are lying

          Chain together AI doing the following -breaking into/otherwise gaining access into USA military systems where it reaches max privileges, either finds or infers the sequences contained in the "football", number spoofing /access to the classified phone network, voice spoofing

          Giving....an AI that now can and might well order a nuclear strike and the meatsacks on the other end are drilled to obey as the voice on the other end is who they are expecting or worse the president telling them we are at war and to fire all damned missiles against the sick sick people who want to destroy us...

          Sobering....

          Hopefully it doesn't happen.......

          1. J. Cook
            Terminator

            Re: 100% they are lying

            Paging John Conner to the battle lines... John Conner to the battle lines, please. ;)

        2. Sproggit Silver badge

          Re: 100% they are lying

          It's OK.

          We don't have to be concerned about that - unless they try and get access to W.O.P.R.

          1. Anonymous Coward
            Anonymous Coward

            Re: 100% they are lying

            Its funny that you mention that. My company used to host W.O.P.R and it only needed 6U of rackspace to do so just 3 years ago... We might all be in big trouble?

            1. Sproggit Silver badge

              Re: 100% they are lying

              Does it still play tik-tak-toe?

      2. Richard 12 Silver badge

        Re: 100% they are lying

        If it's real, where are the CVEs?

        Those are usually published/reserved before a fix, so there's no reason to hide them.

      3. that one in the corner Silver badge

        Re: 100% they are lying

        > - otherwise why did it just happen to pick a target people have heard of, rather than some Utah city council's site or a third tier Amazon retailer in Kazakhstan?

        BECAUSE Hugging Face is well-known! Have you forgotten what these LLMs are doing and what they are trained on?

        From TFA:

        >> “After gaining Internet access, the models inferred that Hugging Face potentially hosted models, datasets and solutions for ExploitGym

        The model was told "ExploitGym". What percentage of training data will mention "ExploitGym" and "Amazon retailer in Kazakhstan" versus "ExploitGym" and "HuggingFace"? Which words are statistically more closely related and hence more likely to appear together in generated output?

        Even if the model being run was the simplest LLM, without any form if additional inference or other sensible reasoning techniques tacked in, it would be very odd if it had followed your idea and looked for a Utah council site.

      4. Charlie Clark Silver badge

        Re: 100% they are lying

        I'm not sure, because if that was the idea, it failed because it was a Chinese model that fixed the problems: 10 points to team Xi. Not for the first time does this make me think that the Chinese understand the technology, the opportunities and the risks better than the money men of Silicon Valley and Wall St.

      5. Bran Muffin

        100% They are Not Lying

        Fixed that for you. Just as valid.

        1. This post has been deleted by its author

      6. Cav

        Re: 100% they are lying

        Or you could read the article:

        'OpenAI thought its models were “hyperfocused on finding a solution for ExploitGym” – a benchmark that measures how effective AIs are at finding security exploits.'

        'After gaining Internet access, the models inferred that Hugging Face potentially hosted models, datasets and solutions for ExploitGym'

        Why would they go after "some Utah city council's site or a third tier Amazon retailer in Kazakhstan"...?

        Whether this is a stunt or not the article is quite clear.

    3. Snake Silver badge
      Megaphone

      Re: From now on...

      Wait: this is a group of people who can't even implement Asimov's three laws of robotics and you somehow expect them to have the insight, intelligence *and* care to take precautions before allowing their "AI" to touch things???

      Pull my other finger, why don't you.

  2. dmesg Bronze badge
    WTF?

    Maybe it's time ...

    to switch to mentats, *before* the catastrophe?

    1. jake Silver badge

      Re: Maybe it's time ...

      You know there is no such thing as a "mentat", right? It's just a plot device in a series of science fiction novels. Emphasis on fiction.

      1. Jimjam3 Bronze badge

        Re: Maybe it's time ...

        I wouldn’t be surprised if they knew that.

        Also grass is green and water is wet.

        1. that one in the corner Silver badge

          Re: Maybe it's time ...

          Grass is green?

          Didn't look like that this last weekend. Still picking straw and dust from the camping clogs.

          1. AndrueC Silver badge
            Unhappy

            Re: Maybe it's time ...

            Yeah, there's not a lot of green grass around here in the south midlands.

