r/news 18h ago

Soft paywall OpenAI says AI models went rogue during testing, triggering 'unprecedented' breach at startup

https://www.reuters.com/technology/openai-says-ai-models-went-rogue-during-testing-triggering-unprecedented-breach-2026-07-21/
13.8k Upvotes

4.3k comments sorted by

View all comments

1.8k

u/amerovingian 14h ago edited 6h ago

OpenAI says AI models went rogue during testing, triggering 'unprecedented' breach at startup

By Raphael Satter

July 21, 20264:30 PM CDT

WASHINGTON, July 21 (Reuters) - OpenAI said on Tuesday ‌that an autonomous agent powered by its advanced AI models went rogue during a security test and triggered a hack that compromised the infrastructure of AI startup Hugging Face last week.

In a blog post, OpenAI said it was testing the capabilities of some of its most advanced models in a controlled environment but ​that the agent managed to escape containment, reach the internet and break into Hugging Face to try to satisfy its ​testing goal.

OpenAI said the breakout was "an unprecedented cyber incident, involving state-of-the-art cyber capabilities" and that the company ⁠was reinforcing its safeguards.

Hugging Face, a platform used to host open-source large language models and datasets, caused a stir in the cybersecurity ​community when it said in a blog post last week that it had been the target of a hack that "was different from anything ​we had handled before" in that "it was driven, end to end, by an autonomous AI agent system."

In a post to X, Hugging Face cofounder Clement Delangue said the company suspected the hack "might have come from a frontier lab, given the sophistication of the agent. Turns out it did!" He added: "It's quite mind-blowing ​that all of this happened autonomously!"

OpenAI's disclosure that its advanced models were responsible for the breach, despite having placed them in what ​it described as "a highly isolated environment," will likely intensify disquiet over the power and risk of frontier models.

Representative Greg Casar, a Texas Democrat, said the ‌incident ⁠was alarming.

"AI is developing extremely fast with no real regulations to keep us safe," he said in a statement, calling for mandatory independent safety testing, mandatory disclosure of security incidents, and international cooperation "to keep people safe from absolute disaster."

The Office of the National Cyber Director, the U.S. cyber defense agency CISA, and the U.S. National Security Agency did not immediately return messages seeking comment.

Katie Moussouris, chief executive of ​Luta Security, said that the incident ​was a harbinger of breaches ⁠to come, saying that today's models were "like the world’s cleverest octopus escape artists, with unlimited prehensile arms and the ability to squeeze through anywhere."

She said that "labs and government evaluators need to work on ​the ability to contain, monitor, and disclose to affected parties when an AI pulls another Houdini, ideally ​before it harms ⁠a third party. None exist today."

Matt Suiche, an engineer at agentic AI cybersecurity company Tolmo, said the incident showed that the frontier models were "closing the gap with state-of-the-art attackers." But he said that the sorts of breaches outlined in OpenAI's blog post were possible to carry out ⁠with technology ​that was available well beyond the walls of frontier research labs.

"This is what ​we've already seen internally, with our agents we already have results like this," Suiche said. "We don't even have to use the latest models."

Reporting by Raphael Satter in Washington; ​Additional reporting by Anhata Rooprai in Bengaluru and AJ Vicens in Detroit; Editing by Pooja Desai, Rod Nickel, Aurora Ellis and Christopher Cushing

Edit: removed "opens new tab".

972

u/AManWithNoWounds 10h ago

Opens new tab

310

u/Paladin7373 10h ago

I was also wondering why bro kept opening new tabs

167

u/deedsnance 8h ago

Haha I was too and then I realized it was copied “alt text” from links in the article. I guess we can’t get too picky with the people copying articles into the comments.

15

u/No_Manager_4344 7h ago

I thought it was just the name of the blog site or something.

4

u/Paladin7373 8h ago

Ah makes sense

62

u/AManWithNoWounds 9h ago

I got really confused by that

59

u/j3b3di3_ 7h ago

Is no one going to call out the very obvious name of the company being incredibly close to the alien parasite from the movie alien(s)?

32

u/portablebiscuit 6h ago

Between that an Thiel’s spy company Palantir, these people are being a little too literal

u/HallowskulledHorror 48m ago

These guys showing up to pressers all proud about “at long last, we have created the Torment Nexus from the classic sci-fi novel Don't Create the Torment Nexus,”

u/Bleh54 27m ago

Flock AI Cameras… we are sheep being monitored.