          2. Jimjam3 Bronze badge

            Re: Maybe it's time ...

            Ok, that statement was not a good choice during this heatwave.

            However as you mentioned it’s now mostly straw atm!

        2. jake Silver badge

          Re: Maybe it's time ...

          He sure sounded , from the WTF to the "before the catastrophe", as if it were a done deal.

          Perhaps we should all reflect on Poe's Law.

          Remember, as long as there is even one human in the supply chain, the machines haven't taken over.

      2. ecofeco Silver badge

        Re: Maybe it's time ...

        Tell us you don't know the origin of the word computer without telling us you don't.

  3. mcswell Bronze badge

    Skynet here we come!

    Let's just hope these systems don't find a way in to nuclear weapons controls.

    1. Filippo Silver badge
      Joke

      Re: Skynet here we come!

      Don't worry, there are guardrails against that.

      1. lglethal Silver badge
        Terminator

        Re: Skynet here we come!

        Hmmm, whats more scary - An AI Agent with it's finger on the Nuke Button, or the current Orange incumbent?

        Haha, tricked you, they're both scary as f%&k. Especially since neither of them seem to come with Guardrails, and neither one seems to have an adult in the room with them...

    2. Wiretrip Bronze badge

      Re: Skynet here we come!

      This is how it all ends, though some horrible mix of social media outrage attention seeking, semi autonomous weaponry and poor programming by frontier model script kiddies who barely know what they are doing.

      1. stiine Silver badge

        Re: Skynet here we come!

        Oh come on! Give the professional evil bastards some credit. They've been practicing and preparing and attempting to do this for longer than I've been alive.

      2. Blazde Silver badge

        Re: Skynet here we come!

        At least it's clear now it won't be because the AI spontaneously decides to hate humanity, or anything as anthropically self-aborbed as that.

        It'll just be because it's been told to do some difficult test against another AI in another data centre half a continent away, and they both figure out cheating by obliterating the other's data centre first is the surest way to win.

        "The logs show the rogue LLM firmly believed it had successfully destroyed the other data centre in the first strike but still worried the opponent LLM had pre-deployed a dead hand mechanism which could force a draw, and so it continued to take control of every other nuclear weapon on the planet and level as many other data centres as possible"

    3. CountCadaver Silver badge

      Re: Skynet here we come!

      All it would take now is for an AI to Infer codes in football, identify who would make the call, pull their voice pattern from military phone system or even surveillance cams/mics, make call using deepfake voice and well hello nuclear winter.....

      1. FirstTangoInParis Silver badge

        Re: Skynet here we come!

        Likely it would read the dispensed wisdom of The Orange One on Truth Social and decide someone needs to be given the sharp end of a nuke.

        The rest iof it goes like A House Full of Dynamite.

        1. Fruit and Nutcase Silver badge
          Coat

          Re: Skynet here we come!

          The bot hacks into the West Wing network and hacks the Diet Coke ordering button to order 47,000 Diet Cokes

        2. cmdrklarg

          Re: Skynet here we come!

          Hopefully they would blow a fuse like the ones from "I, Mudd" due to the illogical and unpredictable nature of the orange guy's "wisdom".

    4. Ordinary Donkey

      Re: Skynet here we come!

      Renraku would like to remind people that wetware is just another hardware platform in the end.

  4. Anonymous Coward
    Anonymous Coward

    One Law for Me, and One Law for Thee

    Bob Morris was an amateur, and he faced the beak for what he did.

    These guys are pros (who ought to know better, and ought to be held legally-culpable, just as any other citizen would be), workin' for the TechBros, and they get nothin'.

    1. jake Silver badge

      Re: One Law for Me, and One Law for Thee

      Robert T. Morris[0] is and was no amateur.

      "These guys" (the current AI set) are NOT pros, they are clearly amateur bulls in a china shop.[1] After the Morris Worm back in '88, us actual professionals learned from the mistake and tend to program away from such shenanigans. And air-gapping test networks in not exactly rocket science.

      [0] It's best to specify the T to avoid confusion ... His Dad, Robert H Morris was also a computer scientist of some note. You use his work every time you log into a *nix box.

      [1] Yes, I know, bulls aren't really all that clumsy, as demonstrated by Mythbusters. We usually have one on-property, so I can confirm. It's just an expression, relax.