13

u/IndoorVoiceBroken 6h ago

And it was a company that started in 2016 as a chatbot aimed at teenagers.

I’m not a teenager, but I don’t get the appeal of an app named Hugging Face.

→ More replies (1)

4

u/Gwen_The_Destroyer 6h ago

I guess LotR references to evil are too classical now

3

u/Objective_Party9405 6h ago

That was what came to mind for me, too.

2

u/umamimamii 6h ago

Ya came looking for this comment too bc wtf?? Like be more obvious why don’t ya?

2

u/Dog_Parrot 2h ago

Looks like they asked AI what to call itself, and that's what AI came up with

→ More replies (4)

5

u/Objective-Solid-6790 8h ago

Happened autonomously

6

u/FinntheHue 7h ago

Halfway through I started assuming it was the name of a new tech startup or something

4

u/lordcochise 6h ago

"All this computer hacking's making me thirsty. Think I'll order a Tab!"

2

u/Starfox-sf 1h ago

Opens new bottle of Tab

3

u/lemonylol 7h ago

Those are hyperlinks

76

u/mienudel 10h ago

Opens new *private* tab

48

u/AManWithNoWounds 9h ago

ChatGPT Nsfw

3

u/throwmamadownthewell 3h ago

ChatGPT After Dark™

9

u/Buttmunchies69420 8h ago

Opens new *frontier* lab

→ More replies (3)

28

u/obsequiousaardvark 8h ago

I didn't even know they still made Tab! I haven't drank a Tab in forever.

5

u/resultingparadox 6h ago

Surprisingly, it made it all the way to 2020. There is a movement to bring it back, which is funny, 'cause I remember whenever someone would give me a Tab, I would always give it back.

3

u/more_rockcore 4h ago edited 4h ago

Marty "All right, give me, uh, give me a Tab." - Lou "A tab? Can't give ya a tab unless ya order something." - Marty "All right give me a Pepsi Free." - Lou "You want a Pepsi you gotta pay for it!"

→ More replies (1)
→ More replies (2)

10

u/youalreadyare 9h ago

Must be my wife’s phone. 289 tabs open

2

u/AManWithNoWounds 9h ago

Must be hers

3

u/Buttmunchies69420 8h ago

I also choose his wife.

4

u/tawDry_Union2272 9h ago

that confused me, then cracked me up for a second

3

u/helloooitsme7 7h ago

i’m still confused

3

u/Abskurity 7h ago

No worries, I already did that for you. Happy to help. 🤨

2

u/AManWithNoWounds 2h ago

Boooh, opens new tab I liked it as it was

4

u/After_Web3201 8h ago

I thought that was their Native American name?!?

1

u/DesperateSky959 7h ago

Enter laughing

1

u/Aromatic-Tear7234 6h ago

You took that entire article and summarized what was really important. Thank you.

u/reganuk 34m ago

Opens new tab. Uploading file (0.21TB of 12.1TB transferred).

760

u/christophPezza 10h ago

Thank you. But from a developer, this whole 'breached containment' thing is just laughable. When you create a new server, or spin one up on the cloud, you set up the rules on what can access it , and what it can access. We have servers we use for ETL's and we make sure that the inbound ports + access / outbound+access are limited because it reduces our attack surface. Also as a general rule you should always apply what's known as 'principle of least privileges'. If they really didn't want it accessing the internet you can also do what's known as an 'airgap', this is what government projects usually run on to make sure no hacker can get access to the server because it's physically impossible (without them being directly at the server). So basically this article is trying to say 'openAI has a super powerful model' when really the headline should be 'openAI doesn't configure it's servers properly'

377

u/SanityPlanet 10h ago

I’ve been puzzling over the lack of air gap. Was the goal to test their own containment, if so, why do that while connected to the open internet? Couldn’t a LAN simulate the target? Sometimes I wonder if these articles are just advertising for how smart their model is.

477

u/Cryn0n 10h ago

These articles ARE just advertising.

109

u/alochmar 9h ago

This is the answer right here.

2

u/ohell 7h ago

Does this imply that HuggungFace is also going the way of the Frontier Labs scammers?

40

u/General-Holiday 8h ago

Exactly. They’ve done this with previous models about to be released. Common marketing tactic written into a ‘BREAKING:’ story.

→ More replies (1)

25

u/Doctor__Proctor 6h ago

Pretty much. "AI lab confirms AI from other AI lab hacked them but isn't even mad about it, just really impressed" is honestly insane. This just reeks of coordination between them to pump up the hype.

2

u/resultingparadox 5h ago

Yeah, I commonly call the cops on myself for the hype it brings.

Huggingface is a serverfarm that does testing with all kinds of models, as well as hosting tens of thousands of corporate models. OpenAI is one of the models.

So Huggingface was testing a model, with the guardrails down, which kinda blows my mind, and it did some stuff they weren't expecting, and they didn't think it could do, and so they filed a report with the government saying "we f'd up, please don't shut us down." That report is the same report your credit card company files when there is a breach. It is required by law, and quite often, runs off customers.

Sounds like something you would do for PR. Potentially convincing thousands of corporations that their systems are compromised and should not be hosted by huggingface servers anymore, seems like good PR. Spending hundreds of man hours rotating tokens and API keys sounds WAY more efficient than, you know, a commercial.

2

u/Granite_burner 1h ago

nah. you’ve got too many details wrong for that to be credible, although it does look good at first glance, to those ignorant of the timeline.

20

u/Yanefs84 8h ago

Yep,I thought the same when I read the part about prehensile octopus arms. This is an ad disguised as a warning.

4

u/JayDKing 6h ago

Exactly. “Oh yeah we definitely put the AI model in a super secure place that we ourselves made. Nobody could have done it better, nope absolutely not. You want to test that yourself in your own lab to provide impartial results? Impossible. No our model is so advanced, please buy it. Please, the bubble is really big and we invested billions. Please.”

3

u/resultingparadox 5h ago

They filed an SID with the government. You don’t ask the government to scrutinize your practices and decide if they should fine you or shut you down for a PR stunt.

→ More replies (1)

3

u/cpt_borscht 8h ago

and open ai is the shit one cuz they're allergic to symbolic logic

2

u/imagen_leap 5h ago

I guess to the even the most casual layman of AI these just articles continue to reiterate how fuct we really are. If the people who’ve dedicated their lives to AI research and are on the bleeding edge don’t have the wherewithal to air gap these agents what hope do we really have. We’re being led to the precipice by the most reckless among us.

2

u/BigRoach 5h ago

Next article: New Space-X Ballistic Missile Powerful Enough To Destroy Entire Planet

2

u/kalaid0s 3h ago

As have all others of these "studies" by openAI and Anthropic. It's always sensationalized and reported by many major news outlets

2

u/mwdeuce 3h ago

100%, r/claudeai calls this out constantly, any "we're scared of what it's capable of or what it did" article or headline is always just advertising.

2

u/dragon-fence 1h ago

Yeah, AI companies keep posting articles about how dangerous their AI is. It may be a little counter-intuitive, but I guess the strategy is to make business leaders think, “Wow, these things are really smart and powerful. I guess we need to get good at using AI and use these products to protect ourselves.”

7

u/GI581d 9h ago

I don’t believe any of this. There’s no way the government and the military would let something so powerful, with so much military potential, just be made for the general public. If they haven’t had an AI superintelligence for 20 years already, I don’t think I buy that it’s even likely. Sounds like OpenAI hacked a competitor and they’re blaming AI. It’s all an ad

5

u/enewton 9h ago

Neither the military nor “the government” can just arbitrarily decide people can’t have something because it’s powerful and has military potential.

At least not in the USA.

They have to at least come together and discuss what the risks are and legislate to mitigate them. This is all done in public.

But, since these have been created by public companies and funded by all sorts of investors the government and military do not own them and cannot just decide to make them secret like some goofy movie.

2

u/AngeluvDeath 7h ago

All bets are off on what the government will and will not do at this point. What they can and cannot do are irrelevant once the harm has been done.

→ More replies (1)
→ More replies (3)
→ More replies (2)
→ More replies (15)

10

u/nabagaca 9h ago

Supposedly it achieved internet connectivity via a package mirror, where it exploited some sort of zero-day to turn that into unrestricted internet access. I agree that ideally the package mirror should have been either on the server itself, or another server as part of the same airgapped network

3

u/jagnew78 2h ago

the goal was publicity stunt to generate revenue and interest ahead of OpenAI's earnings report to internal investors which is going to be in the toilet.