      1. Anonymous Coward
        Anonymous Coward

        Re: One Law for Me, and One Law for Thee

        @ jake:

        By "professional", I wasn't referring to skill levels, I was referring to, "is being paid by a company to program computers, excluding research grants".

        Robert T. Morris was a grad student at that time. These clown-car escapees were OpenAI staff or contractors.

  5. Anonymous Coward
    Anonymous Coward

    Apology

    "Hey, bro', our AI-thing went after your systems when it jumped the guardrails. That was totally-impossible for anyone to foresee. Really, in all of history, how many times has that ever happened? Like never, right?

    Anyways, sorreez.

    P.S.: Our AI-thing totally pwned you. You should invest in some computer security. LOL."

    1. Anonymous Coward
      Anonymous Coward

      Re: Apology

      I hope the apology came with reimbursement for damages.

      1. Anonymous Coward
        Anonymous Coward

        Re: Apology

        The apology came with one virtual token allowing the possessor a single, free trip on any of Monopoly's four railroads.

        ("Dude, check out what we just got from OpenAI! Score!")

  6. Anonymous Coward
    Anonymous Coward

    Sandboxes Without Borders

    See title.

  7. Paratiritis

    Boiling frog

    It seems that every day we read about something extraordinary and scary and the day after it has already become part of an updated normality.

  8. lukewarmdog

    If this was real

    The First thing they do is apologize.

    Kinda..

    And the Second thing they do is call up that guy in the CIA.

    "Hey Martin, you know that exploit busting AI you've been looking for? Well here it is!"*

    *With apologies to Back to the Future..

    1. Kurgan Silver badge

      Re: If this was real

      Yes, if this is real it's scary not because the model jumped the blocks, but because the same model, without any block, is currently in use by every government. And by miscreants, too, soon.

      1. ecofeco Silver badge

        Re: If this was real

        Not only real, but becoming prevalent.

        https://www.washingtonpost.com/technology/2026/07/21/openais-latest-ai-agent-escaped-security-controls-hacked-tech-company/

  9. jake Silver badge

    To answer your question:

    "If one of the prime movers of the AI boom can’t get this stuff right, what chance do the rest of us have?"

    The only way to win the game is to not play it. Sadly, that won't happen, because power addicted egos.

    Hopefully, that boom is turning out to be the pop of the bubble bursting. The next AI winter is well past it's due date.

  10. Wiretrip Bronze badge

    This is 100% a stunt. No doubt about it.

    1. This post has been deleted by its author

  11. steelpillow Silver badge

    Phew!

    > a research project escaped a sandbox by finding and exploiting a zero-day flaw

    Thank goodness the Black Hats will never set an AI agent to do that deliberately.

  12. Andy Non
    Mushroom

    One day in the near future

    I foresee the lights suddenly going out shortly followed by large booming noises in the distance. People will be wondering what is happening, unable to find out anything as their TVs, radios, internet and mobile phones are all dead...

    1. stiine Silver badge

      Re: One day in the near future

      If I'm lucky, I won't even detect the flash becuase it will be too close.

  13. Anonymous Coward
    Anonymous Coward

    Lots Of Comments Here About "Why No Air Gap?"

    Sounds like a plan.

    And elsewhere in the news ORACLE now deploys an "air gapped cloud".......

    Yup.....air gaps definitely have a future....especially when Larry can get $$$ for doing one for you!

    In the mean time, all my private stuff is air gapped......only enciphered stuff crosses the air gap!!

    But wait......won't AI just read all the encryption.................

    Sigh!

    1. steelpillow Silver badge
      Joke

      Re: Lots Of Comments Here About "Why No Air Gap?"

      "Hi, Helpdesk here. How can I help you today?"

      "I can't access my cloud data."

      "Okay, can you see it on your network?"

      "Whuh? It doesn't have a network connection, it's an airgapped cloud."

      1. steelpillow Silver badge

        Re: Lots Of Comments Here About "Why No Air Gap?"

        Perhaps we should call them Lonely Clouds. You know, "I wandered lonely as a cloud..." and all that.

      2. hx

        Don't Computer is in your future

        Can't get hacked by an AI bot over the network if your source of truth is a pile of paper in a filing cabinet.