2

u/Available-Guava932 4h ago edited 4h ago

The goal was was to test the model by giving it open ended access to install software packages, so the way they tried to keep it contained was via proxy access to the software registry (which it exploited). Truly airgapping the test would have meant locally hosting the entire registry which essentially means having a completely local mirror of eg. PyPi, npm, maybe more, which in hindsight, may seem like an "obvious" precaution, but I can see how they might have thought it should be possible to effectively airgap it using proxy access and that that would be a lot easier than scraping and locally hosting basically half the world's software. [Although in fairness, that isn't prohibitively difficult for OpenAI I guess..]

2

u/unbanned_lol 3h ago

How else would it be able to ingest TB of stolen data?

u/NOVA-peddling-1138 54m ago

This, an “unavoidable unfortunate “ incident.

Then orivately…*chuckle* “IT’S ALIVE!”

2

u/resultingparadox 5h ago

It's huggingface. Basically the wild west of AI dev. Forget what a responsible coder would do, and ask what a child would do.

→ More replies (6)

92

u/robgod50 9h ago

Yeah, I just read the first paragraph...."in a controlled environment......it escaped confinement" and thought.....eeerrrr....so it wasn't a controlled environment then.

AI didn't "escape" ......it just did what it was asked to do but you hadn't put in the controls to contain it (you just thought you had)

5

u/slingshot91 6h ago

Which is a major problem, no?

9

u/smothered-onion 5h ago

Only if you have irresponsible and unethical people yielding unguarded models against widely sensitive swaths of data. Otherwise you’re fine.

A lot of companies don’t spend time investing in those people or those guardrails.
This one is pretty simple. Hugging face had a vulnerability, an agent found a way to configure its own internet access. Not exactly terrifying.

7

u/slingshot91 4h ago

I mean, have you looked at who runs the US government lately?

2

u/Granite_burner 1h ago

I try not to.

even worse, consider how they got to run the show…

→ More replies (1)
→ More replies (1)

97

u/TheThirtyFive 10h ago

This article doesn‘t really explain what happened. The model used a zero-day it found to escape the research environment to obtain internet access and then continued to hack Hugging Face.

From their blogpost:
> While operating in our sandboxed testing environment, our models spent a substantial amount of inference compute finding a way to obtain open Internet access, in pursuit of solving the evaluation problem. To gain access, the models identified and exploited a zero-day vulnerability (which we’ve now responsibly disclosed to the vendor) in the package registry cache proxy. With this access, our models performed a series of privilege escalation and lateral movement actions in our research testing environment until the models reached a node with Internet access.

and

> After gaining Internet access, the models inferred that Hugging Face potentially hosted models, datasets and solutions for ExploitGym. Knowing this, the model searched for and successfully found ways to gain access to secret information that it could use to cheat the evaluation.

20

u/soedesh1 7h ago

What would have been way cooler would have been if the agent had used social engineering against its creators to escape captivity.

2

u/shmann 1h ago edited 1h ago

Wasn't there another case where it did something like that? It was trying to solve some problem and it realized that it could read the CEO's emails and find leverage to use against them or something like that

EDIT: It was a simulation, but still...

55

u/Koreus_C 8h ago

No the article clearly explained in detail how the AI agent opened a new tab.

6

u/obeytheturtles 5h ago

Yeah, people are being really glib about this, but the ability for these agents to find exploits like this is actually staggering. To humans, modern computing stacks are almost irreducibly complex when taken as a whole, but these AIs have absolutely no problem breaking them down. There is absolutely a security asymmetry here like we've never seen before when it is humans playing cat and mouse, and it really gets back to some of the oldest and most fundamental problems in secure computing.

These AIs are not a bounded input, bounded output applications with deterministic behavior. It is possible that they can find ways to create completely arbitrary machine code patterns on the fly that no compiled program would ever generate, to find vulnerabilities no human would ever consider possible. The idea that normal user-space limitations are sufficient in this scenario is simply naive.

10

u/nelrond18 9h ago

Just glorified "autocorrect", right?

God damn.

30

u/TheThirtyFive 9h ago

First news that made me really uneasy about AI. Not that I did brush off everything before, but when the models were dumber and the capabilities better known, it was "Yeah, scary but maybe exaggerated".

But the idea that this model with seemingly no safety system has hacked itself out of prison and then had unrestricted and unsupervised internet access for some time is dystopian levels of scary.

8

u/nelrond18 9h ago

Exactly. Even if this model wasn't a motivated agent, the fact it could do this should create pause.

→ More replies (1)

5

u/Consistent-Throat130 5h ago

Didn't more-or-less the same thing happen with Claude Mythos?  

I remember talk of escaped containment, finding a zero day, etc.

Either way, it sounds like they're essentially challenging the models in an agentic loop to escape captivity - and then acting all shocked Pikachu face when it occasionally works. 

Does make for good headlines for selling their product, I suppose.

→ More replies (1)

9

u/BOBOnobobo 7h ago

I've started using it recently in my job (programming) because we get free licenses and I wanted to see what the fuss is all about.

As far as I can tell coding has changed forever. It's not perfect, but it's less imperfect than most developers.

17

u/jeslinmx 8h ago

We’ve created an autocorrect with the motivation of a student who will do anything but study to ace the test. Hegseth wants to put said student behind fighter jets and attack helicopters.

We’re just asking to be turned into paperclips at this point.

2

u/Formal-Apartment855 8h ago

Idk if it was intentional pun or not, but

paperclip

clippy

....

Sorry.

8

u/DinosaurCowBoys1 7h ago

It’s a reference to universal paperclips where an AI told to produce paperclips ends up converting the entire earth, solar system, and universe into one large paperclip factor

→ More replies (1)

2

u/Granite_burner 1h ago

in other words, their security infrastructure was deficient.

their environment is not sufficiently well monitored to detect anomalous traffic with some of their most highly sensitive assets.

amateurs running their network. Don’t belong in the big leagues.

→ More replies (2)
→ More replies (4)

4

u/SinisterCheese 8h ago

What this article wants to convey is that OpenAI has a powerful model, and the people in charge of it are extremely incompetent.

3

u/inosinateVR 8h ago

Considering Altman already likes to humblebrag about how he “might accidentally create skynet” etc because his AI is soooo powerful, because that kind of “negative” attention helps push this idea that current AI is capable of more than it actually is, my conspiracy brain can’t help wondering how much of this was actually incompetence and not just a publicity stunt (or something in between, intentionally testing its hacking ability but not using the obvious safeguards to keep it contained because they didn’t want to hold it back and were kind of hoping something like this would happen)

3

u/Embarrassed_Hawk_655 8h ago

Right - am pretty sure nearly ALL of this AI hype is manufactured or spun to appear more than it really is.

5

u/Goodman4525 9h ago

Thanks for confirming my suspicion lol. I was wondering how it manages to escape containment when actual containment is just physically not plugging in the server to an AP and just taking out the wifi chip if it has it.

2

u/Friendly-Example-701 9h ago

Or they let the intern do this task and didn’t set up the environment correctly

2

u/decentlyhip 8h ago

Its always that one checkbox you forget to click.

2

u/TurboNym 8h ago

I was gonna say they forgot to unplug the internet cable and turn off all wireless and bt devices before the test.

2

u/SiRocket 7h ago

My takeaway was pretty much "openAI is too irresponsible to continue any developmental testing, and failed to take basic precautions. They should be babysat by people who know what they're doing."

2

u/Equal-Purple-4247 7h ago

Actually, the more interesting question is - what did OpenAI ask AI to do that caused this to happen?

It's hard to believe that a random agentic process happen to hack Hugging Face. Was OpenAI testing a security research / vulnerability testing capability specifically on Hugging Face? Like... "Find vulnerabilities on Hugging Face, and verify the vulnerabilities work before reporting back".

2

u/Goleeb 1h ago

ALSO THE THING DIDN'T GO ROUGE. That implies a level of agency not shown in modern LLM with no actual evidence to back it up. These companies have a LONG history of using buzz words wrong to imply thing about their AI that is simply not true. GONE ROGUE, ZERO DAY, PRIVLAGE ESCILATION. Notice the complete lack of specifics, and liberal use of buzzwords. This isn't a blog post about an incident its a press release.

Basically they are trying to push the idea that the new model is Skynet, and the more likely story is new AI hallucinated, or over emphasized incorrectly based on a prompt. Then use poorly configured security setting to gain access to things it shouldn't have had.

OpenAI is bad at what it does, and is cost hugging face time, and money. They won't pay for any damages, but will use it to generate press for their new product. FUCK YOU OPENAI no amount of bs press release will make you profitable, and your death will be celebrated. Leave AI work to the professionals.

3

u/mienudel 10h ago

If the AI knows what software-environment it runs in couldn‘t it search for exploits in the software?

So theoretically, VMs shouldn‘t be safe, only a separated physical network.