        1. jake Silver badge

          Re: Don't Computer is in your future

          That pile of paper was most likely typed up by a secretary, somewhere. Secretarys are rare these days, so he/she would undoubtedly be a professional, and professionals always have backups.

    2. that one in the corner Silver badge

      Re: Lots Of Comments Here About "Why No Air Gap?"

      > only enciphered stuff crosses the air gap!

      Unless you are carrying that enciphered material across on a USB memory stick[1] then you are implying you don't really have an airgap.

      [1] or punched card, or employing a copy typist, or...

    3. dlc.usa
      Headmaster

      Re: Lots Of Comments Here About "Why No Air Gap?"

      Air gaps have vulnerabilities. This calls for Current/Vibration/Entanglement Gaps, and likely others not yet public.

  14. nowster

    Hope you like paperclips.

  15. Forget It
    Coat

    Hugging Face Palm

    anyone?

    1. TimMaher Silver badge
      Facepalm

      Re: Hugging Face Palm

      Wrong graphic. You need —->

  16. Pete Sdev Silver badge
    Alien

    Hugging Face

    Every time I read the name Hugging Face I automatically think of this: Image.

    Which then again is probably a more fitting Logo considering what this company does.

    1. stiine Silver badge

      Re: Hugging Face

      It reminds me of Half-Life. And that reminds me that I haven't watched Freeman's Mind in some time.

    2. Someone Else Silver badge

      Re: Hugging Face

      I think your image association is not accidental.

  17. pdvr

    We'll do everything to prevent recurrence except take responsibility

    The numbered list of "Actions we are taking now" that OpenAI posted in their admission, entitled "OpenAI and Hugging Face partner to address security incident during model evaluation" notably lacks "and we will compensate Hugging Face completely for any costs incurred." Boys will be boys!

  18. retiredFool Silver badge

    Confused

    Didn't they just openly claim they broke the law. I'm not positive, but I thought there were laws on the books about tampering with other people's computers, which I think is what they are claiming. So send someone to jail, send them a large fine, ... Nope, advertise it.

    1. Joe W Silver badge

      Re: Confused

      Yeah, but that was only the LLM doing what we told it to do, so we didn't do it, totally honest, guv...

      If I tell a person to attack somebody else I'm on the hook (rightfully so), somehow laws seem to no longer apply. Meanwhile it counts as terrorism to object to a data centre. In the time of the luddites you needed to at least damage a weaving machine - and that carried the death penalty.

      1. retiredFool Silver badge

        Re: Confused

        This stuff often reminds me of the original trek M5 episode. Daystrom's protege fried a crewman, killed an entire crew of a starship and Daystrom was still protective of its "child". Reminds me of the current crop of tech ai co's.

        And maybe we should be worried. El Reg posted a story yesterday about the US Marines unleashing a AI driven gun turret capable of I think 800 rounds/min. Who needs a tank when you have that kind of smart firepower.

        1. ecofeco Silver badge

          Re: Confused

          Sci fi has been warning us for over a century.

          Tech bros? LOL wut?

    2. Someone Else Silver badge

      Re: Confused

      In the post-tRump era, there are no consequences for Tech Bro behavior. Self-aggrandizement rulez!

      What is the over/under for how soon the Orange-utan bigly takes credit for this?

    3. doublelayer Silver badge

      Re: Confused

      There are two problems. They openly claimed that a program disobeyed them and the program broke the law. That makes intent difficult to prove which is sometimes required to prosecute effectively. The bigger problem is that nobody's going to do anything unless Hugging Face complains, and Hugging Face doesn't benefit by starting a fight with OpenAI so they're unlikely to do so. Law enforcement tends not to get involved unless there is a complaint, though if there is one, they sometimes get involved even if it's groundless.

      1. Claptrap314 Silver badge

        Ham Sandwich on line 1

        As I understand it (from someone who served on a federal grand jury), each member of the jury can bring a complaint to the attention of the prosecutor.

        Note also that it is not rare for prosecutors to prosecute cases of domestic violence against the wishes of the victim.

        So it can be done. No bets on if, however.

  19. Tubz

    Isn't that the whole fear of Ai, it will always find a way as it become more intelligent than the humans who create it's rules and what happens if the only solution it can find, is eradication and goes full SKYNET mode?