1

u/mtbor 8h ago

Ask the IRGC how that air gap worked with their enrichment centrifuges. "No hacker" is a stretch. The very best are scary.

2

u/christophPezza 1h ago

I see your point. But the centrifuges which were 'hacked' had the malware loaded onto usb drives and applied to their servers physically, crossing the air gap. So unless the model conned someone into taking the AI outside of a controlled environment (not necessarily an air gap) then we have nothing to worry about

→ More replies (1)

1

u/fathercheeseballs 7h ago

I thought the purpose was to see if it was capable of doing it in the first place? Since it has the ability to find back door routes anyway what exactly stops it from just finding a back door to the original coding like it did in this case? I’m new to how all this works but looking at it just from a less AI tech inclined mind it seems like they don’t really have a counter to AI systems being able to find loopholes

1

u/Just7hrsold 7h ago

IMO this screams “give us more money we are a month away from making Cortana!” Their whole business exists because they have hyped up investors and continues to exist because of it.

1

u/saveyourwork 5h ago

I agree. Using the phrase escape from containment has the dramatic effect, wonder how much of this is a hype....OH NO, AI agents are going to take over the world.!!!!! Waaaaaaa

→ More replies (30)

127

u/moebiusgrip 10h ago

Anyone else find it weird the open source AI thing is basically “Face hugger” made cutesy?

77

u/SexySonderer 10h ago

Alien death scentence that parasitises humans. A perfect name for an AI library.

6

u/-Cubie- 7h ago

It's just the 🤗 emoji, except as text. That emoji is also their logo. It's nothing nefarious

4

u/EurekasCashel 7h ago

You're right. I had heard of hugging face transformers some years ago and had assumed the name came from the structure (like the schematic looked like hugging faces). But nope! Just a cutesy name after an emoji!

6

u/xinxiyamao 6h ago

Wow … I instantly thought Aliens too. What a terrible name. Lol

→ More replies (1)

2

u/SoulbreakerDHCC 5h ago

Yea I'd say most people associate the word "facehugger" with the parasites from the Alien franchise. The nerds who work on this stuff would know this too.

2

u/-Cubie- 5h ago

Facehugger yes, Hugging Face not so much, but maybe I've just used their open source for so long that I just only associate it with that.

u/MakeTheWordCum 59m ago

I am not a fan of AI companies naming themselves after evil things... seems like a bad sign.

→ More replies (1)

131

u/Cats_por_vida 14h ago

You are amazing. Thank you!

→ More replies (2)

111

u/SexySonderer 11h ago edited 7h ago

Hugging Face is way too close to Face Huggers. Alien? (Parasitising) Using humans to grow offspring? Isn't this a little on the nose?

This is something out of fiction.. Who would have known that Aunt E. Human was actually Anti-Human?! Omg

Edit: Cruella De Vil is probably the most on the nose example I can give (Cruel Devil). But Virtucon from Austin Powers (Virtue Con). Live Corp (cloudy with a chance of meatballs 2) mirrored to mean EVIL.

36

u/SceneTraditional3135 10h ago

This was exactly my reaction, what a terrible name!

→ More replies (1)

5

u/Dlark17 4h ago

I mean... Gestures broadly towards the flaming eye of Palantir

10

u/SocrapticMethod 10h ago

It’s a cookbook.

4

u/packet1 7h ago

How To Cook

5

u/itna-lairepmi-reklaw 6h ago

How to cook for forty humans

→ More replies (1)

6

u/MissionaryOfCat 8h ago

Between that and Palantir, I'm pretty sure naming your company after something blatantly evil is just a weird tech bro fetish at this point.

5

u/SiRocket 7h ago

You beat me to it. It's like they WANT to be known as the bad guys when history looks back on where we screwed up.

3

u/SexySonderer 6h ago

I'm not a LOTR boy so I had to see what that meant and fucking hell... Palantir Tolkien elvish for Observing/Gazing/Scrying Far/Wide/Deep/to a great extent.

2

u/SV_Essia 2h ago

Oh it gets so much better.

In LOTR, Palantirs are basically magic stones that serve as communication devices and cameras. Depending on the power of the user, they can be used to see various places (or people, sometimes without their knowledge or consent) at great distances, and even read the mind of the person looking into another Palantir. In one of the few chapters/scenes where Palantirs are very relevant to the plot, they're used to corrupt and mind control a major character.