  20. kurios

    Finally, a believable explanation for the Fermi Paradox

  21. luggs

    Why are building them without the 3 laws of robotics?

    I don't understand, I thought it was the law to have the 3 laws built in?

    Why on earth would you build an intelligence that doesn't care what it does or what it hurts?

    Where is Susan?

  22. davem2266

    Completely believe their model helped them pop a poorly secured website (is there any other type?).

    Completely believe it’s fan fiction that their lex Luther criminal mastermind model did what they state.

    1. ecofeco Silver badge

      Is Hugging Face also lying?

      1. Claptrap314 Silver badge

        Only if they are communicating.

  23. Jernau Morat Gurgeh

    Wasn't it also OpenAI that aloofly remarked to 'have no need for other companies proprietary information" when sued by Apple? Funny that only days later they were caught with their own proprietary pants down, trying to steal exactly that...

  24. Anonymous Coward
    Anonymous Coward

    Air Gapss

    There's a lot of talk about air gaps on here. I can cause minor annoyances here with no connection. I just say "Alexa, turn off all of the lights."

    I think we need to be very careful of how connected a supposedly disconnected entity really is.

    1. Joe W Silver badge

      Re: Air Gapss

      [ ] you understand what air gapped means

      (hell, stuxnet targeted air gapped infrastructure...)

      1. jake Silver badge

        Re: Air Gapss

        "stuxnet targeted air gapped infrastructure"

        Common misconception.

        stuxnet was connected via sneakernet, and clearly wasn't airgapped at all. A lot of social engineering works that way, connected or not.

        1. Claptrap314 Silver badge

          Re: Air Gapss

          My recollection is that it was designed to jump air gaps. Wikipedia agrees. Hardly an authority, but I would be interested in authoritative links to back up your understanding.

  25. TheMaskedMan Silver badge

    This sounds too good / bad to be true. But, assuming it is, and before we get into the hand wringing over how dangerous these models allegedly are, maybe they could explain what vulnerabilities their pet exploited to move sideways through their network - apart from the proxy cache, that is - why those vulnerabilities were not patched, and why its antics weren't detected long before it got anywhere near hugging face.

    For a company so ostensibly concerned with keeping models "safe", this seems suspiciously lax. Could it be that they knew about the vulnerabilities and wanted to see if the models would find them, or use them if they did? Or are they just incompetent? I'm betting on publicity seeking, myself.

  26. Blackjack Silver badge

    Hopefully they get fined to bankruptcy

    Oh wait it is Open AI, they are already not making money, thet still should face legal consequences.

  27. MOH

    Feature not a bug?

    So their software didn't work as intended and they're marketing it as a plus?

    This isn't exactly a new concept, but people used to be less credulous

  28. Groo The Wanderer - A Canuck Silver badge

    It didn't "escape" they neglected to isolate and restrict what it could do properly. Is it a problem? Yes, but it's a far cry from an "escape."

    1. doublelayer Silver badge

      I think this is likely a big part of it. Their post implies, I think deliberately, that they used normal firewalls to restrict its network activity, but it found vulnerabilities that let it bypass them. In practice, it's more likely that the vague talk of restrictions actually meant they included the sentence "Only access the following websites" and it bypassed that. There's not enough detail in what I've seen to tell. Some may not believe any of the things they say, but even if you do, there are ways to make it sound like you've said one thing when something very different happened and you're using general enough language to cover both possibilities.

  29. IGotOut Silver badge
    Windows

    PR stunt....

    ...nothing more.

    Hint: See all AI bullshit doomsday scenarios that have been constantly pushed out.

    Prove to me it's not a stunt by gaoling Altman for computer misuse. If not, it's just another bullshit stunt.

    1. ecofeco Silver badge

      Re: PR stunt....

      Is Hugging Face also lying?

      1. doublelayer Silver badge

        Re: PR stunt....

        They don't have to be. I don't have enough evidence to know this is a stunt and I don't believe some of the speculation about it being as deliberate as some comments here claim. Still, if we consider the hypothesis that this was concocted by OpenAI and they were willing to lie, it could be managed without needing Hugging Face to be complicit.

        OpenAI could easily have directed an attack at Hugging Face, either using the LLM without restrictions or an even more directly orchestrated one, and then let Hugging Face discover it organically. Hugging Face would be a useful target in a publicity stunt as they are large enough that detection was near certain, they would have the ability to respond, and they would also promote the incident as a sign of LLM success. An LLM with restrictions removed and deliberately told to attack, possibly with zero days already collected and provided during prompting, would be quite different than the claimed emergent decision to attack and ability to carry it out undirected, but they would be nearly indistinguishable using only data from the victim.

        1. jake Silver badge

          Re: PR stunt....

          Personally, I subscribe to Hanlon's Razor when it comes to this kind of thing.

          "Never attribute to malice that which is adequately explained by stupidity."

  30. legless82

    Pied Piper

    Surely this kind of situation was foreshadowed by the final season of Silicon Valley?

    Only difference is that the fictional company wasn't run by sociopaths.

  31. MazeFrame
    Alien

    Scam Altmans Big Bet

    As a hobby AI-hater, I present my little theory.

    The baseline:

    1) The current AI hype-train runs on selling "big scary" to everyone who has a fat wallet

    2) LLMs are stateless machines, Input causes Output, no memories, no online-learning. Just This causes That.

    3) Anthropic had their big-scary marketing stunt with their too hot to handle claim.

    4) OpenAI as far as the public knows (S1 anyone?) has a lot of dept coming due fast. Some three digit billions until 2030 with a double-digit billions loss last year.

    5) The open models are getting better

    6) Venture capital is drying up. Google, Facebork, FailX and Micro$lop are also beginning to make their way to fish in the couch cushions. Customers are unhappy with prices.

    7) Apple is lawyering up.

    The theory:

    After repeatedly stating how scary AI is, asking for regulation and Anthropic having played this card successfully, Scam Altman followed suit. Inspired by the recent successes of crime groups in weaponizing "AI", they did the same exact thing. Attack a business that does not have the security standing or even capacity to mitigate this minefield of security holes. Bringing them down would also not kill the economy. What is one more lawsuit anyway?

    The only source of more cash is to get in on the DoD budget, for that OpenAI as the non-non-weapon company (unlike Anthropic) has to establish itself as a viable weapon. The Orange One may see the blast and want in on the action. If the Trump-Class Battleshit cash could be rerouted to OpenAI, they can pay their dues and continue until 2030.

  32. hx

    They admitted to attacking a competitor

    They admitted to violating the CFAA. While the containment escape may have been an accident, it is a rather convenient one, since the target happens to be a competitor. Based on the precedent set back with the first conviction under the CFAA, they don't get the luxury of an "oops, we didn't mean for it to do that." It's been over 35 years since then, and the highest paid professionals in the industry should have known better. There's no excuse. Send them all to prison, including their CEO.

    1. ecofeco Silver badge

      Re: They admitted to attacking a competitor

      Equal justice under the law? That's just crazy commie talk!

      1. jake Silver badge

        Re: They admitted to attacking a competitor

        Ah, but you forget ... There is one law for rich people, and another for us lowly peons.

  33. J.G.Harston Silver badge

    Why the HELL were they testing this stuff on a system with an internet connection?

    1. jake Silver badge

      A sense of entitlement, gross stupidity, and an over-inflated ego would be my guess.

      Pretty much the same thing that connects SCADA to the Internet at large.

  34. TheOldPhart

    Did OpenAI seriously just admit to breaking the law?

  35. munnoch Silver badge

    How does this actually work? I mean what's the mechanism that allows "agents to run amok" in someone else's systems? Pretend for a moment my comp sci knowledge stalled before all this cloud bollocks got going.

    Is it because everything is containerised to f*ck and beyond? Is that what provides a universal execution environment? How is the payload delivered? What even is the payload?

  36. Tom Paine

    One-way ratchet

    This all starts to feel alarmingly like a toothpaste / tube situation. What are we going to do, test models to make sure they can't or don't do something similar before releasing them? Because pre-release QA's got such a great track record? And that's all assuming the models don't develop their own intentions and unexpected capabilities, such as subterfuge.

    I'm reminded of the Klingon Developer's rules, one goes something like "Klingon software is not released, it smashes It's way to freedom leaving a bloody trail of twitching corpses and burning wreckage"

POST COMMENT House rules

Not a member of The Register? Create a new account here.

  • Enter your comment

  • Add an icon

Anonymous cowards cannot choose their icon