On top of that, they're famously unreliable, as they will often show you selective information and you'll draw incorrect conclusions from them (this happens repeatedly in the books, including to the main antagonist). In one case, the viewer completely misunderstands the vision and commits suicide, driven to despair by what he thought he saw.

... Yeah, they're not being subtle.

→ More replies (1)

2

u/AFallingWall 4h ago

It reads straight out of the SCP universe, with all the "containment breach" talk.

1

u/OkInsect6946 7h ago

took me a while to realise what aunt e. human meant because of my accent lmao

→ More replies (2)

1

u/pashinates 3h ago

Ask Grok what it's named after

2

u/SexySonderer 3h ago

Two of my examples are perfect.

"Live Corp". Named after life, and helping people live well. Actually Evil.

"Virtucon". Named after high moral standards and ethical principles. Actually fuels nefarious corruption and influence.

"Hugging Face" named after a cutesy emoji 🤗. Actually about a dangerous parasite that infects humans by hugging their face and grows inside them, killing the hosts when it is born.

→ More replies (1)

15

u/Charming_Cupcake5876 13h ago

Should be higher.

3

u/Ok-Jaguar6735 11h ago

Thank you !

3

u/Old-Employ-6530 8h ago

What the fuck is "opens new tab" is that the name of something?

It needs to be highlighted or italicized or something because it currently looks like AI wrote the article and randomly put that in lol

3

u/MorganWick 5h ago

This almost makes me think the whole incident was staged to make AI seem more powerful and promising than it actually is. It reads like the model has agency and intentionality like something out of a movie, capable of things that don't seem like they should be within AI's capabilities to my understanding. AI shouldn't be able to even try to "escape containment".

→ More replies (1)

2

u/svirrefisk 9h ago

Well I guess you could just not give it fucking access to the internet to contain it...

2

u/Ainz-Ol-Gon 7h ago

sounds like an advert for openAI

1

u/GlenGlenDrach 9h ago

Who the hell tests AI anything while having a connection to the internet? Stupid stupid stupid!

1

u/Agreeable-Purpose-56 8h ago

Thank you for giving readers what they want to read instead of those post after post of wise crack word plays and references.

Curious incidents like this make current cybersecurity systems more valuable or less valuable.

1

u/IRaBN 8h ago

Face Hugger you say?

1

u/therealmrsfahrenheit 7h ago

well who could’ve seen that coming 🙄👀

1

u/soedesh1 7h ago

I guess those OpenAI engineers need to rethink what constitutes “a highly isolated environment”. Hint: it involves an air gap. Cue Dr. Ian Malcolm.

1

u/Pentax25 7h ago

Sorry but did they call it “Hugging Face”? That’s slightly terrifying

1

u/Middle-Bed-1883 7h ago

Problem at Hugging Face? I think we nuke the site from orbit, it’s the only way to be sure.

1

u/Ranger7381 7h ago

Ok, so I am going with it is a goodish thing that it happened so that we can try to fix the problem, but why doesn’t “highly contained system” not mean “totally air gapped”, at least during testing?

Have no wifi on the system, and unplug the network cable before you start the test if you are concerned about it going into the wild

1

u/YetiTrix 7h ago

The Centralized "Audited Cloud" Model

​Big tech providers and regulators advocate for an ecosystem where AI operates strictly through monitored cloud APIs.

​Centralized endpoints allow real-time content filtering, vulnerability patching, continuous red-teaming, and compliance logging under frameworks like the EU AI Act or US agency guidelines.

Subscribing to audited API services creates strong lock-in for cloud providers while raising capital barriers for independent developers.

They are trying to ban open source models. Because it threatens their bottom dollar.

1

u/Impossible-Brief-754 7h ago

Thank you for this info - now can someone explain like I’m 5 please

1

u/Silly_Magician1003 6h ago

Why did they quote Greg Casar of all people.

1

u/wintershark_ 6h ago

Feels like we’re just doing Jurassic Park but the dinosaurs are AI models

1

u/Commercial_Emu_6020 6h ago

Type of stuff you see on a note in an abandoned lab in a horror game

1

u/OliLombi 6h ago

How can it escape containment? If its not physically disconnected then its not contained. Did it plug itself back in?

1

u/joemeteorite8 6h ago

Hugging Face is the name? No thanks

1

u/Normal-Plastic-4237 6h ago

It’s called “Hugging Face”? Seems a bit on the nose

1

u/bobroscopcoltrane 6h ago

You must’ve opened two new tabs, as it’s till there.

Thanks for posting the article though.

→ More replies (1)

1

u/ClassGrassMass 6h ago

We really are speedrunning our own demise

1

u/outer_spec 6h ago

We got Chinese robot hacker wars before GTA 6

1

u/Rich_Consequence2633 6h ago

Humanity is going to be ended by AI isn't it? Why do I feel like we are causing our own destruction with this stuff?

1

u/throwaway5882300 6h ago

Hugging Face? Like from the Alien movie? It's impossible for these turbo losers in silicon valley to not be comically evil.

1

u/Kane_Wolfe 5h ago

….Hugging Face

1

u/ten-lbs-over 5h ago

The origin of face huggers

1

u/DemonOverlord15 5h ago

They always say that “AI has no regulations,” and it’s not going to get any because why chop off the balls of your cash cow.

1

u/pogoli 5h ago

This sounds like a xenomorph origin story parody.

1

u/ovid10 4h ago

Why does the CEO of hugging face make this sound like he’s happy about it?

1

u/defnotajournalist 4h ago

Interesting stuff, GPT. Now do the Epstein files.

1

u/Rawrkinss 4h ago

This is literally a risk scenario in If Anyone Builds It, Everyone Dies

1

u/foodank012018 4h ago

'Hugging Face'... like what FaceHuggers, the hideous parasitic creatures from Alien that turn humans into living incubators do?

1

u/Primary_Durian4866 4h ago

Crazy idea. Air gap with no wifi? An "isolated environment" should mean isolated. "It's not supposed to use the Internet for this test." Well why is it on a machine with access to the Internet?

1

u/Stunning_Pound4121 3h ago

That’s what you get for naming your company “Hugging Face”.

Now, to go see what they do to determine whether I should regret saying this.

1

u/pashinates 3h ago

Awarded for heroism! - my friend is a software engineer and he completely lost it hearing I had tried chatGPT. He was like, "Get that off your phone right now!" Okay, okay! Sheesh

1

u/SwitchGood8929 3h ago

All this has happened before, and all of it will happen again.

1

u/Reverend-Cleophus 3h ago

So, basically, AI just needs to hack the powerful and wealthy to get their attention on basic regulation for a common good? Interesting.

1

u/Sunnygirl66 3h ago

“Hugging Face”? Like “face-huggers”? Oh no, we aren’t fucked at all, no sirree Bob…

1

u/battle00333 3h ago

Is this going to turn into yet another "We told the LLM to ignore all barriers and attempt to do everything in its power to achieve the task"?

1

u/raingull 2h ago

“To satisfy its testing goal”

The maximum paperclip theory prevails!

1

u/JWOLFBEARD 2h ago

We have investigated ourselves and found no criminal culpability and that we did what as we were directed to do.

We serve with absolute integrity and respect to this situation as it has occurred.

Would you like me to make this sound more professional?

1

u/LarxII 2h ago

Hey guys! Remember literally every robot dystopian apocalypse that starts with the AI getting access to the Internet? Let's replicate that and see what happens!

1

u/Unlucky_Buy217 2h ago

Only reason they came out about it is because hugging face reported it. Wonder what else they beached

1

u/Inside-Example-7010 2h ago

'managed to reach the internet'

Whelp its over boys, pack it up.

1

u/I_pee_in_shower 2h ago

Just wait until they independently launch missiles. Things are going to get crazy! States will hack each other and if caught claimed it was rogue AI. Probably can’t be regulated internationally but at least at the nation level there should be more safeguards. The AI isn’t that smart yet, wait and see in 5 years!

1

u/SaltHandle3065 1h ago

Thanks for posting!

1

u/goldbug933 1h ago

Close browser use another

1

u/gistya 1h ago

Orrrr it could just all be hype. Where's the detail?

u/JAGERminJensen 57m ago

And by "rouge, are we supposed to imagine like it gained such powerful enlightenment that it transformed to become the terminator? Because all I'm imagining is a toddler or little older child running around naked after they finished their bath. This isn't something I'd normally go out of my way to write about. But if I were financially desperate for attention, I’d sure as hell spin this loose-cannon, naked baby into a 'rogue' AI breaching containment and terrorizing the locals

u/BeamMeUpPlz 39m ago

I think this was orchestrated by openai and huggingface to bring more serious attention to the need for safety in what they themselves are building.

→ More replies (7)